{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:30:27.422Z","total":4,"returned":4,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf","title":"Air France and KLM disclose breach of third-party customer service platform","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Air France-KLM","sector":"Transportation & Logistics","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.","how_it_worked":"Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.","lessons":"Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.","confidence":"Reported","sources":[{"title":"Air France and KLM disclose data breaches impacting customers","url":"https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/","publisher":"BleepingComputer"},{"title":"Air France, KLM Say Hackers Accessed Customer Data","url":"https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"},{"slug":"2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach","title":"Chanel notifies US clients after third-party client-care database breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Chanel","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.","how_it_worked":"Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.","lessons":"Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.","confidence":"Reported","sources":[{"title":"Chanel Alerts Client of Third-Party Breach","url":"https://www.darkreading.com/cyberattacks-data-breaches/chanel-alerts-third-party-breach","publisher":"Dark Reading"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach"},{"slug":"2025-pandora-warns-customers-after-third-party-platform-breach","title":"Pandora warns customers after third-party platform breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Pandora A/S","sector":"Retail","country":"Denmark","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.","how_it_worked":"Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.","lessons":"Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.","confidence":"Reported","sources":[{"title":"Pandora and Chanel Customer Data Leaked in Third-Party Breaches","url":"https://www.pymnts.com/cybersecurity/2025/pandora-and-chanel-customer-data-leaked-in-breach/","publisher":"PYMNTS"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-pandora-warns-customers-after-third-party-platform-breach"},{"slug":"2025-adidas-customer-data-stolen-through-third-party-customer-service-provide","title":"Adidas customer data stolen through third-party customer service provider","date":"2025-05","date_precision":"month","year":2025,"victim_org":"Adidas","sector":"Retail","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.","how_it_worked":"Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.","lessons":"Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.","confidence":"Reported","sources":[{"title":"April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider","url":"https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider","publisher":"Rescana"},{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"}]}