{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:29:40.999Z","total":31,"returned":31,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Kraken refuses extortion after two support insiders accessed client data","date":"2026-04-13","date_precision":"day","victim_org":"Kraken","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported in this case.","outcomes":["Extortion","Insider Access","Attempt Blocked"],"loss_usd":null,"loss_note":"Kraken refused to pay and reported no funds at risk; no loss figure disclosed.","records_affected":2000,"threat_actor":null,"summary":"CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.","how_it_worked":"The route in was people, not software. Criminals worked through members of Kraken's own customer support team to reach client support data, mirroring the bribery-of-support-agents pattern seen at Coinbase a year earlier. The stolen material was then repackaged as leverage: the extortionists produced video framed to look like live access to Kraken's internal systems and demanded payment to suppress it. Kraken said its systems were never breached and that the access was terminated, controls tightened, affected clients notified, and law enforcement engaged, with sufficient evidence to identify those responsible.","lessons":"Scoped, justification-based access in support consoles plus insider-risk monitoring limits both what an insider can reach and how long it goes unnoticed.","confidence":"Confirmed","sources":[{"title":"Crypto exchange Kraken targeted in extortion attempt, but says there was no breach and no client funds at risk","url":"https://www.coindesk.com/business/2026/04/13/crypto-exchange-kraken-targeted-in-extortion-attempt-but-says-there-was-no-breach-and-no-client-funds-at-risk","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data"},{"title":"Six-month DPRK social engineering operation preceded $285M Drift Protocol theft","date":"2026-04-01","date_precision":"day","victim_org":"Drift Protocol","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Physical Pretexting","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.","outcomes":["Cryptocurrency Theft"],"loss_usd":285000000,"loss_note":"USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.","records_affected":null,"threat_actor":"UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence","summary":"Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.","how_it_worked":"This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.","lessons":"Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.","confidence":"Reported","sources":[{"title":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","publisher":"The Hacker News"},{"title":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks","publisher":"TRM Labs"}],"entry_type":"incident","slug":"2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol","year":2026,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"},{"title":"Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware","date":"2026-02","date_precision":"month","victim_org":"An unnamed cryptocurrency company executive","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Deepfake Video Call","secondary_vectors":["Tech Support Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.","records_affected":null,"threat_actor":"UNC1069 (DPRK), tracked by Mandiant since 2018","summary":"Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.","how_it_worked":"Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.","lessons":"No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.","confidence":"Confirmed","sources":[{"title":"North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam","url":"https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix","publisher":"The Record (Recorded Future News)"},{"title":"North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms","url":"https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"},{"slug":"2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering","title":"$282M in Bitcoin and Litecoin stolen from a holder via social engineering","date":"2026-01-10","date_precision":"day","year":2026,"victim_org":"Unnamed cryptocurrency holder","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Cryptocurrency Theft"],"loss_usd":282000000,"loss_kind":"direct_loss","loss_note":"USD value at time of theft of 1,459 BTC and 2.05 million LTC; no recovery reported.","records_affected":null,"threat_actor":null,"summary":"On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.","how_it_worked":"Reporting characterised the theft as a support-impersonation social engineering attack of the kind that has become the dominant loss driver in crypto: the attacker poses as an employee of a wallet or exchange provider, builds trust with the holder, and persuades them to hand over a seed phrase, sign a malicious transaction or surrender login details. The theft came days after hardware-wallet maker Ledger disclosed a breach exposing customer names and contact details, the kind of list that makes such calls credible. The victim has not been identified and the exact pretext was not published.","lessons":"No legitimate wallet or exchange support agent ever needs a seed phrase or a remote-access session; large holdings belong behind multi-signature approval with an out-of-band co-signer.","confidence":"Reported","sources":[{"title":"Hacker steals $282 million crypto from a victim in social-engineering attack","url":"https://www.coindesk.com/business/2026/01/16/hacker-steals-usd282-milion-in-hardware-wallet-social-engineering-attack","publisher":"CoinDesk"},{"title":"Crypto User Loses $282 Million in Bitcoin and Litecoin to Social Engineering Scam","url":"https://bravenewcoin.com/insights/crypto-user-loses-282-million-in-bitcoin-and-litecoin-to-social-engineering-scam","publisher":"Brave New Coin"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"},{"slug":"2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing","title":"Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Cryptocurrency holders and companies targeted by the group","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft","Identity Theft"],"loss_usd":13000000,"loss_kind":"direct_loss","loss_note":"About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.","records_affected":null,"threat_actor":"Scattered Spider","summary":"A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.","how_it_worked":"The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.","lessons":"Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.","confidence":"Confirmed","sources":[{"title":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years","url":"https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/","publisher":"Krebs on Security"},{"title":"Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution","url":"https://therecord.media/scattered-spider-affiliate-sentenced-10-years","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"},{"slug":"2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished","title":"Crypto exchange WOO X loses $14 million after staff member phished","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"WOO X","sector":"Cryptocurrency","country":"Taiwan","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Service Disruption"],"loss_usd":14000000,"loss_kind":"direct_loss","loss_note":"Approximately $14 million in customer assets drained; WOO X said it would cover affected user balances from its own reserves.","records_affected":null,"threat_actor":null,"summary":"Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.","how_it_worked":"A single employee was targeted with a phishing lure that led to compromise of their machine and working credentials. From that foothold the attacker reached WOO X's development environment, which retained the ability to influence production withdrawal handling, and submitted malicious withdrawal requests that the platform processed as legitimate. The trust signal abused was the internal provenance of the requests: they came from an authenticated staff context inside the company's own tooling, so they did not look like an external attack. No exchange smart contract was exploited; the entire chain rested on one person being deceived into an action on their own device.","lessons":"Separating development environments from anything that can move production funds, and requiring multi-party approval for withdrawals above a threshold, would have contained the compromised endpoint.","confidence":"Confirmed","sources":[{"title":"July 24th - Security incident post-mortem","url":"https://woox.io/blog/july-24th-security-incident-post-mortem","publisher":"WOO X"},{"title":"Crypto Exchange WOO X Loses $14M After Team Member Falls for Phishing Attack","url":"https://cryptonews.com/news/crypto-exchange-woo-x-loses-14m-after-team-member-falls-for-phishing-attack/","publisher":"Cryptonews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished"},{"title":"BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware","date":"2025-06","date_precision":"month","victim_org":"Employee of a cryptocurrency foundation (Web3 sector)","sector":"Cryptocurrency","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.","outcomes":["Cryptocurrency Theft","Credential Theft","Espionage"],"loss_usd":null,"loss_note":"Amount stolen not disclosed","records_affected":null,"threat_actor":"BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)","summary":"In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.","how_it_worked":"The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.","lessons":"Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.","confidence":"Confirmed","sources":[{"title":"North Korean hackers deepfake execs in Zoom call to spread Mac malware","url":"https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/","publisher":"BleepingComputer"},{"title":"BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware","url":"https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"},{"title":"Bribed overseas support agents leaked Coinbase data; $20M extortion refused","date":"2025-05-15","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in Coinbase's disclosure.","outcomes":["Data Breach","Extortion","Insider Access","Cryptocurrency Theft","Identity Theft"],"loss_usd":null,"loss_note":"Coinbase refused the $20 million demand and instead established a $20 million reward fund for information leading to arrests. Aggregate customer losses from the resulting social engineering were not quantified in the disclosure.","records_affected":69461,"threat_actor":"Unattributed extortion group","summary":"Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.","how_it_worked":"The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.","lessons":"Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.","confidence":"Confirmed","sources":[{"title":"Protecting Our Customers - Standing Up to Extortionists","url":"https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists","publisher":"Coinbase"},{"title":"Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails","url":"https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html","publisher":"The Hacker News"},{"title":"Coinbase confirms insiders handed over data of 70K users","url":"https://www.theregister.com/2025/05/21/coinbase_confirms_insider_breach_affects/","publisher":"The Register"}],"entry_type":"incident","slug":"2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse"},{"title":"Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft","date":"2025-05-08","date_precision":"day","victim_org":"BitoPro","sector":"Cryptocurrency","country":"Taiwan","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":11500000,"loss_note":"About $11.5 million in suspicious withdrawals, disclosed publicly on June 3, 2025. BitoPro said reserves were sufficient and user functions were unaffected.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), attributed by BitoPro","summary":"Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.","how_it_worked":"BitoPro described the entry point only as social engineering against a cloud operations employee and did not disclose the specific channel or pretext used; the vector is recorded here as targeted phishing on that basis and the channel remains unconfirmed. Malware planted on the employee's device let the attackers hijack AWS session tokens, which sidestepped multi-factor authentication entirely because a live session had already satisfied it. Holding valid session tokens, they took control of BitoPro's cloud infrastructure and used their command server to inject scripts into the hot wallet system while a scheduled wallet upgrade and asset transfer was in progress. The malicious withdrawals were timed and shaped to mimic the legitimate migration traffic around them.","lessons":"Binding cloud session tokens to device posture and network origin, so a stolen token is unusable elsewhere, plus freezing automated wallet operations during manual migrations, would have denied both halves of this attack.","confidence":"Reported","sources":[{"title":"BitoPro exchange links Lazarus hackers to $11 million crypto heist","url":"https://www.bleepingcomputer.com/news/security/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/","publisher":"BleepingComputer"},{"title":"Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hack","url":"https://fortune.com/crypto/2025/06/03/taiwanese-crypto-exchange-bitopro-confirms-hack/","publisher":"Fortune"}],"entry_type":"incident","slug":"2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef"},{"title":"Kraken advanced a North Korean fake job applicant to unmask his tradecraft","date":"2025-05","date_precision":"month","victim_org":"Kraken (Payward, Inc.)","sector":"Cryptocurrency","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"Kraken reported the candidate's primary ID appeared altered, likely using details from an identity theft case two years earlier, and that he switched between voices during interviews in a way consistent with real-time coaching. Kraken did not attribute either to AI.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss. The candidate was never hired; Kraken advanced him through the process deliberately to collect intelligence.","records_affected":null,"threat_actor":"DPRK-linked fake IT worker network","summary":"Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.","how_it_worked":"The infiltration relied on the fact that remote hiring verifies documents and video, not people. The candidate presented a resume and a government ID built from a stolen identity, joined interviews from remote colocated Mac desktops routed through VPNs to mask his real location and network, and appeared to be coached in real time, which produced audible shifts between voices. Kraken's team, already holding a partner-supplied list of email addresses tied to the group, matched his application address and let the process continue. In the final round Chief Security Officer Nick Percoco ran trap identity verification: asking him to confirm his location live, hold up his government ID, and recommend restaurants in the city he claimed to live in. He could not answer questions about his own city or citizenship.","lessons":"Unscripted, locality-specific live verification during a video interview, cross-checked against threat-intel lists of known applicant identifiers, catches what document checks and reference calls cannot.","confidence":"Confirmed","sources":[{"title":"How we identified a North Korean hacker who tried to get a job at Kraken","url":"https://blog.kraken.com/news/how-we-identified-a-north-korean-hacker","publisher":"Kraken"},{"title":"Kraken tells how it spotted North Korean hacker in job interview","url":"https://cointelegraph.com/news/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra"},{"title":"Binance and Kraken block bribery attempts aimed at support staff","date":"2025-05","date_precision":"month","victim_org":"Binance and Kraken","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"Contact was made over Telegram; no AI-generated media was reported.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No losses; both attempts were stopped before any customer data was exposed.","records_affected":null,"threat_actor":null,"summary":"In the weeks around the Coinbase insider breach, the same style of attack was attempted against Binance and Kraken. Bloomberg-sourced reporting said threat actors approached customer support staff at both exchanges over Telegram and offered bribes for system access and customer data. Both exchanges detected and blocked the approaches, and neither reported any user data exposure.","how_it_worked":"Attackers contacted individual support agents directly on Telegram, offering cryptocurrency payment and supplying step-by-step instructions on how to retrieve and exfiltrate customer records, evade internal monitoring, and receive payment. The pitch targeted people rather than systems, on the assumption that a support agent with broad record access is cheaper to buy than a vulnerability is to find. Binance's monitoring flagged the suspicious communication patterns, including bribe-related keywords and outbound Telegram contact attempts, while both exchanges relied on data-access policies tightened in late 2024 to limit what any single agent could pull.","lessons":"Access limits that make a single agent's data reach small, plus monitoring for recruitment-style contact and anomalous record retrieval, turn insider bribery into a detected event rather than a breach.","confidence":"Reported","sources":[{"title":"Social Engineering Plot Foiled at Binance and Kraken After Coinbase Breach Fallout","url":"https://yellow.com/news/social-engineering-plot-foiled-at-binance-and-kraken-after-coinbase-breach-fallout","publisher":"Yellow"}],"entry_type":"incident","slug":"2025-binance-and-kraken-block-bribery-attempts-aimed-at-support-staff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-binance-and-kraken-block-bribery-attempts-aimed-at-support-staff"},{"title":"'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders","date":"2025-03","date_precision":"month","victim_org":"Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully","sector":"Cryptocurrency","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The campaign used roughly 30 sock-puppet social media accounts and fabricated company websites; no confirmed use of AI-generated media was reported in the analyses reviewed.","outcomes":["Cryptocurrency Theft","Credential Theft"],"loss_usd":null,"loss_note":"Security Alliance's incident log attributes millions of dollars of stolen funds to the group. No single confirmed per-victim figure was published in the reporting reviewed.","records_affected":null,"threat_actor":"Elusive Comet, tracked by the Security Alliance and assessed as North Korea-linked","summary":"From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.","how_it_worked":"The lure was flattery with a business rationale: an investment conversation or an invitation onto a podcast, backed by around thirty sock-puppet accounts and fabricated corporate websites so that a quick check appeared to confirm the entity. On the call the attacker asked to screen share, then requested remote control. The critical trick was renaming their Zoom display name to 'Zoom' so that the permission prompt read as though it came from the application itself rather than from another participant. A victim clicking approve on what looked like a system dialog handed over interactive control of their machine, at which point infostealers or remote access trojans were installed and wallet material harvested. Tell-tale signs included consumer Zoom accounts used by supposed Bloomberg staff.","lessons":"Disabling Zoom remote control at the account level, and treating any unsolicited investor or media approach that moves to screen control as hostile, removes the single click this campaign depends on.","confidence":"Reported","sources":[{"title":"'Elusive Comet' Attackers Use Zoom to Swindle Victims","url":"https://www.darkreading.com/remote-workforce/elusive-comet-zoom-victims","publisher":"Dark Reading"},{"title":"North Korean Cryptocurrency Thieves Caught Hijacking Zoom 'Remote Control' Feature","url":"https://www.securityweek.com/north-korean-cryptocurrency-thieves-caught-hijacking-zoom-remote-control-feature/","publisher":"SecurityWeek"}],"entry_type":"campaign","slug":"2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders"},{"title":"Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI","date":"2025-02-21","date_precision":"day","victim_org":"Bybit","sector":"Cryptocurrency","country":"United Arab Emirates","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":1500000000,"loss_note":"Approximately 401,000 ETH and stETH, valued between roughly $1.4 billion and $1.5 billion at the time depending on the analysis. It is the largest cryptocurrency theft on record.","records_affected":null,"threat_actor":"Lazarus Group / TraderTraitor (DPRK)","summary":"On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.","how_it_worked":"The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.","lessons":"Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.","confidence":"Confirmed","sources":[{"title":"Lazarus hacked Bybit via breached Safe{Wallet} developer machine","url":"https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/","publisher":"BleepingComputer"},{"title":"In-Depth Technical Analysis of the Bybit Hack","url":"https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/","publisher":"NCC Group"},{"title":"Sygnia's Investigation into the Bybit Hack: What We Know So Far","url":"https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/","publisher":"Sygnia"},{"title":"Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B Hack","url":"https://www.coindesk.com/business/2025/02/26/bybit-and-safe-custody-blame-each-other-over-usd1-5b-hack","publisher":"CoinDesk"},{"title":"How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist","url":"https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa"},{"title":"DPRK actor posing as a former contractor took $50M from Radiant Capital","date":"2024-10","date_precision":"month","victim_org":"Radiant Capital","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported; the impersonation relied on a spoofed contractor domain and an existing working relationship.","outcomes":["Cryptocurrency Theft"],"loss_usd":50000000,"loss_note":"Approximately $50 million, with stolen funds moved on October 24, 2024. Radiant Capital later wound down operations.","records_affected":null,"threat_actor":"UNC4736 / Citrine Sleet (DPRK-nexus), assessed with high confidence by Mandiant","summary":"Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.","how_it_worked":"The pretext worked because the sender was someone the team already knew and the ask, review this document, was ordinary. The ZIP contained a decoy PDF that opened normally while a macOS backdoor installed behind it, and because the developer forwarded the file to colleagues for their input, the compromise multiplied across the signer group. With malware on multiple developer machines, the attackers manipulated what those machines displayed: front-end interfaces and simulation tools such as Tenderly showed benign transaction data while malicious transactions were being signed underneath. Radiant noted that traditional checks and simulations showed no obvious discrepancies, so the review process that should have caught the theft confirmed it instead.","lessons":"Signing must happen on dedicated, hardened devices that do nothing else, with the transaction independently verified on separate hardware, because once the reviewer's endpoint is compromised, on-screen verification is worthless.","confidence":"Reported","sources":[{"title":"Radiant Capital says North Korea posed as ex-contractor to carry out $50M hack","url":"https://cointelegraph.com/news/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack","publisher":"Cointelegraph"},{"title":"Radiant Capital Says DPRK Actor Posed as Ex-Contractor to Pull Off $50 Million Hack","url":"https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack","publisher":"Decrypt"}],"entry_type":"incident","slug":"2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital"},{"title":"Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin","date":"2024-08-19","date_precision":"day","victim_org":"An individual Genesis creditor in Washington, D.C.","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning or synthetic media was reported; the callers used spoofed caller ID and live pretexting.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss"],"loss_usd":243000000,"loss_note":"4,064 BTC, worth approximately $243 million at the time. More than $9 million was subsequently frozen and about $500,000 returned to the victim.","records_affected":null,"threat_actor":"Malone Lam ('Greavys'), Jeandiel Serrano ('VersaceGod') and co-conspirators","summary":"On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.","how_it_worked":"The crew opened with a spoofed call presenting as Google support warning of unauthorised account access, which established urgency and a reason for the victim to accept further contact. A second set of callers then posed as Gemini support and walked the victim through resetting the two-factor authentication on the exchange account. Under the guise of remediation, they had the victim install AnyDesk and share their screen, at which point the attackers were able to see private keys held in the victim's Bitcoin Core wallet and to direct transfers to a wallet they controlled. Funds were then split across many wallets and pushed through more than fifteen exchanges. The crew's spending on cars, watches and designer goods exposed an address that let investigators freeze over $9 million.","lessons":"No legitimate provider initiates a call asking you to reset MFA or install remote-desktop software; hanging up and calling back on a number obtained independently is the single control that defeats this entire sequence.","confidence":"Reported","sources":[{"title":"Police Arrest Two People Related to $243M Crypto Heist Targeting Genesis Creditor","url":"https://www.coindesk.com/business/2024/09/19/police-arrests-two-people-related-to-243m-crypto-heist-targeting-genesis-creditor","publisher":"CoinDesk"},{"title":"Hackers Posed as Google Support to Steal $243 Million in Crypto","url":"https://hackread.com/hackers-posed-google-support-steal-243m-crypto/","publisher":"Hackread"}],"entry_type":"incident","slug":"2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit"},{"title":"WazirX signers approved a spoofed transaction and lost $235M","date":"2024-07-18","date_precision":"day","victim_org":"WazirX","sector":"Cryptocurrency","country":"India","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":234900000,"loss_note":"Approximately $234.9 million in ETH and ERC-20 tokens at the value on July 18, 2024. WazirX and custody provider Liminal publicly disagreed over which side's systems were compromised.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), per multiple third-party analyses","summary":"Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.","how_it_worked":"The signers were the target, and the deception was in what their screens showed them. Analyses of the incident found a discrepancy between how the transaction was rendered in the Liminal custody interface and the actual payload being signed: signers reviewed what appeared to be a routine, whitelisted transfer while the underlying data authorised a malicious contract upgrade. Three WazirX signers and the Liminal signer approved it, satisfying the four-of-six threshold. Because the approval was cryptographically valid, address whitelisting, hardware wallet storage and the multisig scheme itself all passed cleanly, and the attacker gained control to drain the remaining balance without needing any further key.","lessons":"Signers need to verify transaction payloads on an independent, out-of-band device that renders the raw calldata, since any control that trusts the same interface the attacker can influence provides no assurance at all.","confidence":"Reported","sources":[{"title":"2024 WazirX hack","url":"https://en.wikipedia.org/wiki/2024_WazirX_hack","publisher":"Wikipedia"},{"title":"Explained: The WazirX Hack (July 2024)","url":"https://www.halborn.com/blog/post/explained-the-wazirx-hack-july-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m"},{"title":"LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft","date":"2024-05","date_precision":"month","victim_org":"DMM Bitcoin, via wallet software vendor Ginco","sector":"Cryptocurrency","country":"Japan","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in the joint FBI, DC3 and NPA advisory.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":308000000,"loss_note":"4,502.9 BTC, valued at approximately $308 million in the joint FBI/DC3/NPA advisory; Japanese reporting at the time cited roughly $305 million. DMM Bitcoin subsequently wound down, transferring assets to SBI VC Trade.","records_affected":null,"threat_actor":"TraderTraitor (DPRK), per FBI, DC3 and Japan's National Police Agency","summary":"Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.","how_it_worked":"The recruiter pretext delivered a malicious Python script hosted on GitHub, framed as a pre-employment coding assessment. The Ginco employee copied the script into their own GitHub account to work on it, which handed the attacker access to session cookie data. Using those session cookies the attacker impersonated the employee and compromised Ginco's unencrypted internal communications system. From there they waited: in late May a DMM Bitcoin employee submitted a legitimate transaction request through Ginco's system, and the attacker altered it in flight so that the withdrawal, which carried valid authorisation from DMM's side, sent 4,502.9 BTC to attacker-controlled addresses.","lessons":"Take-home coding tasks must be isolated from corporate identity and never touched by an account with production session access, and transaction requests should be verified against an independent channel between exchange and custody vendor before signing.","confidence":"Confirmed","sources":[{"title":"FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com","url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom","publisher":"Federal Bureau of Investigation"},{"title":"FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin","url":"https://cryptoslate.com/fbi-reveals-north-korea-used-linkedin-to-steal-305-million-from-japans-dmm-bitcoin/","publisher":"CryptoSlate"}],"entry_type":"incident","slug":"2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t"},{"title":"Munchables loses $62.5M to a developer it hired who was linked to North Korea","date":"2024-03-26","date_precision":"day","victim_org":"Munchables (NFT game on Blast)","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Insider Access"],"loss_usd":62500000,"loss_note":"About $62.5 million in ether at the time of the exploit. All funds were recovered after the developer surrendered the private keys without a ransom being paid.","records_affected":null,"threat_actor":"A developer using the GitHub handle 'Werewolves0493', assessed by investigator ZachXBT as North Korea-linked","summary":"Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.","how_it_worked":"This was infiltration rather than intrusion: the attacker was hired. Working as a Munchables developer with contract-deployment privileges, they positioned control of stored user funds ahead of a scheduled contract upgrade, then transferred those funds to themselves before the upgrade landed, so the movement looked like part of routine deployment activity. ZachXBT's analysis of GitHub commit timing and cross-referenced accounts suggested the developer was part of a cluster of DPRK-linked personas that had recommended one another into crypto projects, meaning the vetting failure compounded across multiple hires. Recovery came from negotiation, not from any control the project held.","lessons":"Live identity verification, tied to independently corroborated employment history, is the gate for anyone who will hold deployment or upgrade keys, and no single developer should be able to move user funds without multi-party approval.","confidence":"Reported","sources":[{"title":"Munchables Exploited for $62M, North Korea-Linked Exploiter Returns Private Keys to Web 3 Firm","url":"https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","publisher":"CoinDesk"},{"title":"Explained: The Munchables Hack (March 2024)","url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k"},{"title":"Ledger Connect Kit poisoned after a former employee's npm account was phished","date":"2023-12-14","date_precision":"day","victim_org":"Ledger SAS","sector":"Cryptocurrency","country":"France","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Cryptocurrency Theft","Credential Theft"],"loss_usd":600000,"loss_note":"Commonly reported as roughly $600,000 drained; CoinDesk cited an on-chain figure of about $484,000 in the immediate aftermath. Ledger said proceeds were split 85/15 between the attacker and the Angel Drainer service.","records_affected":null,"threat_actor":"Operator using the Angel Drainer drainer-as-a-service","summary":"On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.","how_it_worked":"The former employee's access to Ledger's internal systems had been revoked at offboarding, but their npmjs publishing rights had not been manually removed. A phishing attack captured a valid session token rather than a password, which sidestepped the account's 2FA entirely and let the attacker publish new Connect Kit versions. Those versions injected the Angel Drainer script into any decentralised application that loaded the library, prompting users to sign transactions that transferred their assets to the attacker. Ledger shipped a clean version within about 40 minutes of learning of the compromise, but CDN caching kept the poisoned file reachable for roughly five hours in total.","lessons":"Offboarding must enumerate and revoke package-registry and other third-party publishing rights, and releases to public package registries should require hardware-key-backed signing plus a second approver rather than a single session.","confidence":"Confirmed","sources":[{"title":"Security Incident Report","url":"https://www.ledger.com/blog/security-incident-report","publisher":"Ledger"},{"title":"Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft","url":"https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html","publisher":"The Hacker News"},{"title":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph"},{"title":"Fake recruiter's coding test cost payment processor CoinsPaid $37M","date":"2023-07-22","date_precision":"day","victim_org":"CoinsPaid","sector":"Cryptocurrency","country":"Estonia","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":37000000,"loss_note":"CoinsPaid reported losses of over $37 million; company funds rather than customer funds bore the loss. Most of the proceeds were moved through SwftSwap.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), suspected by CoinsPaid","summary":"Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.","how_it_worked":"After direct infrastructure attacks failed, the operators changed target from the network to a person. Fake recruiters approached a CoinsPaid engineer over messaging and professional platforms with an offer well above market rate, then moved the conversation to an interview process. The 'technical task' the candidate was asked to run as part of that process was the payload. Running it on their working machine gave the attackers a foothold with the employee's credentials and access, from which they reached the infrastructure that authorised outbound transfers and drained more than $37 million. CoinsPaid noted the transaction patterns closely mirrored other Lazarus operations from the same period.","lessons":"Job-application code and take-home assessments must only ever run in a disposable, network-isolated VM, and recruiters approaching engineers with outsized offers should be treated as an active threat indicator, not an HR event.","confidence":"Reported","sources":[{"title":"CoinsPaid claims North Korean hacking group used fake job interview to steal $37M","url":"https://cointelegraph.com/news/coinspaid-claims-north-korean-hacking-group-fake-job-interview-theft","publisher":"Cointelegraph"},{"title":"The CoinsPaid Hack Explained","url":"https://coinspaid.com/company-updates/the-coinspaid-hack-explained/","publisher":"CoinsPaid"}],"entry_type":"incident","slug":"2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m"},{"title":"Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked","date":"2023-05","date_precision":"month","victim_org":"Bart Stephens, co-founder of Blockchain Capital","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft","Attempt Blocked"],"loss_usd":6300000,"loss_note":"$6.3 million in bitcoin, ether and other tokens per the civil complaint. A further attempted theft of about $14 million from a cold storage wallet was stopped. Roughly half the stolen funds were routed through mixers.","records_affected":null,"threat_actor":"Unidentified attacker sued as 'Jane Doe'","summary":"Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.","how_it_worked":"The attacker assembled Stephens's personal details from public sources and dark web data, then used them to pass the identity checks at his mobile carrier, change the account password, order a new handset and port his private cell number to a SIM in that device. Holding the number, the attacker triggered password resets across Stephens's digital wallets and satisfied the SMS second factor on each one, then systematically moved assets out. The one transfer that failed was the cold storage withdrawal, which generated a notification seen by a colleague at the firm who acted before it settled.","lessons":"Removing SMS as a recovery or second factor for any wallet, and routing large withdrawals through a mandatory second-person approval with a time delay, are the two controls that separated the $6.3 million loss from the $14 million save.","confidence":"Reported","sources":[{"title":"Blockchain Capital's Bart Stephens Lost $6.3 Million In SIM-Swap Crypto Hack","url":"https://www.forbes.com/sites/iainmartin/2023/08/21/blockchain-capitals-bart-stephens-lost-63-million-in-sim-swap-crypto-hack/","publisher":"Forbes"}],"entry_type":"incident","slug":"2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked"},{"title":"Coinbase employee phished by SMS then talked through by a fake IT caller","date":"2023-02-05","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.","outcomes":["Data Breach","Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No customer funds or customer data were lost; exposure was limited to some employee contact details.","records_affected":null,"threat_actor":"Reported as the 0ktapus / Scattered Spider cluster","summary":"In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.","how_it_worked":"The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.","lessons":"Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.","confidence":"Confirmed","sources":[{"title":"Social Engineering - A Coinbase Case Study","url":"https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study","publisher":"Coinbase"},{"title":"Coinbase cyberattack targeted employees with fake SMS alert","url":"https://www.bleepingcomputer.com/news/security/coinbase-cyberattack-targeted-employees-with-fake-sms-alert/","publisher":"BleepingComputer"},{"title":"Coinbase breached by social engineers, employee data stolen","url":"https://news.sophos.com/en-us/2023/02/21/coinbase-breached-by-social-engineers-employee-data-stolen","publisher":"Sophos News"}],"entry_type":"incident","slug":"2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller"},{"title":"SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night","date":"2022-11-11","date_precision":"day","victim_org":"FTX (referred to as 'Victim 1' in the indictment)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physical fake ID at a retail store.","outcomes":["Cryptocurrency Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_note":"The DOJ indictment concerns a theft of roughly $400 million. FTX administrators reported $413 million in unauthorised transfers, and Elliptic valued the outflow at $477 million. Prosecutors have not officially named FTX as the victim.","records_affected":null,"threat_actor":"Robert Powell ('ElSwapo1', the 'Powell SIM Swapping Crew'), Emily Hernandez, Carter Rohn","summary":"On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.","how_it_worked":"A member of the crew walked into an AT&T retail location carrying a counterfeit ID in the target's name and asked staff to move the number to a new device. The store employee, following normal identity-check procedure against a document that looked genuine, completed the port. From that point every SMS one-time code and password-reset link for the target's accounts arrived on the attackers' handset. The crew used those codes to reach account credentials and then initiated the transfers out of FTX wallets, timed to a night when the company was in bankruptcy chaos and unusual outflows were least likely to be challenged.","lessons":"Enterprise-controlled authentication that never touches a consumer mobile number, combined with number-lock and in-person ID escalation at carrier retail, closes the pathway a physical fake ID otherwise opens.","confidence":"Reported","sources":[{"title":"Arrests in $400M SIM-Swap Tied to Heist at FTX?","url":"https://krebsonsecurity.com/2024/02/arrests-in-400m-sim-swap-tied-to-heist-at-ftx/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night"},{"slug":"2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx","title":"3Commas users phished for API keys, leading to unauthorised trades on FTX accounts","date":"2022-10","date_precision":"month","year":2022,"victim_org":"3Commas users (with linked FTX and Binance accounts)","sector":"Cryptocurrency","country":"Estonia","primary_vector":"Credential Phishing Portal","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft"],"loss_usd":6000000,"loss_kind":"aggregate","loss_note":"Reported aggregate user losses of roughly US$6 million across affected accounts; FTX said it would compensate some affected users. Individual reported losses ranged widely.","records_affected":null,"threat_actor":null,"summary":"In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.","how_it_worked":"Attackers stood up phishing sites imitating 3Commas and lured users, mainly through crypto community channels and search, into connecting their exchange accounts there. Victims typed their exchange API keys into the fake interface believing they were configuring a trading bot, which is exactly what a real 3Commas onboarding asks for, so the request was indistinguishable from the legitimate flow. With trading-enabled API keys the attackers did not need to withdraw funds, which would have hit withdrawal controls; instead they ran wash trades against illiquid pairs, moving value out of victims' accounts through the market itself.","lessons":"API keys should be issued with the narrowest permissions and an IP allowlist, and platforms should never accept exchange keys through a page a user reached from an untrusted link.","confidence":"Reported","sources":[{"title":"FTX API keys connected to 3Commas confirmed to have been exploited","url":"https://www.theblock.co/post/179237/ftx-api-keys-3commas-exploited","publisher":"The Block"},{"title":"3Commas legal statement in regard of violated API keys","url":"https://3commas.io/blog/3commas-legal-statement-in-regard-of-violated-api-keys","publisher":"3Commas"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx"},{"title":"Deepfake of Binance communications chief used to scam crypto projects on video calls","date":"2022-08","date_precision":"month","victim_org":"Multiple cryptocurrency projects seeking Binance listings","sector":"Cryptocurrency","country":"Multiple countries","primary_vector":"Deepfake Video Call","secondary_vectors":["Romance / Investment Scam"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Binance chief communications officer Patrick Hillmann said attackers built an AI video 'hologram' of him from his past news interviews and TV appearances and used it live on Zoom calls.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Losses to individual projects were not disclosed","records_affected":null,"threat_actor":null,"summary":"In August 2022 Binance disclosed that a 'sophisticated hacking team' had produced a deepfake video likeness of chief communications officer Patrick Hillmann and used it on Zoom calls with representatives of cryptocurrency projects. The impersonator offered help getting tokens listed on Binance and solicited payments and information. Hillmann said several project managers were convinced before the fraud was discovered, and that the clone was built from his publicly available interview footage.","how_it_worked":"The pretext was the single thing small crypto projects want most, a listing on the largest exchange, and the caller occupied a role that plausibly controls access to it. Contact was made over social channels and then escalated to a Zoom call, where the deepfake of a face the targets had seen in Binance media coverage supplied the trust signal that a mere email could not. Because listing discussions are routinely confidential and involve fees, requests for money and business documents did not look out of place. Victims were pushed to move fast on the implied scarcity of a listing slot, and only later checked with Binance through official channels.","lessons":"Exchange listing and partnership discussions should be confirmed through the company's published contact channels, and no vendor should treat a video likeness as proof of employment.","confidence":"Reported","sources":[{"title":"Binance exec says scammers made a deepfake hologram of him","url":"https://www.theregister.com/2022/08/23/binance_deepfake_scam/","publisher":"The Register"},{"title":"Deepfake hologram targets Binance and crypto community","url":"https://www.malwarebytes.com/blog/news/2022/08/deepfake-hologram-targets-binance-and-crypto-community","publisher":"Malwarebytes Labs"}],"entry_type":"campaign","slug":"2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on"},{"title":"Phishing of a Harmony developer preceded the $100M Horizon Bridge theft","date":"2022-06-23","date_precision":"day","victim_org":"Harmony (Horizon Bridge)","sector":"Cryptocurrency","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":100000000,"loss_note":"The FBI put the theft at $100 million in virtual currency, spanning 14 bridged assets including USDC, ETH, USDT and BNB.","records_affected":null,"threat_actor":"Lazarus Group and APT38 (DPRK), per FBI attribution","summary":"Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.","how_it_worked":"Harmony stated the attackers 'employed a phishing scheme to trick at least one software developer to install malicious software on their laptop.' That access let them read internal chat threads to learn how the bridge was operated and reach non-public bridge infrastructure code, then obtain backdoor access to one or more servers. Because the Horizon Bridge used a multisignature scheme requiring only two of five signatures, compromising the operational hosts holding those keys was enough to authorise transfers. On June 23 the attackers moved fourteen bridged asset types out in a series of transactions. Harmony emphasised the bridge contracts themselves were never exploited.","lessons":"Raising the signature threshold and isolating signing keys on dedicated hardware away from developer workstations would have meant that phishing one laptop could not produce a valid bridge withdrawal.","confidence":"Confirmed","sources":[{"title":"Summary of the Harmony Horizon Bridge Incident","url":"https://medium.com/harmony-one/summary-of-the-harmony-horizon-bridge-incident-f9bd87c0c68e","publisher":"Harmony"},{"title":"FBI: North Korean hackers stole $100 million in Harmony crypto hack","url":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft"},{"title":"Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds","date":"2022-04-03","date_precision":"day","victim_org":"SatoshiLabs (Trezor), via email provider Mailchimp","sector":"Cryptocurrency","country":"Czech Republic","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Data Breach","Credential Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Neither Trezor nor Mailchimp published a loss figure, and Trezor said at the time it was unclear whether any funds were successfully stolen. The '106,856 customers' figure that circulated came from the phishing email itself and was attacker-authored text, not a confirmed breach count.","records_affected":null,"threat_actor":"Unattributed actor targeting cryptocurrency-sector Mailchimp tenants","summary":"Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.","how_it_worked":"The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.","lessons":"Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.","confidence":"Confirmed","sources":[{"title":"Ongoing phishing attacks on Trezor users","url":"https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304","publisher":"Trezor (SatoshiLabs)"},{"title":"Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam","url":"https://decrypt.co/96942/mailchimp-insider-targets-trezor-crypto-wallets-phishing-scam","publisher":"Decrypt"}],"entry_type":"incident","slug":"2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"},{"title":"Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF","date":"2022-03-23","date_precision":"day","victim_org":"Sky Mavis (Ronin Network / Axie Infinity)","sector":"Cryptocurrency","country":"Vietnam","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona and interview process were run by humans.","outcomes":["Cryptocurrency Theft"],"loss_usd":620000000,"loss_note":"173,600 ETH and 25.5 million USDC were drained; the value is commonly reported as roughly $540 million at the time of the hack and about $620-625 million at the time of disclosure, depending on the valuation date.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); sanctioned by the US Treasury in April 2022","summary":"On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.","how_it_worked":"Attackers posing as a non-existent company recruited a senior engineer over LinkedIn with an unusually generous compensation package, running a plausible multi-round interview process to build credibility. The final offer arrived as a PDF; downloading and opening it on a company machine executed spyware that gave the attackers a foothold in Sky Mavis systems. From there they obtained the private keys for four of the nine Ronin validator nodes, and used a still-active allowlist permission previously granted by Sky Mavis to the Axie DAO to obtain a fifth signature, reaching the five-of-nine threshold needed to authorise withdrawals from the bridge.","lessons":"Validator key material should live in hardware security modules on isolated machines that never render untrusted documents, and delegated signing permissions must expire automatically rather than persist after a temporary need ends.","confidence":"Confirmed","sources":[{"title":"How a fake job offer took down the world's most popular crypto game","url":"https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","publisher":"The Block"},{"title":"Hackers Used Fake Job Offer to Hack and Steal $540 Million from Axie Infinity","url":"https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","publisher":"The Hacker News"},{"title":"Spear Phishing Fake Job Offer Likely Behind Axie Infinity's Lazarus $600m Hack","url":"https://www.infosecurity-magazine.com/news/fake-job-offer-behind-axie/","publisher":"Infosecurity Magazine"},{"title":"Hackers stole $620 million from Axie Infinity via fake job interviews","url":"https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake-job-interviews/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf"},{"title":"Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash","date":"2020-11-13","date_precision":"day","victim_org":"GoDaddy (registrar); Liquid.com and NiceHash","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning was reported; the callers used conventional pretexting against registrar staff.","outcomes":["Data Breach","Credential Theft","Service Disruption"],"loss_usd":null,"loss_note":"No customer funds were reported lost. Liquid said customer funds remained secure; NiceHash said no emails, passwords or personal data were compromised.","records_affected":null,"threat_actor":"Unattributed","summary":"Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.","how_it_worked":"The attackers called GoDaddy employees and pretended to be authorised parties with a routine domain administration need, a pretext the registrar's own staff were positioned to fulfil. Once a rep made the change, the attackers held registrar-level control of the target's domain and could repoint DNS at will. For Liquid, control of the domain's MX and name server records let them take over internal email accounts, which in turn exposed customer names, addresses, encrypted passwords and identity verification documents. NiceHash saw the same DNS manipulation but reported no data compromise. The exchanges' own security was never touched; the failure was one level up, at the registrar.","lessons":"Registry lock on critical domains, which requires manual out-of-band verification before any DNS or nameserver change, defeats registrar-side social engineering outright.","confidence":"Confirmed","sources":[{"title":"GoDaddy Employees Tricked into Compromising Cryptocurrency Sites","url":"https://threatpost.com/godaddy-employees-tricked-compromise-cryptocurrency/161520/","publisher":"Threatpost"},{"title":"GoDaddy Employees Tricked Into Transferring Control of Crypto Firm Domains: Report","url":"https://www.coindesk.com/markets/2020/11/22/godaddy-employees-tricked-into-transferring-control-of-crypto-firm-domains-report","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic"},{"title":"AT&T SIM swap drains $24M in crypto from investor Michael Terpin","date":"2018-01","date_precision":"month","victim_org":"Michael Terpin (individual investor; Transform Group)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Insider Recruitment","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media was reported in this case; the attack relied on carrier account takeover and insider assistance.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":24000000,"loss_note":"Approximately $24 million in cryptocurrency at the values cited in Terpin's litigation and contemporaneous reporting. A Los Angeles Superior Court default judgment against Nicholas Truglia totaled $75.8 million including treble RICO damages and prejudgment interest.","records_affected":null,"threat_actor":"Nicholas Truglia and associates; Ellis Pinsky, then 15, later named as a participant","summary":"Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.","how_it_worked":"Attackers targeted the mobile carrier rather than Terpin directly. According to reporting on the litigation, a then-15-year-old and an accomplice bribed an AT&T employee to move Terpin's SIM information onto a blank SIM card in a phone they controlled. Once the number was theirs, inbound SMS one-time codes and password-reset links flowed to the attackers, letting them reset credentials on Terpin's email and exchange accounts and sweep his holdings. Terpin had reportedly already asked AT&T to place additional protections on the account, which the complaint alleged were not effective against an employee acting from inside the carrier's own systems.","lessons":"Removing SMS from the authentication path for high-value crypto accounts, and enforcing dual-control plus supervisory approval on carrier-side SIM changes, would have broken this chain.","confidence":"Confirmed","sources":[{"title":"Cryptocurrency Investor Michael Terpin Wins $75.8 Million Judgment in First-Ever SIM Swap Racketeering Case","url":"https://www.greenbergglusker.com/news/cryptocurrency-investor-michael-terpin-wins-75-8-million-judgment-in-first-ever-sim-swap-racketeering-case","publisher":"Greenberg Glusker"},{"title":"Court revives 2020 AT&T case over $24M crypto theft via SIM swap","url":"https://cointelegraph.com/news/att-court-sim-swap-crypto-theft","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin"},{"title":"Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree","date":"2018","date_precision":"year","victim_org":"Approximately 40 individual cryptocurrency holders","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation","Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":7500000,"loss_note":"CoinDesk reported thefts exceeding $7.5 million across roughly 40 victims, including a single May 2018 theft of more than $5.2 million from a Cupertino entrepreneur. Vice reported the aggregate as 'over $5 million'. About $400,000 was recovered at arrest.","records_affected":null,"threat_actor":"Joel Ortiz","summary":"Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.","how_it_worked":"Ortiz and associates identified crypto holders from conference attendance and social media, then attacked their mobile carrier accounts rather than their wallets. Using victim personal data and, in the wider SIM-swap ecosystem the task force mapped, cooperative or deceived retail carrier staff, they had target numbers ported onto SIM cards they controlled. Possession of the number let them intercept SMS one-time passcodes and password-reset links, take over email and exchange accounts, and transfer funds out. One May 2018 swap moved more than $5.2 million within minutes. Proceeds went to club spending, a helicopter rental and designer goods.","lessons":"Carrier port-out PINs and number-lock features, plus app- or hardware-based MFA instead of SMS on exchange accounts, remove the single point of failure this scheme depended on.","confidence":"Confirmed","sources":[{"title":"Student Gets 10-Year Jail Term for SIM-Swap Crypto Thefts Worth $7.5 Million","url":"https://www.coindesk.com/markets/2019/04/23/student-gets-10-year-jail-term-for-sim-swap-crypto-thefts-worth-75-million","publisher":"CoinDesk"},{"title":"Hacker Who Stole $5 Million By SIM Swapping Gets 10 Years in Prison","url":"https://www.vice.com/en/article/hacker-joel-ortiz-sim-swapping-10-years-in-prison/","publisher":"Vice / Motherboard"}],"entry_type":"incident","slug":"2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"}]}