{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:36.895Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Epsilon email marketing breach exposes address lists of banks and retailers","date":"2011-04","date_precision":"month","victim_org":"Epsilon Data Management and other email service providers","sector":"Professional Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":2000000,"loss_note":"The indictment alleged the defendants generated over $2 million from spam campaigns promoting counterfeit software using the stolen lists; downstream costs to the affected brands were not quantified.","records_affected":1000000000,"threat_actor":"Viet Quoc Nguyen, Giang Hoang Vu and David-Manuel Santos Da Silva (indicted March 2015)","summary":"In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.","how_it_worked":"The lead defendant sent targeted phishing emails to employees of email service providers. The messages carried links to sites built to exploit browser vulnerabilities and silently install malware, giving backdoor access to employee workstations and, from there, harvested access credentials for the marketing platforms. With those credentials he bulk-downloaded subscriber lists to a server he controlled in the Netherlands. Because the stolen records paired real names with the specific brands each person banked or shopped with, they were unusually valuable for follow-on spear phishing against consumers.","lessons":"Marketing platforms holding client subscriber lists need bulk-export alerting and least-privilege segregation, so one phished employee workstation cannot pull the entire customer database.","confidence":"Confirmed","sources":[{"title":"Feds Indict Three in 2011 Epsilon Hack","url":"https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail","year":2011,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail"}]}