{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:41.524Z","total":9,"returned":9,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Google's own Salesforce instance hit by UNC6040 IT-support vishing","date":"2025-06","date_precision":"month","victim_org":"Google","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.","records_affected":null,"threat_actor":"UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'","summary":"Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.","how_it_worked":"Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.","lessons":"Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.","confidence":"Confirmed","sources":[{"title":"Salesforce customers duped by series of social-engineering attacks","url":"https://cyberscoop.com/google-unc6040-salesforce-attacks/","publisher":"CyberScoop"},{"title":"Google confirms Salesforce CRM breach, faces extortion threat","url":"https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html","publisher":"Security Affairs"},{"title":"FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups","url":"https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html","publisher":"Security Affairs"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"},{"title":"ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications","url":"https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications","publisher":"EclecticIQ"}],"entry_type":"incident","slug":"2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"},{"title":"Workday discloses CRM breach after social engineering of employees","date":"2025-08-06","date_precision":"day","victim_org":"Workday","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign","summary":"Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.","how_it_worked":"Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.","lessons":"Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.","confidence":"Confirmed","sources":[{"title":"Workday hit by social engineering data breach targeting its CRM platform","url":"https://therecord.media/workday-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Human resources firm Workday disclosed a data breach","url":"https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-workday-discloses-crm-breach-after-social-engineering-of-employees","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"},{"slug":"2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf","title":"Air France and KLM disclose breach of third-party customer service platform","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Air France-KLM","sector":"Transportation & Logistics","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.","how_it_worked":"Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.","lessons":"Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.","confidence":"Reported","sources":[{"title":"Air France and KLM disclose data breaches impacting customers","url":"https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/","publisher":"BleepingComputer"},{"title":"Air France, KLM Say Hackers Accessed Customer Data","url":"https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"},{"slug":"2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm","title":"Cisco confirms vishing call gave attacker access to its third-party CRM instance","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (Salesforce vishing wave)","summary":"Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.","how_it_worked":"The attacker telephoned a Cisco representative and, using an internal-sounding pretext, persuaded them to authorise access to the company's instance of a third-party cloud CRM platform. This is the pattern Google's threat intelligence team documented as UNC6040: callers impersonate IT support and talk the target through granting a connected application or completing a sign-in that hands the caller an authenticated CRM session. The trust signals abused were a plausible internal support identity and the ordinariness of the request, and the abuse was quick and quiet enough that the export was complete before the account activity was identified.","lessons":"Restricting who can authorise connected applications in the CRM, and requiring a call-back through a verified internal directory number before any access-granting action, closes the path a single persuaded employee opens.","confidence":"Confirmed","sources":[{"title":"Vishing Attack Impacting Third-Party CRM System","url":"https://sec.cloudapps.cisco.com/security/center/resources/CRM-vishing","publisher":"Cisco (company advisory)"},{"title":"Cisco discloses data breach impacting Cisco.com user accounts","url":"https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm"},{"slug":"2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft","title":"LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave","date":"2025-07","date_precision":"month","year":2025,"victim_org":"LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040","summary":"Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.","how_it_worked":"The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.","lessons":"Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.","confidence":"Reported","sources":[{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"},{"title":"Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches","url":"https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"},{"slug":"2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million","title":"Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers","date":"2025-05-29","date_precision":"day","year":2025,"victim_org":"Farmers Insurance","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1100000,"threat_actor":"ShinyHunters, working with UNC6040 / UNC6240","summary":"Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.","how_it_worked":"In this campaign the caller poses as internal IT or a support desk and tells the employee that a routine tool needs to be connected to the company's Salesforce tenant. The employee is walked to Salesforce's legitimate connected-app authorisation page and given an eight-digit connection code supplied by the attacker, which they enter and approve. Because every screen the employee sees is a real Salesforce page, the trust signal is Salesforce's own interface, not a spoofed one. Approval binds an attacker-controlled data-extraction application to the tenant with the employee's permissions, after which records can be pulled in bulk without any further interaction.","lessons":"Limiting the connected-app authorisation permission to a small admin group and blocking uninstalled or unapproved apps by default removes the single click that this pretext is engineered to obtain.","confidence":"Reported","sources":[{"title":"Farmers Insurance data breach impacts 1.1M people after Salesforce attack","url":"https://www.bleepingcomputer.com/news/security/farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack/","publisher":"BleepingComputer"},{"title":"Farmers Insurance Data Breach Affects 1.1 Million Customers","url":"https://www.secureworld.io/industry-news/farmers-insurance-data-breach","publisher":"SecureWorld"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million"},{"slug":"2025-adidas-customer-data-stolen-through-third-party-customer-service-provide","title":"Adidas customer data stolen through third-party customer service provider","date":"2025-05","date_precision":"month","year":2025,"victim_org":"Adidas","sector":"Retail","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.","how_it_worked":"Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.","lessons":"Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.","confidence":"Reported","sources":[{"title":"April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider","url":"https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider","publisher":"Rescana"},{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"slug":"2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ","title":"TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs","date":"2025-07-28","date_precision":"day","year":2025,"victim_org":"TransUnion","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4400000,"threat_actor":"ShinyHunters","summary":"Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.","how_it_worked":"TransUnion has described the entry point only as a third-party application serving its consumer support operations and has not publicly confirmed a social engineering pretext. Reporting places the theft in the Salesforce campaign attributed to UNC6040 and ShinyHunters, in which callers impersonating internal IT support telephone employees, cite a routine integration or troubleshooting need, and talk the target through authorising an attacker-controlled connected application inside the genuine Salesforce authorisation screen. The abused trust signal is Salesforce's own real interface combined with a plausible internal support identity; the extraction that follows is automated and needs no further human involvement.","lessons":"Restricting connected-app authorisation to a small set of administrators and alerting on any newly bound application or unusual bulk export from the CRM would have contained this class of intrusion at the moment of consent.","confidence":"Reported","sources":[{"title":"TransUnion suffers data breach impacting over 4.4 million people","url":"https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/","publisher":"BleepingComputer"},{"title":"TransUnion becomes latest victim in major wave of Salesforce-linked cyberattacks, 4.4M Americans affected","url":"https://www.foxnews.com/tech/transunion-becomes-latest-victim-major-wave-salesforce-linked-cyberattacks-4-4m-americans-affected","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ"}]}