{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:29:25.676Z","total":21,"returned":21,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks","date":"2026-08-06","date_precision":"day","victim_org":"Point72, Millennium Management, Two Sigma, Citadel and private-equity firms","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.","outcomes":["Attempt Blocked","Extortion","Credential Theft"],"loss_usd":10600000,"loss_note":"Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.","records_affected":null,"threat_actor":"UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon","summary":"BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.","how_it_worked":"Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.","lessons":"Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.","confidence":"Confirmed","sources":[{"title":"Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group","url":"https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at","year":2026,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"},{"title":"Apollo Global Management breached by BlackFile callers posing as IT support","date":"2026-07-06","date_precision":"day","victim_org":"Apollo Global Management","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Researchers described a large pool of human callers recruited for small fees rather than synthetic voice.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"Apollo did not disclose a figure; researchers said BlackFile typically opens around $3 million and settles under $1 million.","records_affected":null,"threat_actor":"BlackFile (tracked by Google as UNC6671), part of The Com, operating the Redact, Pink, Helix and Falcon extortion brands","summary":"Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.","how_it_worked":"BlackFile industrialised the phone call. Researchers describe hundreds of callers, often low-level people recruited for a small fee or for standing within the group, dialling employees while impersonating internal IT support until one target complies. Volume replaces finesse: the crew averages about 1.5 new victims a day and has hit private equity firms, law firms, ratings agencies and medical technology companies. Once an identity is obtained the operators move into cloud platforms and collect data for extortion, escalating with threatening messages and swatting when victims resist.","lessons":"Phishing-resistant MFA plus a strict no-credentials-over-the-phone policy blunts high-volume calling, and cloud data stores need export alerting because these crews steal rather than encrypt.","confidence":"Confirmed","sources":[{"title":"Apollo discloses data breach from ongoing wave of attacks hitting financial sector","url":"https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/","publisher":"CyberScoop"},{"title":"Details emerge on BlackFile's recent attacks on financial companies","url":"https://cyberscoop.com/blackfile-cyberattacks-financial-sector/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"},{"slug":"2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo","title":"Figure Technology loses ~967,000 customer records after employee falls for SSO vishing","date":"2026-02-19","date_precision":"day","year":2026,"victim_org":"Figure Technology Solutions","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":967000,"threat_actor":"ShinyHunters","summary":"Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.","how_it_worked":"The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.","lessons":"Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.","confidence":"Reported","sources":[{"title":"Nearly 1 Million User Records Compromised in Figure Data Breach","url":"https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/","publisher":"SecurityWeek"},{"title":"Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters","url":"https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/","publisher":"Cybernews"},{"title":"Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People","url":"https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"},{"title":"Betterment named among victims of the January 2026 real-time vishing wave","date":"2026-01-09","date_precision":"day","victim_org":"Betterment","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"No synthetic voice was reported for this campaign; the calls were described as live operators.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.","how_it_worked":"The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.","lessons":"Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav"},{"title":"Okta SSO accounts targeted in vishing campaign against financial firms","date":"2026-01","date_precision":"month","victim_org":"Multiple fintech, wealth management and advisory firms (unnamed)","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_note":"Ransom demands were made by email; no aggregate figure was published for this wave.","records_affected":null,"threat_actor":"ShinyHunters (signed some extortion demands)","summary":"BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.","how_it_worked":"Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.","lessons":"Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.","confidence":"Confirmed","sources":[{"title":"Okta SSO accounts targeted in vishing-based data theft attacks","url":"https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"},{"slug":"2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ","title":"TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs","date":"2025-07-28","date_precision":"day","year":2025,"victim_org":"TransUnion","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4400000,"threat_actor":"ShinyHunters","summary":"Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.","how_it_worked":"TransUnion has described the entry point only as a third-party application serving its consumer support operations and has not publicly confirmed a social engineering pretext. Reporting places the theft in the Salesforce campaign attributed to UNC6040 and ShinyHunters, in which callers impersonating internal IT support telephone employees, cite a routine integration or troubleshooting need, and talk the target through authorising an attacker-controlled connected application inside the genuine Salesforce authorisation screen. The abused trust signal is Salesforce's own real interface combined with a plausible internal support identity; the extraction that follows is automated and needs no further human involvement.","lessons":"Restricting connected-app authorisation to a small set of administrators and alerting on any newly bound application or unusual bulk export from the CRM would have contained this class of intrusion at the moment of consent.","confidence":"Reported","sources":[{"title":"TransUnion suffers data breach impacting over 4.4 million people","url":"https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/","publisher":"BleepingComputer"},{"title":"TransUnion becomes latest victim in major wave of Salesforce-linked cyberattacks, 4.4M Americans affected","url":"https://www.foxnews.com/tech/transunion-becomes-latest-victim-major-wave-salesforce-linked-cyberattacks-4-4m-americans-affected","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"slug":"2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre","title":"Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility","date":"2025-07","date_precision":"month","year":2025,"victim_org":"HPS Investment Partners (BlackRock)","sector":"Financial Services","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_kind":"direct_loss","loss_note":"USD. HPS extended more than $400 million against the disputed receivables, part of roughly $430 million of loans, with BNP Paribas providing leverage on about half. HPS is pursuing recovery through Delaware court action and related bankruptcy proceedings, so the final unrecovered amount has not been published.","records_affected":null,"threat_actor":"Bankim Brahmbhatt and affiliated telecom entities (alleged)","summary":"HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.","how_it_worked":"The borrower supplied invoices purporting to come from large international telecom carriers as collateral for a revolving credit facility, backed by supporting correspondence from email domains crafted to look like those carriers. Credit analysts and underwriters accepted the documents as third-party confirmation of real receivables, and the pattern held for roughly five years because each new drawdown was validated against the same fabricated paper trail. The deception unravelled only when an HPS analyst compared the email domains on the invoices against the real carriers' domains and found mismatches, then found the same discrepancy repeatedly across the portfolio.","lessons":"Out-of-band verification of receivables directly with the named obligor, using contact details sourced independently rather than from the borrower's own documents, would have exposed the fabricated counterparties years earlier.","confidence":"Reported","sources":[{"title":"US Probes Telecom Firms After BlackRock's HPS Uncovers Alleged $400M Fraud","url":"https://www.usnews.com/news/top-news/articles/2025-11-17/us-probes-telecom-firms-after-blackrocks-hps-uncovers-alleged-400m-fraud-financial-times-reports","publisher":"U.S. News / Reuters"},{"title":"How Fake Invoices Duped BlackRock Unit Into a $400 Million Loan (WSJ)","url":"https://www.securitiesdocket.com/2026/02/11/how-fake-invoices-duped-blackrock-unit-into-a-400-million-loan-wsj/","publisher":"Securities Docket / The Wall Street Journal"},{"title":"BlackRock Unit Flags Suspected $400 Million Fraud, Triggering U.S. Probe of Telecom Firms","url":"https://finance.yahoo.com/news/blackrock-unit-flags-suspected-400-150656293.html","publisher":"Yahoo Finance / Bloomberg"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre"},{"title":"Aflac breached in insurance-sector social engineering campaign; 22.6M affected","date":"2025-06-12","date_precision":"day","victim_org":"Aflac","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No public reporting attributes AI-generated voice to the Aflac intrusion.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed; Aflac offered 24 months of credit monitoring, identity theft and medical fraud protection.","records_affected":22650000,"threat_actor":"Not confirmed by Aflac; reporting points to Scattered Spider's 2025 insurance-sector campaign","summary":"Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.","how_it_worked":"Aflac has not published the intrusion mechanics beyond describing a sophisticated cybercrime group and an industry-wide campaign, so the vector here is characterised from the campaign rather than from Aflac's own disclosure. Google Threat Intelligence, warning insurers during the same weeks, told the sector to pay particular attention to social engineering attempts against help desks and call centres, the route the same crews had used against retail and hospitality: a phone call impersonating staff to obtain credential or MFA resets, then rapid data collection with no malware deployed.","lessons":"Identity verification standards for help desks and call centres, applied to both employee and customer channels, is the control the sector was explicitly warned to strengthen.","confidence":"Confirmed","sources":[{"title":"Aflac discloses breach amidst Scattered Spider insurance attacks","url":"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/","publisher":"BleepingComputer"},{"title":"22M Affected by Aflac Data Breach","url":"https://www.securityweek.com/22-million-affected-by-aflac-data-breach/","publisher":"SecurityWeek"},{"title":"Aflac confirms June data breach affecting over 22 million customers","url":"https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html","publisher":"Security Affairs"},{"title":"Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised","url":"https://www.hipaajournal.com/aflac-data-breach/","publisher":"The HIPAA Journal"},{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff"},{"title":"Erie Insurance hit in Scattered Spider help desk campaign against insurers","date":"2025-06","date_precision":"month","victim_org":"Erie Insurance","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.","how_it_worked":"The intrusion set relied on service-desk manipulation rather than exploitation. An operator called the help desk holding enough identifying information to impersonate a named employee, asked for an MFA enrolment link to be issued for a supposed new mobile device, and once that device was trusted, used self-service password reset to seize the account outright. Researchers noted the technique was effective across multiple insurers precisely because help desks follow an identical procedure no matter who calls, so a single credible pretext worked repeatedly.","lessons":"Identity proofing that a caller cannot supply from public or previously breached data, such as manager callback or a live video ID check, is the control that breaks this chain.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure"},{"title":"Philadelphia Insurance Companies disclosed breach in insurer-focused campaign","date":"2025-06","date_precision":"month","victim_org":"Philadelphia Insurance Companies","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.","how_it_worked":"Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.","lessons":"Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"},{"slug":"2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million","title":"Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers","date":"2025-05-29","date_precision":"day","year":2025,"victim_org":"Farmers Insurance","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1100000,"threat_actor":"ShinyHunters, working with UNC6040 / UNC6240","summary":"Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.","how_it_worked":"In this campaign the caller poses as internal IT or a support desk and tells the employee that a routine tool needs to be connected to the company's Salesforce tenant. The employee is walked to Salesforce's legitimate connected-app authorisation page and given an eight-digit connection code supplied by the attacker, which they enter and approve. Because every screen the employee sees is a real Salesforce page, the trust signal is Salesforce's own interface, not a spoofed one. Approval binds an attacker-controlled data-extraction application to the tenant with the employee's permissions, after which records can be pulled in bulk without any further interaction.","lessons":"Limiting the connected-app authorisation permission to a small admin group and blocking uninstalled or unapproved apps by default removes the single click that this pretext is engineered to obtain.","confidence":"Reported","sources":[{"title":"Farmers Insurance data breach impacts 1.1M people after Salesforce attack","url":"https://www.bleepingcomputer.com/news/security/farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack/","publisher":"BleepingComputer"},{"title":"Farmers Insurance Data Breach Affects 1.1 Million Customers","url":"https://www.secureworld.io/industry-news/farmers-insurance-data-breach","publisher":"SecureWorld"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million"},{"title":"UK 'safe account' bank and police impersonation drives £450.7M in APP fraud","date":"2025-05-19","date_precision":"day","victim_org":"UK banking customers (multi-victim campaign)","sector":"Financial Services","country":"United Kingdom","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"UK Finance's 2024 reporting does not break out AI-enabled impersonation as a separate category.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Credential Theft"],"loss_usd":null,"loss_note":"Losses are reported in sterling: £1.17 billion total fraud in 2024, of which £450.7 million was authorised push payment fraud (£365.7 million personal and £84.9 million non-personal) across under 186,000 cases. Safe account impersonation losses fell 16 percent and cases fell 32 percent year on year.","records_affected":186000,"threat_actor":null,"summary":"UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.","how_it_worked":"A caller presents as the victim's bank fraud team or as police, often after a preparatory text or a spoofed caller ID matching the number on the back of the bank card. The victim is told their account has been compromised by a criminal, potentially an insider at the bank, and that the only way to protect the balance is to transfer it immediately to a new safe account which the caller supplies. Because the victim authorises the payment themselves, normal card fraud controls do not apply. The levers are institutional authority, fear of loss, and the instruction not to discuss it with branch staff who might be complicit.","lessons":"No bank or police force ever asks a customer to move money to a safe account; confirmation of payee checks, in-app warnings at the point of transfer and mandatory delays on first-time large payees are the effective controls.","confidence":"Confirmed","sources":[{"title":"Fraud continues to pose a major threat with over £1 billion stolen in 2024","url":"https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2025-press-release","publisher":"UK Finance"},{"title":"Smishing: Package Tracking Text Scams","url":"https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams","publisher":"United States Postal Inspection Service"}],"entry_type":"campaign","slug":"2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud"},{"slug":"2025-vc-firm-insight-partners-breached-through-social-engineering-attack","title":"VC firm Insight Partners breached through social engineering attack","date":"2025-01","date_precision":"month","year":2025,"victim_org":"Insight Partners","sector":"Financial Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.","how_it_worked":"Insight Partners stated publicly that the intrusion was the result of a social engineering attack rather than an exploited vulnerability. Investment firms are a high-value pretext environment: staff routinely exchange documents and wire instructions with founders, co-investors, lawyers and limited partners they have never met in person, so an approach from an unfamiliar sender referencing a live deal reads as normal. The attackers used that trust to obtain access to internal systems, then spent time collecting fund-level financial data, banking and tax details for individuals, and transaction records, before the activity was detected and remediated.","lessons":"For deal-driven firms, phishing-resistant MFA plus verified out-of-band confirmation for any document or credential request from outside the firm is the control that matters.","confidence":"Confirmed","sources":[{"title":"Statement from Insight Partners on Cyber Incident","url":"https://www.insightpartners.com/ideas/statement-from-insight-partners-on-cyber-incident/","publisher":"Insight Partners"},{"title":"VC giant Insight Partners notifies staff and limited partners after data breach","url":"https://techcrunch.com/2025/09/17/vc-giant-insight-partners-notifies-staff-and-limited-partners-after-data-breach/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-vc-firm-insight-partners-breached-through-social-engineering-attack"},{"title":"FBI: business email compromise exposed $43 billion in losses across 177 countries","date":"2022-05-04","date_precision":"day","victim_org":"Businesses, government entities and individuals worldwide (multi-victim campaign)","sector":"Financial Services","country":"Global","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"The 2022 advisory does not describe AI-enabled BEC.","outcomes":["Wire Fraud / Financial Loss","Data Breach","Cryptocurrency Theft"],"loss_usd":43312749946,"loss_note":"$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.","records_affected":241206,"threat_actor":null,"summary":"On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.","how_it_worked":"BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.","lessons":"Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.","confidence":"Confirmed","sources":[{"title":"Business Email Compromise: The $43 Billion Scam","url":"https://www.ic3.gov/PSA/2022/PSA220504","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co","year":2022,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"},{"slug":"2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom","title":"Robinhood support employee socially engineered by phone; 7 million customers exposed","date":"2021-11-03","date_precision":"day","year":2021,"victim_org":"Robinhood Markets","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"An extortion demand was made; Robinhood said it reported the demand to law enforcement rather than paying.","records_affected":7000000,"threat_actor":null,"summary":"On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.","how_it_worked":"The attack was a phone call, not an email. The caller reached a customer support employee and, over the course of the conversation, obtained access to support tooling, most plausibly by presenting as internal IT or as an authorised colleague needing assistance. Support staff are the ideal target for this because their entire job is to be helpful under time pressure to people they cannot see, and their tooling is broad by design: a single support console can query millions of customer records. Robinhood confirmed no Social Security numbers, bank account numbers or debit card numbers were exposed, but the breadth of the customer list made the extortion attempt credible.","lessons":"Support consoles need per-record justification, rate limits and bulk-export alerting, and any inbound request for support access should be verified through an internal directory callback.","confidence":"Confirmed","sources":[{"title":"Robinhood data breach affects 7 million customers","url":"https://fortune.com/2021/11/08/robinhood-data-breach-7-million-customers","publisher":"Fortune"},{"title":"Robinhood Data Breach Leads Data Events in November","url":"https://www.idtheftcenter.org/post/robinhood-data-breach-leads-data-events-november-number-data-compromises-reaches-all-time-high/","publisher":"Identity Theft Resource Center"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom"},{"title":"Sequoia Capital investor data exposed after employee falls for phishing email","date":"2021-02","date_precision":"month","victim_org":"Sequoia Capital","sector":"Financial Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed; the associated fraudulent transfer attempt was reported as unsuccessful.","records_affected":null,"threat_actor":null,"summary":"Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.","how_it_worked":"An employee at the firm received and acted on a phishing email, handing over credentials that gave the attacker access to their corporate mailbox. The intruder used that mailbox to read stored correspondence containing investor personal and financial details, and attempted to leverage the account for fraudulent payment instructions in the style of a business email compromise, which was not successful. Sequoia notified affected limited partners, engaged outside investigators and law enforcement, and offered credit monitoring. No malware deployment or wider network intrusion was reported.","lessons":"Phishing-resistant MFA on cloud mailboxes plus alerting on anomalous mailbox rules and sign-in locations catches this pattern in hours rather than weeks.","confidence":"Reported","sources":[{"title":"Scoop: Sequoia Capital says it was hacked","url":"https://www.axios.com/2021/02/20/sequoia-capital-says-it-was-hacked","publisher":"Axios"},{"title":"VC Giant Sequoia Capital Informs Investors of Data Breach","url":"https://www.securityweek.com/vc-giant-sequoia-capital-informs-investors-data-breach/","publisher":"SecurityWeek"},{"title":"VC giant Sequoia Capital discloses data breach after failed BEC attack","url":"https://www.bleepingcomputer.com/news/security/vc-giant-sequoia-capital-discloses-data-breach-after-failed-bec-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing"},{"title":"Cloned company director's voice used in US$35M bank transfer fraud","date":"2020","date_precision":"year","victim_org":"Unnamed company and its bank; investigated by UAE authorities","sector":"Financial Services","country":"United Arab Emirates","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Business Email Compromise","Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"UAE investigators stated in court filings that the fraudsters used 'deep voice' technology to clone a company director's speech for the phone call. The specific tooling was not established publicly.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":35000000,"loss_note":"Up to US$35 million per UAE court documents; US$400,000 traced to two US accounts at Centennial Bank","records_affected":null,"threat_actor":null,"summary":"In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.","how_it_worked":"The pretext was a confidential corporate acquisition that required the branch to release large sums quickly. The channel was a phone call from a person whose voice the manager had heard before, reinforced by a parallel email thread from the same director and from an outside lawyer retained to coordinate the deal, which is a familiar and legitimising pattern in M&A work. Secrecy was built into the story, so the manager had a reason not to ask colleagues. The layered corroboration between a recognised voice and matching documentation removed his doubt, and the transfers were executed before anyone verified through an independent channel.","lessons":"Any acquisition-related payment instruction should require verification through a pre-established channel with a named counterparty, not the contact details supplied inside the request itself.","confidence":"Reported","sources":[{"title":"Fraudsters Cloned Company Director's Voice In $35 Million Bank Heist, Police Find","url":"https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/","publisher":"Forbes"},{"title":"Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme","url":"https://incidentdatabase.ai/cite/147/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud","year":2020,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud"},{"title":"Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails","date":"2016-02","date_precision":"month","victim_org":"Bangladesh Bank (central bank of Bangladesh)","sector":"Financial Services","country":"Bangladesh","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss","Service Disruption"],"loss_usd":81000000,"loss_note":"$101 million in fraudulent SWIFT transfers were executed, of which $81 million reached accounts in the Philippines and about $20 million sent to Sri Lanka was blocked; a portion of the Philippine funds was later recovered, leaving roughly $65 million outstanding.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); US DOJ charged Park Jin Hyok in 2018","summary":"In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.","how_it_worked":"Emails from a fabricated job-seeker persona were sent to Bangladesh Bank employees with a link to a résumé hosted externally; retrieving it delivered malware that established remote access. The attackers dwelled for about a year, mapping the bank's network and the workstation used for SWIFT Alliance Access. They then deployed custom malware that manipulated the SWIFT client's database and print output so fraudulent messages would not appear on the confirmation printer, issued transfer instructions to the New York Fed over a weekend, and routed proceeds through Philippine bank accounts and casino junkets to launder them.","lessons":"Isolating the SWIFT terminal on its own segment with application allow-listing, and independent reconciliation of outbound payment messages, would have caught both the intrusion path and the tampered confirmations.","confidence":"Reported","sources":[{"title":"Hackers took years before stealing $81m from Bangladesh Bank: FBI","url":"https://www.newagebd.net/print/article/141463","publisher":"New Age Bangladesh"},{"title":"When North Korean hackers almost pulled off a billion-dollar heist from Bangladesh Bank","url":"https://www.thedailystar.net/tech-startup/news/when-north-korean-hackers-almost-pulled-billion-dollar-heist-bangladesh-bank-2115317","publisher":"The Daily Star"},{"title":"Lessons Learned From the Bangladesh Bank Heist","url":"https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/lessons-learned-from-the-bangladesh-bank-heist","publisher":"ISACA Journal"}],"entry_type":"incident","slug":"2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin"},{"title":"Belgian bank Crelan loses €70 million to CEO-fraud payment orders","date":"2016-01","date_precision":"month","victim_org":"Crelan NV/SA","sector":"Financial Services","country":"Belgium","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":75800000,"loss_note":"€70 million (about $75.8 million). The bank said reserves absorbed the loss and customers were not affected.","records_affected":null,"threat_actor":null,"summary":"Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.","how_it_worked":"The scheme attacked a bank's own treasury payment process rather than customer accounts. Fraudsters used a compromised or spoofed executive mailbox to issue payment instructions to finance staff, relying on the authority of the sender and on urgency and confidentiality to suppress questions. Because the orders came through the expected internal channel and carried apparently legitimate executive approval, they were processed without out-of-band confirmation. The diversion went undetected until routine internal audit work flagged irregularities, at which point the funds had already left the institution. Crelan reported the matter to prosecutors and reviewed its internal control framework.","lessons":"Internal payment instructions deserve the same scrutiny as external ones: even executive-originated transfers should require verification through a separate channel and a segregation-of-duties check before release.","confidence":"Confirmed","sources":[{"title":"Belgian bank Crelan loses €70 million to BEC scammers","url":"https://www.helpnetsecurity.com/2016/01/26/belgian-bank-crelan-loses-e70-million-to-bec-scammers/","publisher":"Help Net Security"}],"entry_type":"incident","slug":"2016-belgian-bank-crelan-loses-70-million-to-ceo-fraud-payment-orders","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-belgian-bank-crelan-loses-70-million-to-ceo-fraud-payment-orders"},{"title":"Xoom Corporation loses $30.8 million to employee impersonation fraud","date":"2014-12-30","date_precision":"day","victim_org":"Xoom Corporation","sector":"Financial Services","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":30800000,"loss_note":"$30.8 million of corporate cash transferred to overseas accounts. The company said no customer data or customer funds were involved.","records_affected":null,"threat_actor":null,"summary":"Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.","how_it_worked":"The attackers directed impersonated internal requests at Xoom's finance department, the function authorized to move corporate treasury cash. Posing as company personnel, they issued transfer instructions that fit the company's own internal request format, so the payments were processed as legitimate corporate disbursements rather than customer transactions. The money went to accounts abroad and was not recovered. Xoom emphasized that its systems were not breached and no customer funds or data were touched, underscoring that the failure was in the human approval chain for corporate wires. The board's response included an independent investigation, a review of internal controls, and the immediate departure of the CFO.","lessons":"Corporate treasury disbursement requests should be authenticated in a workflow system with enforced separation of duties, never accepted as an emailed instruction that appears to come from a colleague.","confidence":"Confirmed","sources":[{"title":"Xoom Corporation Form 8-K (filed January 5, 2015)","url":"https://www.sec.gov/Archives/edgar/data/1315657/000110465915000360/a15-1144_18k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud","year":2014,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud"}]}