{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:35.183Z","total":9,"returned":9,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman","title":"700+ education and tech sites hijacked to serve ClickFix paste-the-command lures","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Visitors to 700+ compromised university and technology company websites","sector":"Education","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.","how_it_worked":"The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.","lessons":"Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.","confidence":"Confirmed","sources":[{"title":"700+ education and tech websites hijacked in huge ClickFix malware campaign","url":"https://www.malwarebytes.com/blog/bugs/2026/05/700-education-and-tech-websites-hijacked-in-huge-clickfix-malware-campaign","publisher":"Malwarebytes"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"},{"slug":"2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec","title":"Dickinson Public Schools loses $4.92M to vendor-impersonation BEC","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Dickinson Public Schools","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4920000,"loss_kind":"direct_loss","loss_note":"USD; two payments diverted from the district's restricted building fund. No recovery reported at time of disclosure.","records_affected":null,"threat_actor":null,"summary":"Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.","how_it_worked":"The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.","lessons":"Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.","confidence":"Confirmed","sources":[{"title":"North Dakota School District Loses $4.9M to Email Scam","url":"https://www.govtech.com/education/k-12/north-dakota-school-district-loses-4-9m-to-email-scam","publisher":"Government Technology"},{"title":"North Dakota school district loses nearly $5 million in sophisticated email scam","url":"https://www.valleynewslive.com/2026/02/11/north-dakota-school-district-loses-nearly-5-million-sophisticated-email-scam/","publisher":"Valley News Live"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"},{"slug":"2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack","title":"Harvard alumni and donor data stolen in phone-based phishing attack","date":"2025-11-18","date_precision":"day","year":2025,"victim_org":"Harvard University","sector":"Education","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.","how_it_worked":"The attacker telephoned someone with access to the advancement systems and, over the call, obtained what was needed to log in as that person. Harvard characterised the incident explicitly as a phone-based phishing attack on its Alumni Affairs and Development environment. Advancement offices are attractive because a small number of staff hold broad read access to donor records, and because fundraising work involves frequent legitimate calls from unfamiliar people, which normalises an unexpected voice asking for help. Once authenticated as the employee, the intruder queried and exported donor and alumni records before the university revoked the access and brought in outside responders.","lessons":"Phishing-resistant MFA on advancement systems and a standing rule that credentials or one-time codes are never handled over the phone would have blocked the login.","confidence":"Confirmed","sources":[{"title":"Harvard University discloses data breach affecting alumni, donors","url":"https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/","publisher":"BleepingComputer"},{"title":"Harvard University reports data breach following voice phishing incident","url":"https://www.paubox.com/blog/harvard-university-reports-data-breach-following-voice-phishing-incident","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack"},{"slug":"2025-princeton-advancement-database-breached-in-targeted-phishing-attack","title":"Princeton advancement database breached in targeted phishing attack","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Princeton University","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.","how_it_worked":"The intrusion started with a targeted phishing approach aimed at a single staff member with advancement-system access rather than a mass campaign. The message and follow-up were crafted around university fundraising work, an area where staff routinely receive unfamiliar outreach about events, gifts and alumni records, which made the approach unremarkable. The trust signal abused was the appearance of legitimate internal or alumni-related correspondence; the pressure was ordinary work urgency rather than threats. Once the employee's session or credentials were captured, the attacker authenticated as them and queried the advancement database directly, exporting constituent records before the university detected the activity and cut off access.","lessons":"Hardware-backed or passkey MFA for advancement staff, plus alerting on unusual bulk queries against constituent databases, would have contained the single compromised account.","confidence":"Confirmed","sources":[{"title":"Princeton Database Breached in Targeted Phishing Incident","url":"https://paw.princeton.edu/article/princeton-database-breached-targeted-phishing-incident","publisher":"Princeton Alumni Weekly"},{"title":"Cybersecurity incident information and FAQ","url":"https://oit.princeton.edu/cybersecurity-incident-information-and-faq","publisher":"Princeton University OIT"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-princeton-advancement-database-breached-in-targeted-phishing-attack"},{"slug":"2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering","title":"University of Pennsylvania donor systems breached via social engineering","date":"2025-10-31","date_precision":"day","year":2025,"victim_org":"University of Pennsylvania","sector":"Education","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.","how_it_worked":"Penn said the intrusion began with social engineering that tricked an individual into giving up login credentials, and reporting noted that some senior staff held exemptions from the university's multi-factor authentication requirement, which removed the backstop that would normally have blunted a stolen password. The pretext targeted people working in development and alumni relations, whose accounts unlock both donor databases and mass-email tooling. After authenticating, the attacker pulled constituent records and then used the same access to blast offensive messages to alumni and donors, converting a quiet data theft into a public humiliation and extortion play.","lessons":"No MFA exemptions for executives or fundraising leadership, and separate authorisation for mass-email sending, would have limited both the theft and the follow-on abuse.","confidence":"Confirmed","sources":[{"title":"University of Pennsylvania confirms hacker stole data during cyberattack","url":"https://techcrunch.com/2025/11/05/university-of-pennsylvania-confirms-hacker-stole-data-during-cyberattack/","publisher":"TechCrunch"},{"title":"University of Pennsylvania confirms data stolen in cyberattack","url":"https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering"},{"slug":"2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a","title":"Baltimore County schools ransomware started with a contractor opening a phishing email","date":"2020-11-24","date_precision":"day","year":2020,"victim_org":"Baltimore County Public Schools","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Service Disruption","Data Breach"],"loss_usd":9700000,"loss_kind":"business_impact","loss_note":"About US$9.7 million in recovery and remediation costs according to the Maryland Office of the Inspector General for Education; no ransom was paid.","records_affected":null,"threat_actor":"Ryuk (reported)","summary":"Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.","how_it_worked":"A contractor working with the district opened a malicious email attachment, which established the foothold that led to district-wide encryption on the eve of the Thanksgiving holiday, a timing choice that maximised the gap before anyone noticed. The Inspector General's report placed the weight of the finding not on the click but on what surrounded it: the district had received specific security recommendations from a prior state audit and had not implemented them, and had extended network access to a contractor without correspondingly hardened controls. Remote learning for 115,000 students halted, and rebuilding cost nearly ten million dollars.","lessons":"Contractor accounts need the same email defences, MFA and least privilege as employees, and audit findings left unimplemented become the incident's root cause.","confidence":"Confirmed","sources":[{"title":"Baltimore County schools ignored warnings before 2020 cyberattack, audit finds","url":"https://statescoop.com/baltimore-county-schools-ransomware-attack-2020-inspector-general/","publisher":"StateScoop"},{"title":"Report: Contractor 'mistakenly' opened email starting Baltimore County school cyberattack","url":"https://foxbaltimore.com/news/local/investigative-report-released-2-years-after-baltimore-county-schools-cyberattack","publisher":"Fox Baltimore (WBFF)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a"},{"slug":"2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake","title":"Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow","date":"2019-07","date_precision":"month","year":2019,"victim_org":"Lancaster University","sector":"Education","country":"United Kingdom","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":12500,"threat_actor":null,"summary":"Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.","how_it_worked":"Phishing against university staff yielded access to the applicant records system. What made this breach unusual is the immediate monetisation: rather than selling the data, the attacker used it to send fraudulent invoices directly to undergraduate applicants. Those recipients were the ideal targets, because a prospective student who has just applied is expecting communication from the university about fees and accommodation, and has no baseline for what a genuine invoice looks like. The stolen contact details supplied exactly the personalisation, real name, real address, real course application, that makes a fake bill credible. The university reported to the ICO and warned applicants directly.","lessons":"Multi-factor authentication on staff accounts, plus a published policy that the university never invoices applicants by email, closes both the intrusion and the downstream fraud.","confidence":"Confirmed","sources":[{"title":"Lancaster University Confirms Data Breach, Applicants Targeted","url":"https://www.infosecurity-magazine.com/news/lancaster-university-breach/","publisher":"Infosecurity Magazine"},{"title":"Lancaster University data breach","url":"https://www.theregister.com/2019/07/23/lancaster_university_data_breach/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake"},{"slug":"2018-san-diego-unified-staff-phished-exposing-500-000-students-parents-and-em","title":"San Diego Unified staff phished, exposing 500,000 students, parents and employees","date":"2018-10","date_precision":"month","year":2018,"victim_org":"San Diego Unified School District","sector":"Education","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":500000,"threat_actor":null,"summary":"San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.","how_it_worked":"The attacker sent phishing emails to district staff that led to pages designed to capture network log-in credentials. Because a school district's staff population is large, distributed across many sites and generally does not have dedicated security support, a broad credential-harvesting campaign only had to work on a handful of recipients. The stolen log-ins gave ordinary authenticated access to district systems, which is why the intrusion looked like normal staff activity for eleven months. It was detected in October 2018 only because multiple employees independently reported the phishing emails, which prompted the investigation that revealed the wider access.","lessons":"Multi-factor authentication on staff single sign-on, plus alerting on anomalous access to student information systems, is what turns an eleven-month intrusion into a same-day one.","confidence":"Confirmed","sources":[{"title":"Info on Over 500,000 Students and Staff Exposed in San Diego School District Hack","url":"https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/","publisher":"BleepingComputer"},{"title":"San Diego Schools Say Phishing Scam Caused Cyber Breach","url":"https://www.newsweek.com/san-diego-unified-school-district-san-diego-police-department-phishing-cyber-1269185","publisher":"Newsweek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-san-diego-unified-staff-phished-exposing-500-000-students-parents-and-em"},{"title":"IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits","date":"2017-02-02","date_precision":"day","victim_org":"US school districts, tribal organizations, nonprofits and employers (multi-victim campaign)","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in the IRS alert.","outcomes":["Data Breach","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The IRS did not publish an aggregate dollar figure; it stated some organisations lost both employee W-2s and thousands of dollars in wire transfers.","records_affected":null,"threat_actor":null,"summary":"In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.","how_it_worked":"Criminals spoofed an organisation's executive and emailed payroll or human resources staff asking for a list of all employees and their Forms W-2. School districts and small nonprofits were attractive because payroll is often handled by one or two people with no formal verification procedure and no security team. After the W-2 file was sent, the same spoofed executive followed up with a request to the payroll or comptroller staff to wire funds to a specified account, exploiting the compliance momentum created by the first successful request. Some organisations lost both the employee data and the money.","lessons":"Small public-sector and nonprofit payroll functions need a written, mandatory callback rule for executive requests, since they lack the compensating controls larger firms rely on.","confidence":"Confirmed","sources":[{"title":"IR-2017-20: Dangerous W-2 Phishing Scam Evolving; Targeting Schools, Restaurants, Hospitals, Tribal Groups and Others","url":"https://www.irs.gov/pub/irs-news/ir-17-020.pdf","publisher":"Internal Revenue Service"}],"entry_type":"campaign","slug":"2017-irs-warns-of-w-2-phishing-epidemic-spreading-to-school-districts-and-non","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-irs-warns-of-w-2-phishing-epidemic-spreading-to-school-districts-and-non"}]}