{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:24:49.897Z","total":24,"returned":24,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee","title":"Brinks Home breached after Microsoft Entra vishing call to an employee","date":"2026-07-13","date_precision":"day","year":2026,"victim_org":"Brinks Home","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.","how_it_worked":"The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.","lessons":"Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.","confidence":"Confirmed","sources":[{"title":"ShinyHunters claims Brinks Home breach, threatens to leak stolen data","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/","publisher":"BleepingComputer"},{"title":"Salesforce Hacks 2026: Everything We Know So Far","url":"https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"},{"title":"ADT confirms breach after vishing attack on employee's Okta SSO account","date":"2026-04-20","date_precision":"day","victim_org":"ADT","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using AI voice agents in its vishing operations; AI use in the ADT call was not separately confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"ShinyHunters set an April 27, 2026 ransom deadline; no payment or loss figure was disclosed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.","how_it_worked":"An operator called an ADT employee posing as internal support and used a plausible authentication pretext to route them to a company-branded fake sign-in page. The page relayed the credentials and one-time code to the real Okta login in real time, giving the attacker a live SSO session. Because Salesforce sat behind that same single sign-on, the session opened the CRM directly, and the attackers exported customer and prospect records in bulk before ADT terminated the intrusion. Extortion followed, with a leak deadline set three days after public confirmation.","lessons":"Phishing-resistant passkeys bound to managed devices, plus export-volume alerting on the CRM, would have blocked both the credential relay and the bulk extraction.","confidence":"Confirmed","sources":[{"title":"ADT confirms data breach after ShinyHunters leak threat","url":"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/","publisher":"BleepingComputer"},{"title":"ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack","url":"https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack","publisher":"Rescana"}],"entry_type":"incident","slug":"2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account"},{"slug":"2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text","title":"Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Consumers and card issuers worldwide (Google plaintiff)","sector":"Consumer","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"Court filings and researchers cited estimates of many millions of compromised cards; no single verified loss figure was published.","records_affected":null,"threat_actor":"Smishing Triad / 'Lighthouse' phishing-as-a-service","summary":"In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.","how_it_worked":"Victims received a text claiming an unpaid road toll, a stuck parcel or a suspended account, with a short deadline and a link to a convincing replica of the relevant agency or brand. Toll authorities and postal services were chosen because almost everyone plausibly has an outstanding interaction with one, and because the sums demanded were small enough not to warrant scrutiny. The site collected card details and then, critically, the one-time passcode sent by the bank, which let the operators load the stolen card into a mobile wallet on their own phone. The kit also spoofed sender identities and rotated domains to evade filtering.","lessons":"Banks should refuse to provision cards into wallets on the strength of an SMS passcode alone, and consumers should reach toll and postal accounts only through an app or a typed-in official domain.","confidence":"Confirmed","sources":[{"title":"Google Sues to Disrupt Chinese SMS Phishing Triad","url":"https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/","publisher":"Krebs on Security"},{"title":"Google sues to dismantle Chinese phishing platform behind US toll scams","url":"https://www.bleepingcomputer.com/news/security/google-sues-to-dismantle-chinese-phishing-platform-behind-us-toll-scams/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text"},{"title":"Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds","date":"2025-10-14","date_precision":"day","victim_org":"Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign)","sector":"Consumer","country":"Cambodia","primary_vector":"Romance / Investment Scam","secondary_vectors":["Fake Job Offer / Recruitment Lure","Smishing (SMS)"],"ai_involvement":"Unknown","ai_notes":"The indictment does not attribute the schemes to AI tooling, though contemporaneous reporting on the sector describes AI-assisted personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss"],"loss_usd":15000000000,"loss_note":"Approximately 127,271 bitcoin, worth roughly $15 billion at the time, were seized in what DOJ called its largest forfeiture action ever. This is the seizure value, not a per-victim loss total.","records_affected":null,"threat_actor":"Chen Zhi and the Prince Holding Group (indicted)","summary":"On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.","how_it_worked":"Workers inside the compounds contacted strangers through messaging apps and social media using fabricated personas, opening with an apparent wrong number or a friendly cold approach. Over weeks or months they built a personal relationship, often romantic, before introducing a cryptocurrency investment opportunity backed by a fake trading platform that displayed rising balances and permitted small early withdrawals to prove legitimacy. Victims were then pressed to deposit progressively larger sums, and any attempt to withdraw triggered demands for taxes or fees. The compound operators tracked which schemes ran from which rooms and logged the profits.","lessons":"Banks and exchanges need behavioural interdiction for customers making escalating transfers to newly seen crypto addresses after prolonged online-only relationships, since the victim will defend the transaction when asked directly.","confidence":"Reported","sources":[{"title":"Chairman of Prince Group Indicted for Operating Cambodian Forced Labor Scam Compounds","url":"https://www.justice.gov/opa/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged","publisher":"U.S. Department of Justice"},{"title":"U.S. and U.K. Take Largest Action Ever Targeting Cybercriminal Networks in Southeast Asia","url":"https://home.treasury.gov/news/press-releases/sb0278","publisher":"U.S. Department of the Treasury"}],"entry_type":"campaign","slug":"2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri","year":2025,"loss_kind":"seizure","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri"},{"title":"US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud","date":"2025-09-08","date_precision":"day","victim_org":"US, European and Chinese scam victims (multi-victim campaign)","sector":"Consumer","country":"Myanmar and Cambodia","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Romance / Investment Scam","Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"The sanctions announcement does not characterise AI use in the compounds' scam operations.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":10000000000,"loss_note":"Over $10 billion in losses to Americans was cited in connection with the announcement; this is a sector-wide aggregate, not a single-incident figure.","records_affected":null,"threat_actor":"Shwe Kokko / Yatai International Holdings Group network and Cambodian casino operators","summary":"On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.","how_it_worked":"The compounds are staffed by recruitment fraud. Thousands of people are lured with fake job offers, typically advertised as customer service, translation or IT work at attractive salaries in Thailand or Cambodia, then transported across borders, held against their will and forced to run scams targeting people in the United States, Europe and China. Inside, workers follow scripted romance and investment playbooks against assigned target lists, with quotas enforced by violence. The compound model industrialises social engineering: the recruitment lure supplies the labour, and the labour supplies the volume of romance and investment approaches.","lessons":"Because the front-line operators are themselves trafficking victims, effective controls sit upstream in sanctions, telecom and payment infrastructure rather than in prosecuting individual callers.","confidence":"Confirmed","sources":[{"title":"US sanctions companies behind cyber scam centers in Cambodia, Myanmar","url":"https://therecord.media/us-sanctions-companies-southeast-asia-scam-compounds","publisher":"The Record (Recorded Future News)"},{"title":"Myanmar Military Arrests Hundreds in Raid on Thai-Border Scam Center","url":"https://www.occrp.org/en/news/myanmar-military-arrests-hundreds-in-raid-on-thai-border-scam-center","publisher":"OCCRP"}],"entry_type":"campaign","slug":"2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la"},{"title":"DOJ moves to forfeit $225M in crypto traced to pig butchering victims","date":"2025-06-18","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Romance / Investment Scam","secondary_vectors":["Smishing (SMS)","Spear Phishing (Email)","Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The forfeiture complaint focuses on the money laundering trail rather than the tooling used to create the scam personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss","Identity Theft","Data Breach"],"loss_usd":19400000,"loss_note":"Over $225 million in USDT was targeted for forfeiture. DOJ identified 434 victims, of whom 60 named victims lost a combined $19.4 million; the $19.4M figure is used here as the confirmed victim loss.","records_affected":434,"threat_actor":null,"summary":"On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.","how_it_worked":"Victims were groomed online and induced to send tether to any of 93 deposit addresses controlled by the network. The proceeds were then split across up to 100 intermediary wallets to break the trail and to blend deposits from many victims, before consolidation into 22 primary exchange accounts and 122 further accounts linked by shared IP addresses and reused know-your-customer documents. The Heartland Tri-State case shows the depth of the psychological hold: a serving bank chief executive stole from his own bank, his church, an investment club and his daughter's college fund to keep feeding the scam, and received a 24-year sentence in August 2024.","lessons":"The rule that a legitimate employer never requires an employee to deposit money to be paid is the whole control; payment providers should also flag consumer crypto purchases immediately preceding transfers to newly seen platforms.","confidence":"Confirmed","sources":[{"title":"DOJ Ties Kansas Bank Collapse to $225 Million 'Pig Butchering' Seizure","url":"https://www.coindesk.com/policy/2025/06/18/doj-ties-kansas-bank-collapse-to-225-million-pig-butchering-seizure","publisher":"CoinDesk"},{"title":"New FTC Data Show Skyrocketing Consumer Reports About Game-Like Online Job Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2024/12/new-ftc-data-show-skyrocketing-consumer-reports-about-game-online-job-scams","publisher":"Federal Trade Commission"},{"title":"FBI Releases Annual Internet Crime Report","url":"https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims"},{"title":"25 Canadians charged over $21M grandparent scam targeting seniors in 40 states","date":"2025-03-05","date_precision":"day","victim_org":"Elderly US residents in more than 40 states (multi-victim campaign)","sector":"Consumer","country":"United States and Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"The indictment describes live callers posing as grandchildren and lawyers; it does not allege voice cloning.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":21000000,"loss_note":"Over $21 million in losses, per the charging announcement.","records_affected":null,"threat_actor":"Montreal-area call center network (25 Canadian nationals charged)","summary":"On 5 March 2025 US authorities announced charges against 25 Canadian nationals over a grandparent scam run from call centers in and around Montreal that defrauded elderly people in more than 40 states of over $21 million. Twenty-three defendants were arrested on 4 March and two remained at large. Money was moved to Canada after cash pickups, sometimes through cryptocurrency, to obscure its source.","how_it_worked":"Callers phoned elderly Americans and claimed to be a grandchild who had been arrested after a car crash and needed bail money immediately. A second conspirator came on the line posing as an attorney to lend procedural credibility, and told the victim a gag order forbade discussing the case with anyone, an instruction that isolates the target from the family members who would otherwise puncture the story. The emotional lever was fear for a grandchild in custody, layered with legal authority and enforced secrecy. Collection was in person: a conspirator posing as a bail bondsman came to the victim's home to take the cash.","lessons":"A pre-agreed family code word and an absolute rule of hanging up and calling the relative back on a known number defeats this script, since the scam depends on the victim never independently verifying.","confidence":"Reported","sources":[{"title":"25 Canadian nationals connected to nationwide multi-million dollar 'grandparent scam' charged in Vermont","url":"https://www.ice.gov/news/releases/25-canadian-nationals-connected-nationwide-multi-million-dollar-grandparent-scam","publisher":"U.S. Immigration and Customs Enforcement"}],"entry_type":"campaign","slug":"2025-25-canadians-charged-over-21m-grandparent-scam-targeting-seniors-in-40-s","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-25-canadians-charged-over-21m-grandparent-scam-targeting-seniors-in-40-s"},{"title":"AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman","date":"2025-02","date_precision":"month","victim_org":"Massimo Moratti and other Italian business leaders","sector":"Consumer","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Fraudsters used an AI-generated clone of Defence Minister Guido Crosetto's voice on phone calls, alongside accomplices posing as ministry staff.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":1000000,"loss_note":"Approx EUR 1 million paid by Massimo Moratti in two transfers; funds were traced to a Dutch bank account and frozen","records_affected":null,"threat_actor":null,"summary":"In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.","how_it_worked":"The pretext was engineered for the target audience: a matter of national interest, secret by nature, in which wealthy patriots were being asked to advance funds the state would repay. Calls came first from someone presenting as a ministry official, which set the frame, and then from the minister himself in a recognisable synthetic voice, an escalation that made the request feel personally sanctioned at the highest level. The promise of Bank of Italy reimbursement reduced the perceived risk to a short-term loan. Secrecy and the lives of hostages supplied both urgency and a reason not to consult advisers, and payment was directed to a foreign account presented as an operational necessity.","lessons":"Government officials do not solicit private funds by phone; any such request should be verified with the ministry's published switchboard before any transfer, and banks should challenge large first-time international transfers from personal accounts.","confidence":"Reported","sources":[{"title":"Police recover EUR 1M sent to deepfake scammers impersonating Italy's Defense Minister","url":"https://cybernews.com/cybercrime/deepfake-scammers-dupe-italian-buinessman-1-million-police-recover-funds/","publisher":"Cybernews"},{"title":"Fraudsters Allegedly Use AI-Generated Voice of Italian Defense Minister Guido Crosetto to Scam Business Leaders","url":"https://incidentdatabase.ai/cite/927/","publisher":"AI Incident Database"},{"title":"Guido Crosetto","url":"https://en.wikipedia.org/wiki/Guido_Crosetto","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a"},{"title":"Hong Kong arrests 31 in second deepfake romance fraud ring targeting Southeast Asia","date":"2025-01","date_precision":"month","victim_org":"Victims in Taiwan, Singapore and Malaysia","sector":"Consumer","country":"Hong Kong","primary_vector":"Romance / Investment Scam","secondary_vectors":["Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The syndicate combined photographs of attractive people scraped online with deepfake technology to create and sustain fictitious personas on dating apps.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":4370000,"loss_note":"Over HK$34 million, approx US$4.37 million","records_affected":null,"threat_actor":"Hong Kong-based fraud syndicate operating from Kowloon Bay","summary":"Hong Kong police arrested 31 people on 2 and 3 January 2025 over a deepfake-enabled romance and investment fraud syndicate that operated from two premises in Kowloon Bay and took more than HK$34 million (about US$4.37 million) from victims in Taiwan, Singapore and Malaysia. Members were trained to approach targets on dating apps using online photographs of attractive people combined with deepfake technology. It was the second major deepfake fraud bust by Hong Kong authorities in three months.","how_it_worked":"Recruits worked from scripts and training materials, opening on dating apps with fabricated female personas assembled from scraped photographs and rendered live with face-swapping software when a target asked for video proof. The romance was cultivated over weeks so that the eventual investment pitch arrived from someone the victim believed they knew personally rather than from a stranger. Targets in neighbouring jurisdictions were chosen partly because cross-border reporting and recovery are slower. Funds were routed into cryptocurrency, which made reversal difficult once the persona went dark.","lessons":"Cross-border anti-fraud coordination and dating-platform detection of face-swap artefacts on live video are the two controls that materially shrink this model.","confidence":"Confirmed","sources":[{"title":"Hong Kong police arrest 31 over deepfakes used to scam victims in Singapore, Malaysia","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3293476/hong-kong-police-arrest-31-who-used-deepfakes-scam-victims-singapore-malaysia","publisher":"South China Morning Post"}],"entry_type":"campaign","slug":"2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou"},{"title":"FBI warns criminals are using generative AI to scale voice-clone and identity fraud","date":"2024-12-03","date_precision":"day","victim_org":"US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Deepfake Video Call","Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The entire advisory concerns criminal use of generative AI: AI text for phishing and fake profiles, AI images for fake IDs and personas, voice cloning to impersonate relatives and account holders, and real-time video synthesis to impersonate executives and authorities.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Extortion","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"The advisory does not publish an aggregate loss figure for AI-enabled fraud.","records_affected":null,"threat_actor":null,"summary":"On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.","how_it_worked":"Voice cloning is the pivotal technique for consumer harm. A short sample of a person's speech, readily available from social media video, is enough to synthesise a distressed relative calling to say they have been in an accident or arrested and need money immediately. The lever is the recognisable voice of a loved one under duress, which suppresses verification instincts far more effectively than any script. The same technology is used to satisfy bank voice authentication as an account holder, and real-time video synthesis extends it to live calls impersonating executives or providing proof of legitimacy to a romance or investment target. AI translation also strips the grammatical errors that once exposed foreign operators.","lessons":"The FBI's own recommendation is the practical control: agree a family or organisational verification code word in advance, and independently call back on a known number before acting on any urgent request.","confidence":"Confirmed","sources":[{"title":"Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud","url":"https://www.ic3.gov/PSA/2024/PSA241203","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide"},{"title":"Deepfake Elon Musk videos drive crypto investment scams against US consumers","date":"2024-11","date_precision":"month","victim_org":"Multiple US consumers","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Romance / Investment Scam","Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Scammers generated AI video and voice of Elon Musk pitching cryptocurrency investment schemes and distributed them as ads and posts on Facebook and TikTok.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Individual victim Heidi Swan lost over US$10,000; Deloitte estimated generative AI contributed to more than US$12 billion in US fraud losses in 2023, projected to reach US$40 billion by 2027","records_affected":null,"threat_actor":null,"summary":"By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.","how_it_worked":"The lure ran on the credibility of a single very famous investor whose views on cryptocurrency are widely known, so a video of him endorsing a platform confirmed what many targets already half-believed. Distribution through paid social advertising delivered the content inside trusted feeds and let operators target older users with disposable savings. The synthetic Musk described a limited-time opportunity with outsized returns, and the follow-through moved victims onto a bogus exchange with a support representative who coached them through funding the account. Fabricated balance growth and, in some cases, small permitted withdrawals sustained belief and encouraged larger deposits until withdrawals were blocked.","lessons":"Celebrity endorsement is never a basis for investing; platforms must verify advertiser identity and screen for synthetic likeness of public figures before ads run.","confidence":"Reported","sources":[{"title":"Deepfakes of Elon Musk are contributing to billions of dollars in fraud losses in the U.S.","url":"https://www.cbsnews.com/texas/news/deepfakes-ai-fraud-elon-musk/","publisher":"CBS News"},{"title":"Deepfake Elon Musk Videos Have Reportedly Contributed to Billions in Fraud","url":"https://incidentdatabase.ai/cite/795/","publisher":"AI Incident Database"}],"entry_type":"campaign","slug":"2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu"},{"title":"Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring","date":"2024-10","date_precision":"month","victim_org":"Men across Asia targeted through dating apps","sector":"Consumer","country":"Hong Kong","primary_vector":"Romance / Investment Scam","secondary_vectors":["Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Syndicate members used AI face-swapping to replace their own faces with those of attractive women during video calls with victims, sustaining the fiction of a relationship.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":46000000,"loss_note":"HK$360 million, approx US$46 million","records_affected":null,"threat_actor":"Hong Kong-based syndicate with reported triad links","summary":"Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.","how_it_worked":"Operators opened on dating apps with AI-generated or face-swapped profiles of attractive women and invested weeks in ordinary conversation, building an emotional bond before money was ever mentioned. Video calls were the decisive trust signal, because a target who has seen and spoken with the person on camera discounts warnings about catfishing. Once the relationship felt real, the persona introduced a cryptocurrency trading platform run by the syndicate, showing fabricated gains and letting small withdrawals succeed so the returns appeared genuine. Pressure came from a mixture of intimacy and fear of missing out, and the training documents seized by police show the manipulation was scripted, not improvised.","lessons":"Reverse-image and liveness checks on dating profiles help, but the durable control is treating any investment platform introduced by an online romantic contact as fraudulent by default.","confidence":"Confirmed","sources":[{"title":"Hong Kong fraudsters use deepfake tech to swindle love-struck men out of HK$360 million","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3282345/hong-kong-fraudsters-use-deepfake-tech-swindle-love-struck-men-out-hk360-million","publisher":"South China Morning Post"},{"title":"Police arrest 27 for deepfake love scams totaling $360m, seizes scam-training documents","url":"https://www.thestandard.com.hk/news/article/221507/Police-arrest-27-for-deepfake-love-scams-totaling-360m-seizes-scam-training-documents","publisher":"The Standard (Hong Kong)"}],"entry_type":"campaign","slug":"2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen","year":2024,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen"},{"title":"AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads","date":"2024-01","date_precision":"month","victim_org":"Multiple US consumers; brands Taylor Swift and Le Creuset impersonated","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Voice Clone / Audio Deepfake","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The ads paired authentic images of the singer with a synthesised clone of her voice; a Carnegie Mellon researcher confirmed the audio was fabricated while the photographs were genuine.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Individual victims reported paying small shipping fees and supplying card details; aggregate loss not published","records_affected":null,"threat_actor":null,"summary":"In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.","how_it_worked":"The scam borrowed two trusted identities at once, a celebrity with an unusually devoted fanbase and a premium cookware brand that plausibly runs promotions. Distribution came through paid social ads, so the content arrived inside a feed the target already trusted rather than in an unsolicited message. The cloned voice narrating a personal-sounding offer supplied the authenticity that still images alone would not, and the giveaway framing made urgency natural: a limited number of free sets meant acting immediately. The small shipping fee was the conversion step, low enough to feel harmless while capturing card data and personal details.","lessons":"Consumers should verify giveaways on the brand's own site, and ad platforms need celebrity-likeness and synthetic-voice detection in advertiser review rather than post-hoc takedown.","confidence":"Reported","sources":[{"title":"The Taylor Swift Le Creuset cookware giveaway is fake","url":"https://www.today.com/food/news/taylor-swift-le-creuset-cookware-giveaway-fake-rcna133325","publisher":"TODAY / NBC News"},{"title":"AI-generated ads using Taylor Swift's likeness dupe fans with fake Le Creuset giveaway","url":"https://cbsnews.com/news/taylor-swift-le-creuset-ai-generated-ads","publisher":"CBS News"}],"entry_type":"campaign","slug":"2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads"},{"title":"FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings","date":"2023-09-29","date_precision":"day","victim_org":"US senior citizens (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"The advisory does not describe AI-generated voice or content in this campaign.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":542000000,"loss_note":"IC3 received 19,000 tech support scam complaints between January and June 2023 with estimated victim losses over $542 million; nearly half of victims were over 60 and accounted for 66 percent of losses.","records_affected":19000,"threat_actor":null,"summary":"On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.","how_it_worked":"Phase one is a supposed technology company representative reaching the victim by call, text, email or pop-up, who obtains remote access, shows fabricated virus scan results and reviews the victim's financial accounts to find the largest balance, then warns that the institution's fraud department will be in touch. Phase two is a caller posing as that bank or brokerage saying a foreign hacker has accessed the accounts and the money must be moved to a safe government account by wire, cash or cryptocurrency, with instructions to keep it confidential. Phase three is a purported Federal Reserve or government employee, sometimes sending official-looking letterhead, who confirms the story and presses the victim to complete the transfer.","lessons":"The confidentiality instruction is the diagnostic tell; bank staff trained to treat customer secrecy plus urgent large outbound transfers as a scam indicator, and mandatory cooling-off holds, break the chain.","confidence":"Confirmed","sources":[{"title":"'Phantom Hacker' Scams Target Senior Citizens and Result in Victims Losing their Life Savings","url":"https://www.ic3.gov/PSA/2023/PSA230929","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"campaign","slug":"2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings"},{"title":"AI voice clone of teenage daughter used in Arizona virtual kidnapping attempt","date":"2023-04","date_precision":"month","victim_org":"Jennifer DeStefano, a private individual in Scottsdale, Arizona","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"The mother testified that the caller played back what sounded exactly like her 15-year-old daughter's voice, sobs and inflection included; investigators and researchers attributed this to AI voice cloning, though the sample source was never identified.","outcomes":["Attempt Blocked","Extortion"],"loss_usd":null,"loss_note":"No money was transferred","records_affected":null,"threat_actor":null,"summary":"Jennifer DeStefano of Scottsdale, Arizona received a call in which she heard what she believed was her 15-year-old daughter crying, followed by a man claiming to hold the girl and demanding a US$1 million ransom, later reduced to US$50,000 in cash. While she kept the caller talking, other parents reached her husband, who confirmed the daughter was safe at home. No money changed hands. DeStefano described the incident in written testimony to the US Senate Judiciary Committee in June 2023, and it became one of the most cited AI voice-cloning cases in US policy debate.","how_it_worked":"The pretext was the most emotionally overwhelming one available, a child in immediate physical danger, delivered by phone at a moment when the mother was away from her daughter and could not instantly verify. The cloned crying voice was the trust signal; it matched not just the timbre but the way the girl cries. The caller then applied escalating threats and refused to let her hang up or make another call, closing off exactly the verification path that would have ended the scam. Pressure was tuned by dropping the demand from US$1 million to US$50,000 cash, making compliance feel achievable, and by insisting on an in-person handover rather than a traceable wire.","lessons":"Families need a pre-agreed verbal code word and a habit of hanging up and calling the relative back on a known number before acting on any ransom or emergency call.","confidence":"Reported","sources":[{"title":"Written Statement of Jennifer DeStefano, US Senate Committee on the Judiciary","url":"https://www.judiciary.senate.gov/imo/media/doc/2023-06-13%20PM%20-%20Testimony%20-%20DeStefano.pdf","publisher":"US Senate Committee on the Judiciary"},{"title":"AI kidnapping scam targets Arizona mother","url":"https://www.fox10phoenix.com/news/ai-kidnapping-scam-targets-arizona-mother-youll-never-see-your-daughter-again","publisher":"FOX 10 Phoenix"}],"entry_type":"incident","slug":"2023-ai-voice-clone-of-teenage-daughter-used-in-arizona-virtual-kidnapping-at","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ai-voice-clone-of-teenage-daughter-used-in-arizona-virtual-kidnapping-at"},{"title":"French woman loses EUR 830,000 to an AI-image 'Brad Pitt' romance scam","date":"2023-02","date_precision":"month","victim_org":"Private individual in France (identified only as 'Anne')","sector":"Consumer","country":"France","primary_vector":"Romance / Investment Scam","secondary_vectors":[],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Scammers sent AI-generated photographs purporting to show Brad Pitt in a hospital bed, along with images of a fake passport, to sustain the impersonation across an 18-month relationship.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":857900,"loss_note":"EUR 830,000, approx US$858,000","records_affected":null,"threat_actor":"Nigerian-linked fraud network under French investigation","summary":"Beginning in February 2023, a 53-year-old French woman known publicly as Anne was drawn into an online relationship with someone posing as actor Brad Pitt. Over about 18 months she sent EUR 830,000, largely after being told he needed money for kidney cancer treatment and that his accounts were frozen by divorce proceedings. AI-generated images of the actor in hospital and a forged passport reinforced the deception. She realised she had been defrauded on seeing genuine photographs of Pitt with his partner, and filed a police complaint; the case became public in January 2025 when French broadcaster TF1 aired and then withdrew her interview.","how_it_worked":"Contact began through social media with a persona claiming to be the actor's mother, which lent credibility before the celebrity persona itself appeared. The relationship was built slowly with daily messages, declarations of love and a promise of marriage, so that by the time money was requested the target was emotionally invested rather than evaluating a proposition. AI-generated hospital photographs, tailored to each new claim, answered the natural demand for proof, and a fabricated passport addressed identity doubts. The medical emergency supplied urgency, and the story that the actor's assets were frozen in divorce explained why a wealthy man would need her money at all.","lessons":"Any claim of celebrity contact should be treated as fraudulent absent verified representation, and banks flagging repeated large outbound transfers from an unusual customer profile can interrupt the sequence.","confidence":"Reported","sources":[{"title":"Nigerian scammers accused in AI-driven fake Brad Pitt fraud","url":"https://www.france24.com/en/live-news/20250121-nigerian-scammers-accused-in-ai-driven-fake-brad-pitt-fraud","publisher":"AFP via France 24"},{"title":"AI Brad Pitt convinced a French woman to pay EUR 830K for kidney treatment","url":"https://www.ccn.com/news/technology/ai-brad-pitt-convinced-french-woman-pay-e830k/","publisher":"CCN"}],"entry_type":"incident","slug":"2023-french-woman-loses-eur-830-000-to-an-ai-image-brad-pitt-romance-scam","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-french-woman-loses-eur-830-000-to-an-ai-image-brad-pitt-romance-scam"},{"title":"Nature's Sunshine loses $4.8 million in BEC against Synergy Japan unit","date":"2023-02","date_precision":"month","victim_org":"Nature's Sunshine Products, Inc. (Synergy Japan)","sector":"Consumer","country":"Japan","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The company's filing did not describe the impersonation technique or reference AI.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4800000,"loss_note":"$4.8 million in fraudulently induced wire transfers between February 1 and February 17, 2023. Recovery amount not disclosed.","records_affected":null,"threat_actor":null,"summary":"Nature's Sunshine Products disclosed in a Form 8-K filed February 24, 2023 that a criminal scheme involving employee impersonation and fraudulent requests targeting its Synergy Japan operations produced a series of fraudulently induced wire transfers totaling $4.8 million between February 1 and February 17, 2023. The company discovered the fraud on February 17, 2023, contacted its bank and law enforcement to attempt recovery, and said it had identified no additional fraudulent activity.","how_it_worked":"The attackers focused on a foreign subsidiary, where distance from group finance, language differences and time-zone gaps weaken verification. Impersonating company personnel, they submitted payment requests over a seventeen-day window rather than a single lump sum, letting each transfer pass as an ordinary local disbursement while the cumulative total reached $4.8 million. Because the requests appeared internal and no technical compromise of company systems was reported, they moved through the subsidiary's normal approval path unchallenged. The pattern was recognized only when the cluster of transfers was reviewed together, after which the parent engaged its bank and law enforcement and reviewed controls across its international units.","lessons":"Cumulative velocity monitoring across a subsidiary's outbound payments, not just per-transaction limits, is what surfaces a drip-feed impersonation scheme before it reaches millions.","confidence":"Confirmed","sources":[{"title":"Nature's Sunshine Products, Inc. Form 8-K, Item 8.01 (filed February 24, 2023)","url":"https://www.sec.gov/Archives/edgar/data/275053/000027505323000003/natr-20230217.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2023-nature-s-sunshine-loses-4-8-million-in-bec-against-synergy-japan-unit","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-nature-s-sunshine-loses-4-8-million-in-bec-against-synergy-japan-unit"},{"title":"FTC: business and government impersonation scams hit $1.1 billion in 2023","date":"2023","date_precision":"year","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Callback Phishing (TOAD)"],"ai_involvement":"Unknown","ai_notes":"The 2024 data spotlight does not break out AI-enabled impersonation.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft","Identity Theft"],"loss_usd":1100000000,"loss_note":"$1.1 billion in combined reported losses to business and government impersonation scams in 2023, more than triple the $310 million reported in 2020. Over 330,000 business impersonation reports and nearly 160,000 government impersonation reports, together about 48 percent of fraud reports made directly to the FTC.","records_affected":490000,"threat_actor":null,"summary":"An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.","how_it_worked":"The dominant openers are bogus account security alerts purporting to come from a company such as Amazon or from a bank, claiming unauthorised activity and steering the victim toward transferring funds or feeding cash into a Bitcoin ATM to protect their money. A second pattern is the fake subscription renewal notice, often impersonating Geek Squad, which offers a refund and then coerces the victim into buying gift cards and reading out the numbers. The most damaging innovation is the multi-agency handoff: scammers who begin as a business then transfer the victim to a fake bank representative, FBI agent or even a purported FTC employee, so that each successive persona corroborates the last.","lessons":"No government agency or legitimate business asks anyone to move money to protect it or to pay in gift cards or Bitcoin ATM deposits; retailer and ATM operator interdiction prompts at the point of payment are the strongest late-stage control.","confidence":"Confirmed","sources":[{"title":"Impersonation scams: not what they used to be","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2024/04/impersonation-scams-not-what-they-used-be","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023"},{"title":"FTC data: $147.8M in gift card fraud driven by government and business impersonators","date":"2021-12-08","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam","Romance / Investment Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement described.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":147800000,"loss_note":"$147.8 million reported lost across 39,263 gift card fraud reports in the first nine months of 2021. Government impersonation accounted for 7,844 reports and $39.6 million; business impersonation for 12,239 reports and $35.5 million.","records_affected":39263,"threat_actor":null,"summary":"An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.","how_it_worked":"A caller impersonating the Social Security Administration, another government agency, or a business such as Amazon or Apple tells the victim that money is owed or that an account has been compromised, and instructs them to resolve it immediately by buying gift cards at a nearby retailer. The victim is kept on the phone throughout the drive and the purchase, which prevents consultation with anyone and lets the scammer coach them past cashier questions with a cover story about buying gifts. At the register the victim reads the card numbers and PINs aloud over the phone, and the value is drained within minutes. Gift cards are attractive because they are irreversible and untraceable.","lessons":"Retail checkout interdiction, where staff are trained and empowered to stop high-value gift card purchases by customers on the phone, is the single highest-yield control at the point of loss.","confidence":"Confirmed","sources":[{"title":"Scammers prefer gift cards, but not just any card will do","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2021/12/scammers-prefer-gift-cards-not-just-any-card-will-do","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp","year":2021,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp"},{"title":"Virtual kidnapping ring extorts parents with staged ransom calls","date":"2018-09-20","date_precision":"day","victim_org":"Parents in Texas, California and Idaho (multi-victim campaign)","sector":"Consumer","country":"United States and Mexico","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"The scheme used pre-recorded gasping audio and live callers, not synthetic voice.","outcomes":["Extortion","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The Justice Department did not publish a total loss figure for this prosecution.","records_affected":null,"threat_actor":"Yanette Rodriguez Acosta and Mexico-based co-conspirators (convicted)","summary":"On 20 September 2018 Yanette Rodriguez Acosta of Houston was sentenced to 88 months in federal prison for conspiracy to commit wire fraud and money laundering in a virtual kidnapping extortion scheme. Co-conspirators in Mexico called victims in Texas, California and Idaho falsely claiming to have kidnapped their children and demanding ransom. The sentencing judge said the defendant showed gleeful disregard for victims while inflicting pain, fear and long-term effects for profit.","how_it_worked":"The call opened with recorded audio of a child gasping and saying mom or dad. When the parent reacted by calling out their child's name, the caller seized that name and used it for the rest of the call, manufacturing proof of possession without knowing anything about the family. Threats of violence followed, and the parent was kept on the phone continuously for hours while driving to banks and wire transfer offices, a tactic that prevents any call to the child's school or mobile phone. In one case a couple searched nearby dumpsters for their child's body. No actual abduction ever occurred.","lessons":"The single control is refusing to stay on the line: any ransom call should be met by a second person immediately calling the supposed victim on another phone, which collapses the pretext in seconds.","confidence":"Confirmed","sources":[{"title":"Texas Woman Sentenced in Virtual Kidnapping Extortion Scheme","url":"https://www.justice.gov/usao-sdtx/pr/texas-woman-sentenced-virtual-kidnapping-extortion-scheme","publisher":"U.S. Department of Justice"}],"entry_type":"campaign","slug":"2018-virtual-kidnapping-ring-extorts-parents-with-staged-ransom-calls","year":2018,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-virtual-kidnapping-ring-extorts-parents-with-staged-ransom-calls"},{"title":"India-based IRS and USCIS impersonation call centers: 24 defendants sentenced","date":"2018-07-20","date_precision":"day","victim_org":"US consumers, many of them elderly (multi-victim campaign)","sector":"Consumer","country":"United States and India","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the calls were made by live scripted operators.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":8970396,"loss_note":"Restitution of $8,970,396 was ordered for identified victims across 22 defendants, with money judgments exceeding $72.9 million; defendants were held liable for laundering between $3.5 million and $25 million collectively.","records_affected":null,"threat_actor":"Ahmedabad-based call center network and US-based runner network","summary":"On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.","how_it_worked":"Operators in Ahmedabad called Americans, many of them elderly or recent immigrants, and identified themselves as IRS or USCIS officials. They asserted that back taxes were owed or that an immigration status problem had been found, and threatened immediate arrest, imprisonment, fines or deportation unless payment was made at once. The lever was raw state authority plus a deliberately compressed timeline that prevented the victim from consulting family or a lawyer. Payment was demanded in stored value cards or wire transfers, and US-based runners then liquidated the cards, bought money orders and collected wires under false identities to launder the proceeds.","lessons":"Public education that tax and immigration agencies never demand payment by gift card or threaten immediate arrest by phone, combined with retailer prompts at gift card checkout, directly disrupts this model.","confidence":"Confirmed","sources":[{"title":"24 Defendants Sentenced in Multimillion Dollar India-Based Call Center Scam Targeting U.S. Victims","url":"https://www.justice.gov/archives/opa/pr/24-defendants-sentenced-multimillion-dollar-india-based-call-center-scam-targeting-us-victims","publisher":"U.S. Department of Justice"}],"entry_type":"campaign","slug":"2018-india-based-irs-and-uscis-impersonation-call-centers-24-defendants-sente","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-india-based-irs-and-uscis-impersonation-call-centers-24-defendants-sente"},{"title":"Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups","date":"2017-05-12","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Callback Phishing (TOAD)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the era predates generative tooling in this scam type.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The FTC stated consumers paid millions of dollars but published no single campaign total. Individual matters included a $27 million default judgment and $1.3 million in forfeited assets.","records_affected":null,"threat_actor":"Repair All PC LLC, Troth Solutions, Vylah Tec, Universal Network Solutions, Click4Support, BigDog Solutions, First Choice Tech Support and others","summary":"On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.","how_it_worked":"Consumers browsing the web were served pop-up advertisements built to mimic genuine security alerts from Microsoft, Apple and other technology companies, warning that the machine was infected or being hacked and instructing the user to call a toll-free number. Telemarketers answering those calls claimed to represent the impersonated vendor, talked the victim into installing remote access software, and ran theatrical fake diagnostic tests that displayed ordinary system logs as evidence of infection. Having manufactured alarm and demonstrated apparent expertise, they sold hundreds of dollars of unnecessary repairs, software and multi-year service plans.","lessons":"Browser and OS vendors blocking full-screen dialog abuse, plus the simple consumer rule that no legitimate vendor puts a support phone number in a security warning, removes the entry point.","confidence":"Confirmed","sources":[{"title":"FTC and Federal, State and International Partners Announce Major Crackdown on Tech Support Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2017/05/ftc-federal-state-international-partners-announce-major-crackdown-tech-support-scams","publisher":"Federal Trade Commission"}],"entry_type":"campaign","slug":"2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support"},{"title":"Mattel wires $3 million to Chinese account in CEO impersonation scam, recovers it","date":"2015-04-30","date_precision":"day","victim_org":"Mattel, Inc.","sector":"Consumer","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":3000000,"loss_note":"$3 million transferred and subsequently recovered in full after Chinese authorities froze the receiving account.","records_affected":null,"threat_actor":null,"summary":"On April 30, 2015 a Mattel finance executive wired $3 million to a bank in Wenzhou, China after receiving an email purporting to come from newly appointed chief executive Christopher Sinclair. The fraud was recognized the same day. Because May 1 was a banking holiday in China, Mattel was able to work with U.S. and Chinese law enforcement and the receiving bank to freeze the account, and the funds were returned within days.","how_it_worked":"The attackers studied Mattel's payment approval rule, which required sign-off from two senior managers, and timed their approach to a leadership transition when a new CEO's email habits were unfamiliar. They sent a spoofed request from the incoming chief executive asking for a vendor payment to a new supplier in China, framed as routine business expansion. The finance executive believed the request satisfied the two-approver rule because the CEO himself appeared to be one of the approvers. Only afterward, when she mentioned it to Sinclair, was the fraud exposed. A Chinese public holiday delayed onward movement of the money long enough for law enforcement to freeze it.","lessons":"Approval rules must count only independently verified approvers; a request that supplies its own authorization by email is not dual control, and new-vendor payments deserve a mandatory verification step.","confidence":"Confirmed","sources":[{"title":"Chinese scammers take Mattel to the bank, phishing them for $3 million","url":"https://www.csoonline.com/article/555513/chinese-scammers-take-mattel-to-the-bank-phishing-them-for-3-million.html","publisher":"CSO Online"}],"entry_type":"incident","slug":"2015-mattel-wires-3-million-to-chinese-account-in-ceo-impersonation-scam-reco","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-mattel-wires-3-million-to-chinese-account-in-ceo-impersonation-scam-reco"},{"title":"Celebrity iCloud photo theft: 600 victims phished with fake Apple and Google emails","date":"2014-09","date_precision":"month","victim_org":"Celebrities and private individuals with Apple iCloud and Google accounts","sector":"Consumer","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement.","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_note":"No monetary loss figure was published; harm was the public leak of private photographs.","records_affected":600,"threat_actor":"Ryan Collins (convicted)","summary":"The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.","how_it_worked":"Collins sent messages that mimicked Apple and Google account security notices, using the vendors' visual conventions and a plausible security pretext to make responding feel like protecting the account rather than surrendering it. Victims replied with, or entered, their account usernames and passwords. Collins then signed in directly and downloaded the full contents of iCloud backups, which on Apple devices at that time included the entire camera roll and message history. No platform vulnerability was exploited; the whole compromise rested on the victim voluntarily supplying credentials to a convincing imitation of the provider.","lessons":"Mandatory two-factor authentication on consumer cloud backup accounts, and provider policies that never request passwords by email, would have neutralised the harvested credentials.","confidence":"Confirmed","sources":[{"title":"Pennsylvania Man Sentenced to 18 Months in Federal Prison for Hacking Apple and Google E-Mail Accounts","url":"https://www.justice.gov/usao-cdca/pr/pennsylvania-man-sentenced-today-18-months-federal-prison-hacking-apple-and-google-e","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2014-celebrity-icloud-photo-theft-600-victims-phished-with-fake-apple-and-goo","year":2014,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-celebrity-icloud-photo-theft-600-victims-phished-with-fake-apple-and-goo"}]}