{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:42.024Z","total":4,"returned":4,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"QR code phishing campaign targets a major US energy company's Microsoft logins","date":"2023-08","date_precision":"month","victim_org":"Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets)","sector":"Energy & Utilities","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Credential Theft","Attempt Blocked"],"loss_usd":null,"loss_note":"No loss figure; Cofense reported the campaign volume rather than confirmed compromises.","records_affected":null,"threat_actor":null,"summary":"Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.","how_it_worked":"Emails spoofed Microsoft security notifications and told recipients they had to update account security relating to two-factor or multifactor authentication. Rather than a clickable link, the message carried a QR code inside an image or PDF attachment, which defeated URL scanning in email gateways because the destination was encoded in pixels. Scanning the code moved the victim onto a personal mobile phone, typically outside corporate device management and web filtering, where a credential harvesting page imitating Microsoft sign-in captured the username and password. Attackers also used redirects through legitimate services such as Bing to further obscure the final destination.","lessons":"Email security needs to decode QR images rather than only parse hyperlinks, and enrolling users in phishing-resistant authentication means a credential captured on an unmanaged phone is not enough to sign in.","confidence":"Confirmed","sources":[{"title":"Major Energy Company Targeted in Large QR Code Campaign","url":"https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign","publisher":"Cofense"},{"title":"QR Code Phishing Campaign Targets Top US Energy Company","url":"https://www.darkreading.com/cyberattacks-data-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company","publisher":"Dark Reading"},{"title":"Phishing campaign used QR codes to target large energy company","url":"https://therecord.media/phishing-campaign-used-qr-codes-to-target-energy-firm","publisher":"The Record"}],"entry_type":"campaign","slug":"2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft"},{"title":"UK energy firm CEO tricked by AI voice clone of German parent-company boss","date":"2019-03","date_precision":"month","victim_org":"Unnamed UK-based energy company (subsidiary of a German parent)","sector":"Energy & Utilities","country":"United Kingdom","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Business Email Compromise"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Fraud investigators at insurer Euler Hermes attributed the call to commercial voice-synthesis software that reproduced the German executive's accent and speech melody. The AI attribution rests on the insurer's assessment, not on forensic recovery of the tool.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":243000,"loss_note":"EUR 220,000, approx US$243,000","records_affected":null,"threat_actor":null,"summary":"In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.","how_it_worked":"The attacker phoned the UK CEO directly and presented as the group chief executive, a person the target reported to and whose voice he knew. The cloned audio carried the familiar German accent and cadence, which served as the trust signal that displaced any need for written confirmation. The pretext was an urgent payment to a Hungarian supplier that had to clear within the hour, and the caller promised the subsidiary would be reimbursed immediately. After the first transfer succeeded the fraudster called back twice more, once claiming reimbursement had been sent and once asking for a further payment. The CEO only balked when the promised refund failed to appear and a later call arrived from an Austrian number.","lessons":"Out-of-band callback to a known-good number and a dual-authorisation rule for first-time beneficiary payments would have broken the single-channel voice trust the attack depended on.","confidence":"Reported","sources":[{"title":"A Voice Deepfake Was Used To Scam A CEO Out Of $243,000","url":"https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/","publisher":"Forbes"},{"title":"Scammers deepfake CEO's voice to talk underling into $243,000 transfer","url":"https://www.sophos.com/en-us/blog/scammers-deepfake-ceos-voice-to-talk-underling-into-243000-transfer","publisher":"Sophos Naked Security"}],"entry_type":"incident","slug":"2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo","year":2019,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo"},{"slug":"2017-russian-fsb-officers-spear-phished-wolf-creek-nuclear-plant-in-global-en","title":"Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign","date":"2017","date_precision":"year","year":2017,"victim_org":"Wolf Creek Nuclear Operating Corporation","sector":"Energy & Utilities","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Russian FSB Center 16 (Dragonfly / Energetic Bear); three officers indicted by the US DOJ in 2021, unsealed 2022","summary":"A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.","how_it_worked":"The operators mailed engineers and IT staff at energy companies with documents tailored to their work, including material presented as job applications and CVs and as industry technical content, so opening the attachment felt like part of the job. Recipients who opened the files installed malware or were funnelled to credential-harvesting pages. The campaign also compromised websites the same engineers routinely visited, so credentials could be captured without any email at all. At Wolf Creek the successful phishing gave access to the corporate business network, which the group then used to push deeper into the victim's systems.","lessons":"Role-targeted phishing against engineers demands hardware-backed MFA and strict separation between corporate email environments and any network adjacent to operational technology.","confidence":"Confirmed","sources":[{"title":"Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide","url":"https://www.justice.gov/archives/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical","publisher":"U.S. Department of Justice"},{"title":"Indictment related to Wolf Creek computer hack unsealed","url":"https://www.ans.org/news/article-3818/indictment-related-to-wolf-creek-computer-hack-unsealed/","publisher":"American Nuclear Society"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-russian-fsb-officers-spear-phished-wolf-creek-nuclear-plant-in-global-en"},{"title":"Ukraine power grid blackout of 2015 began with BlackEnergy spear phishing","date":"2015-12-23","date_precision":"day","victim_org":"Kyivoblenergo, Prykarpattyaoblenergo and Chernivtsioblenergo","sector":"Energy & Utilities","country":"Ukraine","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Service Disruption","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No monetary loss figure published; impact measured in customer-hours of lost electricity supply.","records_affected":null,"threat_actor":"Sandworm (Russian GRU-linked)","summary":"On 23 December 2015 three Ukrainian regional electricity distribution companies were hit by a coordinated cyberattack that opened breakers at roughly 30 substations and left about 225,000 customers without power. The joint E-ISAC/SANS analysis found the intrusion began months earlier with spear phishing emails carrying malicious Office documents that installed BlackEnergy 3, which was used to harvest credentials for the operators' VPN and SCADA environments.","how_it_worked":"Staff at the distribution companies received emails with Word and Excel attachments; opening them produced a prompt to enable macros, which installed BlackEnergy 3. The attackers spent months conducting reconnaissance, stealing Windows domain credentials and mapping the SCADA environment, then used legitimate remote access to the operators' control systems to open circuit breakers by hand. They followed up by uploading malicious firmware to serial-to-Ethernet converters, wiping workstations with KillDisk, and flooding customer call centres with a telephony denial of service so outages were harder to report and restore.","lessons":"Macro execution should be blocked by policy for ordinary users, and remote access into an ICS environment should be MFA-protected and separated from the corporate domain whose credentials phishing yields.","confidence":"Confirmed","sources":[{"title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","url":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2016/05/20081514/E-ISAC_SANS_Ukraine_DUC_5.pdf","publisher":"E-ISAC and SANS ICS"},{"title":"Analysis of the Cyber Attack on the Ukrainian Power Grid (archived copy)","url":"https://nsarchive.gwu.edu/sites/default/files/documents/3891751/SANS-and-Electricity-Information-Sharing-and.pdf","publisher":"National Security Archive"},{"title":"Power grid cyberattack in Ukraine (2015)","url":"https://cyberlaw.ccdcoe.org/wiki/Power_grid_cyberattack_in_Ukraine_(2015)","publisher":"NATO CCDCOE Cyber Law Toolkit"}],"entry_type":"incident","slug":"2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin","year":2015,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin"}]}