{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:16:45.596Z","total":35,"returned":35,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ReliaQuest blocks ShinyHunters vishing attack with device-trust controls","date":"2026-08-24","date_precision":"day","victim_org":"ReliaQuest","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"ReliaQuest did not state whether synthetic voice was used on the calls.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; no customer data was accessed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.","how_it_worked":"The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.","lessons":"Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.","confidence":"Confirmed","sources":[{"title":"ReliaQuest confirms failed data-theft attack after ShinyHunters breach","url":"https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"},{"slug":"2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe","title":"Abbott investigates ShinyHunters claim after mid-June vishing on employees","date":"2026-06","date_precision":"month","year":2026,"victim_org":"Abbott Laboratories (legacy Exact Sciences systems)","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.","how_it_worked":"Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.","lessons":"Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.","confidence":"Reported","sources":[{"title":"Abbott Investigating Cyberattack Claims From Two Threat Actors","url":"https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/","publisher":"HIPAA Journal"},{"title":"Abbott investigates after ShinyHunters claims massive data theft","url":"https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"},{"slug":"2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill","title":"Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records","date":"2026-01-29","date_precision":"day","year":2026,"victim_org":"Match Group (Match, Hinge, OkCupid)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":10000000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.","how_it_worked":"The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.","lessons":"Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.","confidence":"Reported","sources":[{"title":"Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match","url":"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/","publisher":"BleepingComputer"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill"},{"slug":"2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec","title":"Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Crunchbase","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":2000000,"threat_actor":"ShinyHunters","summary":"Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.","how_it_worked":"The attackers called Crunchbase staff and posed as internal IT support, using a pretext about an account or access issue that required the employee to sign in while the caller stayed on the line. The employee entered Okta single sign-on credentials and read back the one-time code, which the caller replayed against the live Okta login within its validity window, producing an authenticated session under a legitimate staff identity. The trust signals abused were the routine familiarity of an IT support call and the employee's own genuine Okta prompt; the pressure was urgency framed as fixing a problem already affecting the employee's access.","lessons":"Phishing-resistant, origin-bound authenticators remove the readable one-time code these calls depend on, and a standing rule that IT never requests codes by phone gives staff a clean refusal script.","confidence":"Reported","sources":[{"title":"Crunchbase Confirms Data Breach After Hacking Claims","url":"https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/","publisher":"SecurityWeek"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"},{"title":"ShinyHunters claims 2 Million Crunchbase records; company confirms breach","url":"https://securityaffairs.com/187340/data-breach/shinyhunters-claims-2-million-crunchbase-records-company-confirms-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing","title":"ShinyHunters claim 14M Panera Bread records after Entra SSO vishing","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Panera Bread","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.","how_it_worked":"The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.","lessons":"Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.","confidence":"Alleged","sources":[{"title":"ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach","url":"https://www.techrepublic.com/article/news-panera-bread-data-breach/","publisher":"TechRepublic"},{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing"},{"slug":"2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee","title":"Brinks Home breached after Microsoft Entra vishing call to an employee","date":"2026-07-13","date_precision":"day","year":2026,"victim_org":"Brinks Home","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.","how_it_worked":"The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.","lessons":"Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.","confidence":"Confirmed","sources":[{"title":"ShinyHunters claims Brinks Home breach, threatens to leak stolen data","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/","publisher":"BleepingComputer"},{"title":"Salesforce Hacks 2026: Everything We Know So Far","url":"https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"},{"slug":"2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai","title":"RingCentral data on 1.6M accounts leaked after social engineering campaign","date":"2026-07","date_precision":"month","year":2026,"victim_org":"RingCentral","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1600000,"threat_actor":"ShinyHunters","summary":"Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.","how_it_worked":"RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.","lessons":"Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.","confidence":"Confirmed","sources":[{"title":"RingCentral data breach exposed info of 1.6 million accounts","url":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","publisher":"BleepingComputer"},{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","url":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai"},{"slug":"2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft","title":"Cushman & Wakefield confirms vishing-triggered Salesforce data theft","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Cushman & Wakefield","sector":"Professional Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters; Qilin also claimed the victim","summary":"Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.","how_it_worked":"The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.","lessons":"Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.","confidence":"Confirmed","sources":[{"title":"Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim","url":"https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/","publisher":"Cybernews"},{"title":"Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped","url":"https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/","publisher":"Breached.Company"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"},{"title":"ADT confirms breach after vishing attack on employee's Okta SSO account","date":"2026-04-20","date_precision":"day","victim_org":"ADT","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using AI voice agents in its vishing operations; AI use in the ADT call was not separately confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"ShinyHunters set an April 27, 2026 ransom deadline; no payment or loss figure was disclosed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.","how_it_worked":"An operator called an ADT employee posing as internal support and used a plausible authentication pretext to route them to a company-branded fake sign-in page. The page relayed the credentials and one-time code to the real Okta login in real time, giving the attacker a live SSO session. Because Salesforce sat behind that same single sign-on, the session opened the CRM directly, and the attackers exported customer and prospect records in bulk before ADT terminated the intrusion. Extortion followed, with a leak deadline set three days after public confirmation.","lessons":"Phishing-resistant passkeys bound to managed devices, plus export-volume alerting on the CRM, would have blocked both the credential relay and the bulk extraction.","confidence":"Confirmed","sources":[{"title":"ADT confirms data breach after ShinyHunters leak threat","url":"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/","publisher":"BleepingComputer"},{"title":"ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack","url":"https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack","publisher":"Rescana"}],"entry_type":"incident","slug":"2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account"},{"slug":"2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi","title":"Carnival confirms social engineering of an employee account exposed 6 million customers","date":"2026-04-14","date_precision":"day","year":2026,"victim_org":"Carnival Corporation","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5995277,"threat_actor":"ShinyHunters","summary":"Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.","how_it_worked":"Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.","lessons":"Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.","confidence":"Reported","sources":[{"title":"Carnival Cruise confirms data breach affecting nearly 6 million people","url":"https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/","publisher":"BleepingComputer"},{"title":"Carnival Data Breach Exposed 6 Million People","url":"https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/","publisher":"SecurityWeek"},{"title":"Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach","url":"https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach","publisher":"Office of the Texas Attorney General"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"},{"slug":"2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi","title":"Charter Communications breach of 4.9M accounts began with an Entra vishing call","date":"2026-04-01","date_precision":"day","year":2026,"victim_org":"Charter Communications (Spectrum)","sector":"Telecom","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4900000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.","how_it_worked":"The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.","lessons":"Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.","confidence":"Confirmed","sources":[{"title":"Charter Communications data breach affects 4.9 million accounts","url":"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/","publisher":"BleepingComputer"},{"title":"Charter confirms Spectrum data breach after ShinyHunters claims hack","url":"https://www.foxnews.com/tech/charter-breach-warning-customers-know","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi"},{"title":"Identity protection firm Aura breached in vishing attack; ~900,000 records taken","date":"2026-03","date_precision":"month","victim_org":"Aura","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call that compromised the employee account.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":900000,"threat_actor":"ShinyHunters","summary":"Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.","how_it_worked":"The attackers targeted a single employee account with a voice phishing call, the same pattern the group used against Okta and Microsoft Entra single sign-on accounts throughout early 2026: pose as internal IT, offer help with an authentication task, and capture credentials and a one-time code through a lookalike login page. The compromised account was live for only about an hour, but that was long enough to export a marketing database wholesale. The stolen combination of name, address, phone and email is itself high-quality raw material for follow-on phishing and vishing.","lessons":"Short-lived access still enables bulk export; rate-limiting and alerting on large database exports would have caught the theft inside the one-hour window.","confidence":"Reported","sources":[{"title":"Aura data breach","url":"https://en.wikipedia.org/wiki/Aura_data_breach","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records"},{"slug":"2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo","title":"Figure Technology loses ~967,000 customer records after employee falls for SSO vishing","date":"2026-02-19","date_precision":"day","year":2026,"victim_org":"Figure Technology Solutions","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":967000,"threat_actor":"ShinyHunters","summary":"Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.","how_it_worked":"The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.","lessons":"Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.","confidence":"Reported","sources":[{"title":"Nearly 1 Million User Records Compromised in Figure Data Breach","url":"https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/","publisher":"SecurityWeek"},{"title":"Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters","url":"https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/","publisher":"Cybernews"},{"title":"Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People","url":"https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"},{"slug":"2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod","title":"CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes","date":"2026-02-13","date_precision":"day","year":2026,"victim_org":"CarGurus","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.","how_it_worked":"Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.","lessons":"One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.","confidence":"Reported","sources":[{"title":"CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach","url":"https://news.dealershipguy.com/p/cargurus-probes-cyberattack-shinyhunters-theft-1-7-million-records-data-breach-2026-02-23","publisher":"Dealership Guy News"},{"title":"CarGurus Reported Data Breach","url":"https://complyauto.com/cargurus-reported-data-breach/","publisher":"ComplyAuto"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod"},{"title":"Optimizely confirms data breach after vishing attack on employees","date":"2026-02-11","date_precision":"day","victim_org":"Optimizely","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"Optimizely did not state whether synthetic voice was used on the calls.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed; the company said there was no disruption to business operations.","records_affected":null,"threat_actor":"Likely ShinyHunters-affiliated","summary":"Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.","how_it_worked":"Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.","lessons":"Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.","confidence":"Confirmed","sources":[{"title":"Ad tech firm Optimizely confirms data breach after vishing attack","url":"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees"},{"slug":"2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts","title":"Hims & Hers support tickets stolen through compromised Okta SSO accounts","date":"2026-02-04","date_precision":"day","year":2026,"victim_org":"Hims & Hers Health","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.","how_it_worked":"Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.","lessons":"Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.","confidence":"Confirmed","sources":[{"title":"Hims & Hers warns of data breach after Zendesk support ticket breach","url":"https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/","publisher":"BleepingComputer"},{"title":"Telehealth Giant Hims & Hers Announces Data Breach","url":"https://www.hipaajournal.com/him-hers-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts"},{"title":"Betterment named among victims of the January 2026 real-time vishing wave","date":"2026-01-09","date_precision":"day","victim_org":"Betterment","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"No synthetic voice was reported for this campaign; the calls were described as live operators.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.","how_it_worked":"The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.","lessons":"Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav"},{"title":"SoundCloud hit as real-time vishing kits drive browsers through SSO logins","date":"2026-01","date_precision":"month","victim_org":"SoundCloud","sector":"Media & Entertainment","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":36000000,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.","how_it_worked":"The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.","lessons":"Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"},{"title":"Okta SSO accounts targeted in vishing campaign against financial firms","date":"2026-01","date_precision":"month","victim_org":"Multiple fintech, wealth management and advisory firms (unnamed)","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_note":"Ransom demands were made by email; no aggregate figure was published for this wave.","records_affected":null,"threat_actor":"ShinyHunters (signed some extortion demands)","summary":"BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.","how_it_worked":"Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.","lessons":"Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.","confidence":"Confirmed","sources":[{"title":"Okta SSO accounts targeted in vishing-based data theft attacks","url":"https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"},{"slug":"2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform","title":"Stellantis confirms customer data stolen from Salesforce platform","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Stellantis","sector":"Manufacturing","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered Lapsus$ Hunters (claimed)","summary":"Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.","how_it_worked":"The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.","lessons":"Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.","confidence":"Reported","sources":[{"title":"Automaker giant Stellantis confirms data breach after Salesforce hack","url":"https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/","publisher":"BleepingComputer"},{"title":"Stellantis confirms data breach involving customers' contact information","url":"https://www.engadget.com/big-tech/stellantis-confirms-data-breach-involving-customers-contact-information-194136744.html","publisher":"Engadget"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform"},{"slug":"2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the","title":"Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Kering (Gucci, Balenciaga, Alexander McQueen)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.","how_it_worked":"ShinyHunters told reporters the access came from the same telephone-based playbook it ran against dozens of consumer brands in 2025: a caller posing as internal IT or a SaaS vendor contacted staff with CRM access, cited a plausible support ticket, and guided them through granting a connected application permission in the customer-relationship platform. The identity impersonated was the victim's own IT function; the trust signal abused was a vendor-branded consent page that looked routine. No malware was deployed. Once approved by a human, the app was used to enumerate and export customer profiles, which were then used for private extortion demands.","lessons":"Retail and luxury CRM tenants should treat third-party app consent as a privileged administrative action requiring a second approver and out-of-band caller verification.","confidence":"Reported","sources":[{"title":"Company that owns Gucci, Balenciaga, other brands confirms hack","url":"https://techcrunch.com/2025/09/15/company-that-owns-gucci-balenciaga-other-brands-confirms-hack","publisher":"TechCrunch"},{"title":"Gucci, Balenciaga, McQueen confirm breach, ShinyHunters claim 7.4M customers' data stolen","url":"https://cybernews.com/news/gucci-balenciaga-kering-data-breach-7-million-customers-compromised-shiny-hunters/","publisher":"Cybernews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the"},{"title":"Workday discloses CRM breach after social engineering of employees","date":"2025-08-06","date_precision":"day","victim_org":"Workday","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign","summary":"Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.","how_it_worked":"Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.","lessons":"Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.","confidence":"Confirmed","sources":[{"title":"Workday hit by social engineering data breach targeting its CRM platform","url":"https://therecord.media/workday-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Human resources firm Workday disclosed a data breach","url":"https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-workday-discloses-crm-breach-after-social-engineering-of-employees","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"},{"slug":"2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf","title":"Air France and KLM disclose breach of third-party customer service platform","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Air France-KLM","sector":"Transportation & Logistics","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.","how_it_worked":"Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.","lessons":"Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.","confidence":"Reported","sources":[{"title":"Air France and KLM disclose data breaches impacting customers","url":"https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/","publisher":"BleepingComputer"},{"title":"Air France, KLM Say Hackers Accessed Customer Data","url":"https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"},{"slug":"2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach","title":"Chanel notifies US clients after third-party client-care database breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Chanel","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.","how_it_worked":"Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.","lessons":"Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.","confidence":"Reported","sources":[{"title":"Chanel Alerts Client of Third-Party Breach","url":"https://www.darkreading.com/cyberattacks-data-breaches/chanel-alerts-third-party-breach","publisher":"Dark Reading"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach"},{"slug":"2025-pandora-warns-customers-after-third-party-platform-breach","title":"Pandora warns customers after third-party platform breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Pandora A/S","sector":"Retail","country":"Denmark","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.","how_it_worked":"Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.","lessons":"Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.","confidence":"Reported","sources":[{"title":"Pandora and Chanel Customer Data Leaked in Third-Party Breaches","url":"https://www.pymnts.com/cybersecurity/2025/pandora-and-chanel-customer-data-leaked-in-breach/","publisher":"PYMNTS"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-pandora-warns-customers-after-third-party-platform-breach"},{"slug":"2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ","title":"TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs","date":"2025-07-28","date_precision":"day","year":2025,"victim_org":"TransUnion","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4400000,"threat_actor":"ShinyHunters","summary":"Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.","how_it_worked":"TransUnion has described the entry point only as a third-party application serving its consumer support operations and has not publicly confirmed a social engineering pretext. Reporting places the theft in the Salesforce campaign attributed to UNC6040 and ShinyHunters, in which callers impersonating internal IT support telephone employees, cite a routine integration or troubleshooting need, and talk the target through authorising an attacker-controlled connected application inside the genuine Salesforce authorisation screen. The abused trust signal is Salesforce's own real interface combined with a plausible internal support identity; the extraction that follows is automated and needs no further human involvement.","lessons":"Restricting connected-app authorisation to a small set of administrators and alerting on any newly bound application or unusual bulk export from the CRM would have contained this class of intrusion at the moment of consent.","confidence":"Reported","sources":[{"title":"TransUnion suffers data breach impacting over 4.4 million people","url":"https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/","publisher":"BleepingComputer"},{"title":"TransUnion becomes latest victim in major wave of Salesforce-linked cyberattacks, 4.4M Americans affected","url":"https://www.foxnews.com/tech/transunion-becomes-latest-victim-major-wave-salesforce-linked-cyberattacks-4-4m-americans-affected","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ"},{"slug":"2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm","title":"Cisco confirms vishing call gave attacker access to its third-party CRM instance","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (Salesforce vishing wave)","summary":"Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.","how_it_worked":"The attacker telephoned a Cisco representative and, using an internal-sounding pretext, persuaded them to authorise access to the company's instance of a third-party cloud CRM platform. This is the pattern Google's threat intelligence team documented as UNC6040: callers impersonate IT support and talk the target through granting a connected application or completing a sign-in that hands the caller an authenticated CRM session. The trust signals abused were a plausible internal support identity and the ordinariness of the request, and the abuse was quick and quiet enough that the export was complete before the account activity was identified.","lessons":"Restricting who can authorise connected applications in the CRM, and requiring a call-back through a verified internal directory number before any access-granting action, closes the path a single persuaded employee opens.","confidence":"Confirmed","sources":[{"title":"Vishing Attack Impacting Third-Party CRM System","url":"https://sec.cloudapps.cisco.com/security/center/resources/CRM-vishing","publisher":"Cisco (company advisory)"},{"title":"Cisco discloses data breach impacting Cisco.com user accounts","url":"https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"slug":"2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft","title":"LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave","date":"2025-07","date_precision":"month","year":2025,"victim_org":"LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040","summary":"Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.","how_it_worked":"The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.","lessons":"Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.","confidence":"Reported","sources":[{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"},{"title":"Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches","url":"https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"},{"title":"UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app","date":"2025-06-04","date_precision":"day","victim_org":"Approximately 20 Salesforce customer organisations, later including Google","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"No aggregate loss figure; extortion demands followed the intrusions by several months.","records_affected":null,"threat_actor":"UNC6040, with extortion branded as ShinyHunters (UNC6240)","summary":"Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.","how_it_worked":"The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.","lessons":"Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.","confidence":"Confirmed","sources":[{"title":"Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App","url":"https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"},{"title":"Google's own Salesforce instance hit by UNC6040 IT-support vishing","date":"2025-06","date_precision":"month","victim_org":"Google","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.","records_affected":null,"threat_actor":"UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'","summary":"Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.","how_it_worked":"Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.","lessons":"Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.","confidence":"Confirmed","sources":[{"title":"Salesforce customers duped by series of social-engineering attacks","url":"https://cyberscoop.com/google-unc6040-salesforce-attacks/","publisher":"CyberScoop"},{"title":"Google confirms Salesforce CRM breach, faces extortion threat","url":"https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html","publisher":"Security Affairs"},{"title":"FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups","url":"https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html","publisher":"Security Affairs"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"},{"title":"ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications","url":"https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications","publisher":"EclecticIQ"}],"entry_type":"incident","slug":"2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"},{"slug":"2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million","title":"Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers","date":"2025-05-29","date_precision":"day","year":2025,"victim_org":"Farmers Insurance","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1100000,"threat_actor":"ShinyHunters, working with UNC6040 / UNC6240","summary":"Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.","how_it_worked":"In this campaign the caller poses as internal IT or a support desk and tells the employee that a routine tool needs to be connected to the company's Salesforce tenant. The employee is walked to Salesforce's legitimate connected-app authorisation page and given an eight-digit connection code supplied by the attacker, which they enter and approve. Because every screen the employee sees is a real Salesforce page, the trust signal is Salesforce's own interface, not a spoofed one. Approval binds an attacker-controlled data-extraction application to the tenant with the employee's permissions, after which records can be pulled in bulk without any further interaction.","lessons":"Limiting the connected-app authorisation permission to a small admin group and blocking uninstalled or unapproved apps by default removes the single click that this pretext is engineered to obtain.","confidence":"Reported","sources":[{"title":"Farmers Insurance data breach impacts 1.1M people after Salesforce attack","url":"https://www.bleepingcomputer.com/news/security/farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack/","publisher":"BleepingComputer"},{"title":"Farmers Insurance Data Breach Affects 1.1 Million Customers","url":"https://www.secureworld.io/industry-news/farmers-insurance-data-breach","publisher":"SecureWorld"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million"},{"slug":"2025-adidas-customer-data-stolen-through-third-party-customer-service-provide","title":"Adidas customer data stolen through third-party customer service provider","date":"2025-05","date_precision":"month","year":2025,"victim_org":"Adidas","sector":"Retail","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.","how_it_worked":"Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.","lessons":"Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.","confidence":"Reported","sources":[{"title":"April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider","url":"https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider","publisher":"Rescana"},{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"},{"title":"Quantum Health network breached after social engineering call to a user","date":"2026-05-29","date_precision":"day","victim_org":"Quantum Health","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.","how_it_worked":"The intrusion started with a phone call rather than an email or an exploit. The caller persuaded a legitimate user to hand over the credentials needed to reach the network, and the attacker then held that access for roughly four days. Because the login was valid and used in a normal way, nothing surfaced until a network disruption on June 1 prompted investigation. HIPAA Journal noted that the tradecraft aligns with tactics commonly employed by the ShinyHunters threat group, though no ransomware operation claimed the incident.","lessons":"Phishing-resistant MFA prevents a disclosed password from being usable, and impossible-travel or new-device alerts would have flagged the four-day window of unfamiliar access.","confidence":"Reported","sources":[{"title":"Vishing Attack on Quantum Health Network Exposed Patient Data","url":"https://www.hipaajournal.com/quantum-health-precision-imaging-centers-heart-america-data-breaches/","publisher":"The HIPAA Journal"}],"entry_type":"incident","slug":"2026-quantum-health-network-breached-after-social-engineering-call-to-a-user","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-quantum-health-network-breached-after-social-engineering-call-to-a-user"}]}