{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:32.724Z","total":27,"returned":27,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre","title":"Armored Likho spear phishing targets government and power sector in three countries","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Government agencies and electric power organisations in Russia, Brazil and Kazakhstan","sector":"Government","country":"Russia","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Armored Likho (overlaps with Eagle Werewolf)","summary":"Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.","how_it_worked":"The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.","lessons":"Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.","confidence":"Confirmed","sources":[{"title":"Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer","url":"https://thehackernews.com/2026/07/armored-likho-targets-government.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre"},{"slug":"2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag","title":"FBI identifies North Korean remote IT worker employed by a US federal agency","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Unnamed US federal agency","sector":"Government","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Insider Access","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker programme","summary":"FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.","how_it_worked":"The DPRK remote IT worker programme wins access by being hired rather than by breaking in. Operatives apply for remote technical roles using stolen or fabricated identities, often with US-based facilitators who host company laptops, sit for identity checks, or lend a domestic address and bank account so that pay and equipment appear to land with a real person in the United States. Video interviews and onboarding checks are handled by the operative or the facilitator. Once employed the worker holds legitimate credentials and normal access, which is why detection typically comes from behavioural or payroll anomalies rather than security tooling.","lessons":"Live identity proofing at hire and again at equipment issue, plus checks that payroll destinations and laptop network locations match the claimed residence, are what surface these placements.","confidence":"Confirmed","sources":[{"title":"FBI investigating North Korean remote IT staffer working for US agency","url":"https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/","publisher":"Federal News Network"},{"title":"FBI finds North Korean IT worker inside federal agency","url":"https://www.thestreet.com/employment/fbi-north-korean-remote-worker-insider-threat-2026","publisher":"TheStreet"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag"},{"slug":"2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca","title":"City of Aurora loses $1.1M after employee falls for bank impersonation call","date":"2026-04-29","date_precision":"day","year":2026,"victim_org":"City of Aurora, Illinois","sector":"Government","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":1100000,"loss_kind":"direct_loss","loss_note":"USD, approximately $1.1 million taken from municipal payroll accounts. Recovery efforts ongoing with law enforcement and the bank; the city carries insurance covering losses of this type.","records_affected":null,"threat_actor":null,"summary":"On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.","how_it_worked":"The pretext was routine banking business and the identity impersonated was the city's own financial institution, the party a finance employee expects to hear from about account matters. Officials described these schemes as exploiting trust and manufacturing urgency, and the deception worked purely by phone; nothing was hacked. The employee supplied account credentials or verification details during the call, which the fraudster immediately used to authorise transfers out of city payroll accounts. Discovery came shortly after the payments cleared.","lessons":"A hard rule that no banking detail or verification code is ever given on an inbound call, only on a callback to a number held on file, plus bank-side dual authorisation on outbound transfers.","confidence":"Confirmed","sources":[{"title":"Aurora lost nearly $1.1M from city bank accounts after employee fell for phone scam, officials say","url":"https://www.nbcchicago.com/news/local/aurora-lost-1-1m-from-city-bank-accounts-after-employee-fell-for-phone-scam-officials-say/3939104/","publisher":"NBC Chicago"},{"title":"'Social Engineering Fraud' Cost Aurora, Ill., Nearly $1.1M","url":"https://www.govtech.com/security/social-engineering-fraud-cost-aurora-ill-nearly-1-1m","publisher":"Government Technology"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca"},{"slug":"2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov","title":"FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government","date":"2026-01-08","date_precision":"day","year":2026,"victim_org":"Think tanks, academic institutions and government entities","sector":"Government","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Spear Phishing (Email)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Kimsuky (APT43)","summary":"The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.","how_it_worked":"Kimsuky wrote emails in the voice of a diplomat or embassy employee inviting a policy expert to an event or a document review, and placed the link inside a QR code rather than as clickable text. Scanning moved the victim off the monitored corporate desktop onto a personal phone, where enterprise mail filtering and endpoint detection do not reach, and onto a spoofed Google or document-portal sign-in. The FBI noted these operations frequently end in session token theft and replay, which defeats multi-factor authentication because the attacker never faces the login challenge.","lessons":"Treat QR codes in inbound mail as untrusted links and render them for inspection at the gateway; bind sessions to device posture so a stolen token cannot be replayed from unmanaged hardware.","confidence":"Confirmed","sources":[{"title":"FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing","url":"https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html","publisher":"The Hacker News"},{"title":"FBI FLASH AC-000001-MW, 08 January 2026","url":"https://www.ic3.gov/CSA/2026/260108.pdf","publisher":"FBI / IC3"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov"},{"title":"Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers","date":"2025-06","date_precision":"month","victim_org":"US State Department; three foreign ministers, a US governor and a member of Congress","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"A State Department cable described an impostor using AI-generated voice and text to mimic Secretary of State Marco Rubio, leaving Signal voicemails for at least two targets.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.","how_it_worked":"The impostor exploited the fact that senior diplomats routinely use Signal for informal contact, so a message from an account labelled with the Secretary's official email address fit the expected pattern. Rather than opening with a request, the actor left short voicemails in a cloned voice and sent texts inviting the target to continue the conversation on Signal, which builds familiarity before anything is asked. The trust signal was the combination of a recognisable voice and a display name resembling a state.gov address, neither of which is authenticated by the platform. Targets who engaged would then have been positioned for requests for information or for account access.","lessons":"Display names and voices are not identity: diplomatic contact should be initiated or confirmed through embassy and ministry channels, and platforms used for official business need verified organisational identity.","confidence":"Confirmed","sources":[{"title":"Imposter used AI to pose as Marco Rubio and contact foreign ministers","url":"https://feeds.bbci.co.uk/news/articles/crrqkyyjewno","publisher":"BBC News"},{"title":"A Marco Rubio impostor is using AI voice to call high-level officials","url":"https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/","publisher":"The Washington Post"}],"entry_type":"incident","slug":"2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore"},{"title":"FBI warns of AI voice-cloning campaign impersonating senior US officials","date":"2025-05-15","date_precision":"day","victim_org":"Current and former senior US federal and state officials and their contacts","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The FBI stated that malicious actors were sending AI-generated voice messages, alongside text messages, that purported to come from senior US officials.","outcomes":["Credential Theft","Identity Theft","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.","how_it_worked":"The campaign traded on the recipient's relationship with a named senior official rather than on any technical exploit. An initial text or voicemail in a cloned voice established that the official was reaching out personally, which for a colleague or former colleague is unremarkable. Once a reply came, targets were invited to continue on a separate messaging platform, a request that reads as security-conscious in government circles, and the link supplied there led to a credential-harvesting page or a device-linking flow. Each successful compromise fed the next round, since messages arriving from a genuinely compromised official account carry far more weight than any spoof.","lessons":"Officials and their contacts should verify unexpected outreach through a separately known number or channel, and adopt phishing-resistant authentication on personal accounts, which are typically the weak point rather than official systems.","confidence":"Confirmed","sources":[{"title":"Senior US Officials Impersonated in Malicious Messaging Campaign (PSA250515)","url":"https://www.ic3.gov/PSA/2025/PSA250515","publisher":"FBI Internet Crime Complaint Center"},{"title":"FBI warns senior US officials are being impersonated using texts, AI-based voice cloning","url":"https://www.cybersecuritydive.com/news/fbi-us-officials-impersonated-text-ai-voice/748334/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","slug":"2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials"},{"title":"AI voice impersonation of White House chief of staff Susie Wiles targets Republicans","date":"2025-05","date_precision":"month","victim_org":"The White House; senators, governors and business executives contacted","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Officials cited by news reports believed the impersonator used AI to replicate Susie Wiles's voice on phone calls; the contact list appears to have come from her compromised personal phone.","outcomes":["Identity Theft","Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.","how_it_worked":"The attack started from a compromised personal phone, which supplied both the target list and the context needed to make each approach specific. Messages and calls appeared to come from someone recipients genuinely deal with, and the requests, a pardon shortlist or a favour involving money, are the kind of sensitive, informal business that plausibly happens by phone rather than through official channels precisely because it is delicate. The cloned voice removed the last check most recipients would apply. Suspicion emerged from content rather than technology: some recipients noticed the requests did not match how Wiles operates, and the messages came from an unfamiliar number.","lessons":"Senior staff should keep official business off personal devices and pre-agree verification practices with frequent contacts, so that an unexpected request from a new number is confirmed before anyone acts.","confidence":"Reported","sources":[{"title":"White House responds to attempts to impersonate Trump advisor Susie Wiles","url":"https://www.newsweek.com/white-house-susie-wiles-trump-impersonate-fbi-2078802","publisher":"Newsweek"},{"title":"Trump officials keep getting targeted by 'vishing'","url":"https://time.com/7301176/impersonation-ai-voice-vishing-scam-rubio-wiles-trump-fbi-advice/","publisher":"TIME"}],"entry_type":"incident","slug":"2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets"},{"slug":"2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts","title":"Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts","date":"2025-02-13","date_precision":"day","year":2025,"victim_org":"Multiple government, NGO, defence and energy organisations","sector":"Government","country":"Multiple","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Storm-2372 (assessed Russian-aligned)","summary":"Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.","how_it_worked":"The actor built rapport first, messaging targets over WhatsApp, Signal or Teams while posing as a prominent person relevant to the victim's work. It then sent what looked like an invitation to a Teams meeting or a document, containing a genuine Microsoft device code page and a code to type in. Because the sign-in page was real Microsoft infrastructure and the victim entered the code themselves, the flow looked entirely legitimate and MFA prompts appeared expected. Completing it issued the attacker valid access and refresh tokens for the victim's account, giving persistent mailbox and file access without ever handling a password.","lessons":"Disable the device code authentication flow where it is not needed via Conditional Access, and train staff that a legitimate meeting invitation never requires typing a code into a separate sign-in page.","confidence":"Confirmed","sources":[{"title":"Storm-2372 conducts device code phishing campaign","url":"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/","publisher":"Microsoft Security"},{"title":"Phishing campaign targets Microsoft device-code authentication flows","url":"https://www.cybersecuritydive.com/news/phishing-campaign-targets-microsoft-device-code-authentication-flows/740201/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts"},{"title":"US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM","date":"2024-09","date_precision":"month","victim_org":"Office of US Senator Ben Cardin, Senate Foreign Relations Committee","sector":"Government","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Senate security officials described the video call participant as an apparent deepfake of former Ukrainian foreign minister Dmytro Kuleba that matched his appearance and voice from prior encounters.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.","how_it_worked":"The pretext exploited a routine of the job: a foreign official Cardin had genuinely met requesting a follow-up video call on a live policy question. Because the identity was plausible and the scheduling followed normal staff channels, the meeting went ahead without independent verification through the State Department. On camera the deepfake supplied the visual and vocal confirmation staff expected. The impersonator then pushed for on-the-record statements that could be clipped and weaponised, applying pressure by demanding immediate answers. The tell was behavioural rather than technical: the real Kuleba would not badger a committee chair for soundbites, and the mismatch in conduct ended the call.","lessons":"Legislative offices should route requests for meetings with foreign officials through the State Department or the relevant embassy for confirmation before a call is scheduled.","confidence":"Reported","sources":[{"title":"Ben Cardin targeted in apparent deepfake call with someone posing as Dmytro Kuleba","url":"https://www.nbcnews.com/politics/congress/ben-cardin-targeted-apparent-deep-fake-call-dmytro-kuleba-rcna172776","publisher":"NBC News"},{"title":"Elaborate Deepfake Operation Takes a Meeting With US Senator","url":"https://www.darkreading.com/cyberattacks-data-breaches/elaborate-deepfake-operation-meeting-us-senator","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s"},{"title":"Iran's APT42 phishes Israeli and US officials with think-tank impersonation","date":"2024-08-14","date_precision":"day","victim_org":"Current and former Israeli and US government officials, diplomats and political campaign staff","sector":"Government","country":"Israel and United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No monetary loss; the objective was intelligence collection.","records_affected":null,"threat_actor":"APT42 / Charming Kitten (Iranian IRGC-linked)","summary":"On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.","how_it_worked":"APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.","lessons":"High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.","confidence":"Confirmed","sources":[{"title":"Iranian backed group steps up phishing campaigns against Israel, U.S.","url":"https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat"},{"slug":"2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200","title":"Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected","date":"2024-02-19","date_precision":"day","year":2024,"victim_org":"Los Angeles County Department of Public Health","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":200000,"threat_actor":null,"summary":"The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.","how_it_worked":"A phishing email circulated through the department and 53 separate employees entered their credentials on the attacker's page within roughly 24 hours, which shows the message was well matched to the environment rather than obviously fraudulent. With valid log-ins the attacker read the contents of those mailboxes, which in a county public health agency contain case correspondence carrying patient names, diagnoses, prescriptions and benefit identifiers. The department responded by disabling accounts, resetting devices, blocking the phishing sites and quarantining the messages, but by then two days of mailbox access across dozens of accounts had already occurred.","lessons":"Phishing-resistant MFA across county staff accounts would have made the harvested passwords useless, and rapid cross-department alerting would have cut the exposure window.","confidence":"Confirmed","sources":[{"title":"200,000 Impacted by Data Breach at Los Angeles County Public Health Agency","url":"https://www.securityweek.com/200000-impacted-by-data-breach-at-los-angeles-county-public-health-agency/","publisher":"SecurityWeek"},{"title":"Los Angeles Public Health Department Discloses Large Data Breach","url":"https://www.infosecurity-magazine.com/news/los-angeles-health-data-breach/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200"},{"title":"SIM swap of the SEC's X account posted a fake Bitcoin ETF approval","date":"2024-01-09","date_precision":"day","victim_org":"U.S. Securities and Exchange Commission","sector":"Government","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physically printed counterfeit ID card.","outcomes":["Identity Theft","Service Disruption","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"No direct loss to the SEC was published. The fake post moved bitcoin roughly $1,000 higher, then more than $2,000 lower once the SEC disclosed the compromise. Council was paid about $50,000 in bitcoin for performing SIM swaps and was ordered to forfeit that amount.","records_affected":null,"threat_actor":"Eric Council Jr. and co-conspirators","summary":"On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.","how_it_worked":"Council printed a counterfeit identification card on a portable card printer using personal details supplied by co-conspirators, then walked into an AT&T store in Huntsville, Alabama and asked for a replacement SIM for the number tied to the @SECgov account. Store staff issued it against the fake document. He activated the SIM in a newly purchased iPhone, received the password-reset code for the X account, and passed it to the conspirators, who posted the fabricated ETF approval. Bitcoin moved over $1,000 within minutes. The FBI later found fake-ID templates and searches about FBI investigations at his residence.","lessons":"High-consequence institutional social accounts should be secured with hardware security keys rather than SMS-based recovery, and carrier retail ID checks need document-authentication technology rather than visual inspection.","confidence":"Confirmed","sources":[{"title":"Alabama Man Sentenced in Hack of SEC X Account that Spiked the Value of Bitcoin","url":"https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin","publisher":"U.S. Department of Justice"},{"title":"Hacker pleads guilty to SIM swap attack on US SEC X account","url":"https://www.bleepingcomputer.com/news/security/hacker-pleads-guilty-to-sim-swap-attack-on-us-sec-x-account/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval"},{"title":"AI-cloned Biden robocall told New Hampshire voters to skip the primary","date":"2024-01","date_precision":"month","victim_org":"New Hampshire primary voters","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Political consultant Steve Kramer admitted commissioning an AI-cloned voice of President Biden for the robocall; the FCC's enforcement action describes the recording as AI-generated.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"FCC proposed a US$6 million forfeiture against Kramer; carrier Lingo Telecom settled for US$1 million","records_affected":null,"threat_actor":"Steven Kramer (political consultant)","summary":"On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.","how_it_worked":"The channel was an ordinary automated phone call with spoofed caller ID, arriving in the last hours before an election when voters have little time to check anything. The trust signal was the president's recognisable voice delivering a message in his own idiom, addressed to Democratic voters as if from the campaign itself. The persuasion was framed not as suppression but as helpful strategy, telling recipients their vote mattered more in November, which gave the instruction an internally consistent rationale. Because the medium is one-way and the timing left no room for correction, targets had no natural opportunity to verify before the primary took place.","lessons":"Carriers enforcing STIR/SHAKEN caller-ID attestation on upstream customers, plus rapid election-authority rebuttal channels, are the practical controls; voters should treat any voting instruction by phone as unverified.","confidence":"Confirmed","sources":[{"title":"FCC Proposes $6 Million Fine For Illegal Robocalls That Used Deepfake AI Voice","url":"https://docs.fcc.gov/public/attachments/DOC-402762A1.pdf","publisher":"US Federal Communications Commission"},{"title":"Criminal charges and FCC fines issued for deepfake Biden robocalls","url":"https://www.npr.org/2024/05/23/nx-s1-4977582/fcc-ai-deepfake-robocall-biden-new-hampshire-political-operative","publisher":"NPR"}],"entry_type":"incident","slug":"2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary"},{"title":"European mayors duped by deepfake video calls posing as Kyiv mayor Klitschko","date":"2022-06","date_precision":"month","victim_org":"City governments of Berlin, Madrid and Vienna","sector":"Government","country":"Germany","primary_vector":"Deepfake Video Call","secondary_vectors":[],"ai_involvement":"Suspected AI-enabled","ai_notes":"Berlin's mayoral office concluded after the call that deepfake technology had been used to render Vitali Klitschko's face and voice in a live video conference; other analysts suggested edited genuine footage may have been used instead.","outcomes":["Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In June 2022 the mayors of Berlin (Franziska Giffey), Madrid (Jose Luis Martinez-Almeida) and Vienna (Michael Ludwig) each held video calls with someone presenting as Kyiv mayor Vitali Klitschko. Giffey's office said the call was cut short when the topics and framing became implausible, and concluded a deepfake had been used. Klitschko linked the calls to Russian efforts to drive a wedge between Ukraine and its European partners. Attribution was never publicly established.","how_it_worked":"The approach exploited an entirely normal wartime diplomatic pattern: European capitals were actively arranging solidarity calls with Ukrainian city leaders, so an inbound request for a video meeting with Klitschko fit expectations and passed through official scheduling channels. On camera the impersonator looked and sounded like a figure the mayors had seen in constant media coverage, which supplied the trust signal. The caller then steered the conversation toward politically loaded subjects, apparently to elicit quotable statements about Ukrainian refugees and support for Ukraine. Berlin's staff aborted only when the substance of the conversation, rather than the imagery, stopped making sense.","lessons":"Video identity is not authentication; inbound requests for calls with senior officials should be confirmed through the counterpart's own foreign ministry or embassy channel before the meeting is booked.","confidence":"Reported","sources":[{"title":"European mayors duped into calls with fake Kyiv mayor","url":"https://www.clickorlando.com/news/world/2022/06/25/european-mayors-duped-into-calls-with-fake-kyiv-mayor/","publisher":"Associated Press"},{"title":"European mayors duped into calls with fake Kyiv mayor","url":"https://www.cnbc.com/2022/06/25/european-mayors-duped-into-calls-with-fake-kyiv-mayor.html","publisher":"CNBC"}],"entry_type":"incident","slug":"2022-european-mayors-duped-by-deepfake-video-calls-posing-as-kyiv-mayor-klits","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-european-mayors-duped-by-deepfake-video-calls-posing-as-kyiv-mayor-klits"},{"title":"Ghostwriter credential phishing against Ukrainian government and military accounts","date":"2022-05","date_precision":"month","victim_org":"Ukrainian government and military personnel","sector":"Government","country":"Ukraine","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Credential Theft","Espionage","Attempt Blocked"],"loss_usd":null,"loss_note":"No monetary loss; Google reported no accounts were compromised in the Ghostwriter campaign it described.","records_affected":null,"threat_actor":"Ghostwriter / UNC1151 (Belarus-attributed), alongside APT28 and Turla activity","summary":"Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.","how_it_worked":"Ghostwriter sent messages containing links to legitimate but compromised third-party websites that hosted the first-stage phishing page, which lends the URL an innocuous reputation and defeats simple domain blocklists. Users who clicked were redirected to attacker-controlled infrastructure presenting a replica webmail sign-in page, where entered credentials were captured. The campaign leaned on wartime urgency and the volume of official correspondence flowing to government and military staff, conditions in which recipients process messages quickly and are primed to expect unfamiliar senders and new systems.","lessons":"Enrolling government and military accounts in advanced protection with hardware security keys, and treating links to unfamiliar third-party sites as untrusted regardless of domain reputation, blocks this class of harvesting.","confidence":"Confirmed","sources":[{"title":"Update on cyber activity in Eastern Europe","url":"https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar"},{"slug":"2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak","title":"Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover","date":"2021-07","date_precision":"month","year":2021,"victim_org":"Town of Peterborough, New Hampshire","sector":"Government","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2300000,"loss_kind":"direct_loss","loss_note":"About US$2.3 million diverted, roughly 15 percent of the town's annual budget; the US Secret Service recovered US$594,331 that had not yet been converted to cryptocurrency.","records_affected":null,"threat_actor":null,"summary":"The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.","how_it_worked":"After taking over a town finance employee's email account, the attackers read the genuine correspondence with two payees, the regional school district and a bridge construction contractor, both of which had asked to be paid by electronic transfer. They then inserted themselves into those live threads with revised banking details, and deleted the payees' incoming emails so that the real counterparties' queries never reached town staff. The town had procedures requiring notarised change forms and confirmatory phone calls, but staff who were supposed to check each other's work did not follow them, which is what let the diverted payments clear.","lessons":"Existing verification procedures only work if they are enforced; mailbox rule creation and mass deletion in a finance account should also raise an automatic alert.","confidence":"Confirmed","sources":[{"title":"Peterborough payment scam: Single compromised email account led to $2.3M theft","url":"https://ledgertranscript.com/2021/10/05/pbscam-ml-100521-42830401/","publisher":"Monadnock Ledger-Transcript"},{"title":"Cyber-thieves Scam New Hampshire Town Out of $2.3m","url":"https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak"},{"title":"Scattered Canary floods Washington's pandemic unemployment system with fake claims","date":"2020-05","date_precision":"month","victim_org":"Washington State Employment Security Department","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Reported as hundreds of millions of dollars; the state had not determined a final figure at the time of reporting, and a substantial portion was later recovered.","records_affected":null,"threat_actor":"Scattered Canary (Nigeria-based fraud ring)","summary":"In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.","how_it_worked":"The ring assembled identity packages from earlier consumer data breaches, giving them the Social Security numbers, dates of birth and addresses of real Washington workers. They registered claims using disposable email services and Gmail address variations so that a single controlled inbox could receive correspondence for many claimants, and they targeted the enhanced $600 weekly federal supplement, which raised the payout per fraudulent claim. Benefit payments were then directed to out-of-state bank accounts held by recruited mules. The pretext succeeded because the agency, overwhelmed by unprecedented claim volume, had relaxed verification to speed payments.","lessons":"Identity proofing and cross-matching against employer wage records must not be suspended under surge conditions; duplicate-contact and out-of-state-payee detection would have surfaced the ring early.","confidence":"Reported","sources":[{"title":"How missed 'red flags' helped Nigerian fraud ring 'Scattered Canary' bilk Washington's unemployment system amid coronavirus chaos","url":"https://www.spokesman.com/stories/2020/may/25/how-missed-red-flags-helped-nigerian-fraud-ring-sc/","publisher":"The Spokesman-Review / The Seattle Times"}],"entry_type":"incident","slug":"2020-scattered-canary-floods-washington-s-pandemic-unemployment-system-with-f","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-scattered-canary-floods-washington-s-pandemic-unemployment-system-with-f"},{"title":"Puerto Rico government agency sends $2.6 million to fraudulent account","date":"2020-01-17","date_precision":"day","victim_org":"Puerto Rico Industrial Development Company (PRIDCO)","sector":"Government","country":"Puerto Rico","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2600000,"loss_note":"$2.6 million transferred on January 17, 2020. Recovery outcome not confirmed in the cited reporting.","records_affected":null,"threat_actor":null,"summary":"Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.","how_it_worked":"The scheme exploited an inter-agency remittance payment process in which large periodic transfers are routine and the receiving party is trusted. The fraudulent email announced a change of banking details for those remittances, a message finance staff had reason to expect from time to time, and gave no cause for alarm because it referenced a genuine payment relationship. Officials updated the destination details and executed the scheduled payment of $2.6 million into the criminals' account. The loss surfaced only when the legitimate recipient's non-receipt was noticed, by which time the funds had left the account, prompting a complaint to police and a wider review of government payment controls.","lessons":"Government payment offices need a standing rule that account-change notices are never actioned from email alone, plus periodic reconciliation with recipients to catch a diversion within days rather than weeks.","confidence":"Confirmed","sources":[{"title":"Official says Puerto Rico government lost $2.6M in phishing scam","url":"https://www.pbs.org/newshour/nation/official-says-puerto-rico-government-lost-2-6m-in-phishing-scam","publisher":"PBS NewsHour / Associated Press"}],"entry_type":"incident","slug":"2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account","year":2020,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account"},{"slug":"2019-riviera-beach-pays-600-000-ransom-after-an-employee-clicked-a-malicious","title":"Riviera Beach pays $600,000 ransom after an employee clicked a malicious email link","date":"2019-05-29","date_precision":"day","year":2019,"victim_org":"City of Riviera Beach, Florida","sector":"Government","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Service Disruption","Extortion"],"loss_usd":600000,"loss_kind":"ransom_paid","loss_note":"65 bitcoin, about US$600,000 at the time, authorised by the city council and paid largely through the city's insurance. The city separately approved about US$1 million for replacement hardware.","records_affected":null,"threat_actor":null,"summary":"The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.","how_it_worked":"A single employee in the city's administration opened an email and clicked the link inside it, which delivered the payload that encrypted municipal systems. Nothing about the delivery was exotic; the significance is what a small municipality's environment allowed to follow. Flat networks, shared administrative credentials and backups reachable from the same domain meant one workstation compromise propagated to payroll, email, utility billing and dispatch support systems. With no clean restore path and public safety services degraded, the council concluded that paying the ransom was faster than rebuilding, making Riviera Beach the template case for municipal ransom payment.","lessons":"Offline, immutable backups tested for restoration change the entire calculus, because the decision to pay was driven by recovery capability rather than by the initial click.","confidence":"Confirmed","sources":[{"title":"Florida city to pay $600K ransom to hacker who seized computer systems weeks ago","url":"https://www.cnn.com/2019/06/20/us/riviera-beach-to-pay-hacker/index.html","publisher":"CNN"},{"title":"Florida city pays hackers $600,000 after ransomware attack","url":"https://statescoop.com/florida-city-pays-hackers-600000-after-ransomware-attack/","publisher":"StateScoop"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-riviera-beach-pays-600-000-ransom-after-an-employee-clicked-a-malicious"},{"slug":"2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000","title":"Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients","date":"2019-01-08","date_precision":"day","year":2019,"victim_org":"Oregon Department of Human Services","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":645000,"threat_actor":null,"summary":"On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.","how_it_worked":"A single phishing email reached staff across a large state welfare agency and nine separate employees acted on it, which is the salient fact: the message was ordinary enough that nearly a dozen people in different roles saw nothing wrong. No malware was installed at any point, so there was nothing for endpoint defences to catch. The attacker simply logged into the mailboxes with the harvested credentials and read them like any other user. The exposure was so large because caseworker mailboxes in a human services agency accumulate years of correspondence about benefit recipients, with identifiers and health details in the message bodies.","lessons":"Multi-factor authentication would have neutralised the stolen passwords outright; mailbox retention limits would have shrunk the two million messages sitting behind them.","confidence":"Confirmed","sources":[{"title":"Phishing Attack Exposes Data of 645,000 Oregon DHS Clients","url":"https://www.bleepingcomputer.com/news/security/phishing-attack-exposes-data-of-645-000-oregon-dhs-clients/","publisher":"BleepingComputer"},{"title":"645,000 Clients Affected in Oregon Department of Human Services Data Breach","url":"https://www.securityweek.com/645000-clients-affected-oregon-department-human-services-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000"},{"title":"Cabarrus County, NC diverts $2.5 million school payment to BEC actors","date":"2018-11","date_precision":"month","victim_org":"Cabarrus County, North Carolina","sector":"Government","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2504601,"loss_note":"$2,504,601 paid to fraudsters; $776,518.40 recovered, leaving about $1.7 million unrecovered.","records_affected":null,"threat_actor":null,"summary":"Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.","how_it_worked":"The attackers targeted the vendor master-data process rather than a single invoice. Posing as the school construction contractor, they submitted a bank-account change request accompanied by forms and signatures that matched what the county's finance staff expected to see for a legitimate update. Once the fraudulent account details were accepted into the vendor record, the next scheduled construction draw, more than $2.5 million, flowed to the criminals automatically through the county's normal payment run, with no anomaly to catch. The money was then layered through multiple downstream accounts, and only a fraction was traced and clawed back after the county recognized the diversion weeks later.","lessons":"Vendor bank-detail changes should be treated as a privileged change: verified by outbound call to a number from the original contract, confirmed by a second staffer, and followed by a small test payment before the next large draw.","confidence":"Confirmed","sources":[{"title":"Scammers Grab $2.5 Million From North Carolina County in BEC Scam","url":"https://www.securityweek.com/scammers-grab-25-million-north-carolina-county-bec-scam/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors"},{"title":"City of Ottawa treasurer wires about US$98,000 to fake city manager","date":"2018-07","date_precision":"month","victim_org":"City of Ottawa","sector":"Government","country":"Canada","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":98000,"loss_note":"Approximately US$98,000 wired (reported locally as roughly C$128,000). A second request for US$150,000 was blocked. The U.S. Secret Service monitored a receiving account and an individual connected to the scheme was arrested.","records_affected":null,"threat_actor":null,"summary":"In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.","how_it_worked":"The attacker impersonated the city manager, the one person whose instruction the treasurer would be least likely to challenge, and framed the payment as a confidential acquisition requiring a quick wire. The exchange ran over several emails, letting the fraudster answer questions and build rapport in the city manager's voice, which reinforced authenticity. Because the amount was modest by municipal standards and the requester was the treasurer's superior, the transfer cleared normal handling. The scheme unraveled only by coincidence when the treasurer was physically next to the real city manager during a follow-up request, illustrating that the control that caught it was luck rather than process.","lessons":"Executive-initiated wire requests should require verbal confirmation on a known number before release, and municipalities should bar email as an authorization channel for funds transfers entirely.","confidence":"Confirmed","sources":[{"title":"City of Ottawa treasurer fell victim to US$100K phishing scam: auditor general","url":"https://obj.ca/city-of-ottawa-treasurer-fell-victim-to-us100k-phishing-scam-auditor-general/","publisher":"Ottawa Business Journal"}],"entry_type":"incident","slug":"2018-city-of-ottawa-treasurer-wires-about-us-98-000-to-fake-city-manager","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-city-of-ottawa-treasurer-wires-about-us-98-000-to-fake-city-manager"},{"slug":"2016-gru-spear-phished-election-vendor-vr-systems-then-122-local-election-off","title":"GRU spear-phished election vendor VR Systems, then 122 local election officials","date":"2016-11","date_precision":"month","year":2016,"victim_org":"VR Systems and US local election administrators","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Russian GRU military intelligence","summary":"A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.","how_it_worked":"The first stage was a credential phishing portal: emails that looked like Google security notices pointed VR Systems staff at a counterfeit Google sign-in page where they typed their passwords. The second stage weaponised the resulting familiarity. The operators registered a Gmail address in the name of a real VR Systems employee and mailed 122 local election administrators, who knew VR Systems as their voter-registration software vendor, attaching trojanised Word documents that ran PowerShell to fetch further malware. The trust signal was the vendor relationship itself, and the timing, days before the election, supplied the urgency that made recipients open attachments.","lessons":"Phishing-resistant MFA on vendor accounts and out-of-band confirmation of unexpected vendor attachments would have broken both stages of the chain.","confidence":"Reported","sources":[{"title":"Top-Secret NSA Report Details Russian Hacking Effort Days Before 2016 Election","url":"https://theintercept.com/2017/06/05/top-secret-nsa-report-details-russian-hacking-effort-days-before-2016-election/","publisher":"The Intercept"},{"title":"Report: Russia Launched Cyberattack On Voting Vendor Ahead Of Election","url":"https://www.npr.org/2017/06/05/531649602/report-russia-launched-cyberattack-on-voting-vendor-ahead-of-election","publisher":"NPR"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spear-phished-election-vendor-vr-systems-then-122-local-election-off"},{"title":"John Podesta and DNC staff phished by fake Google security alerts in 2016","date":"2016-03-19","date_precision":"day","victim_org":"Hillary for America campaign and the Democratic National Committee","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No direct monetary loss reported; harm was reputational and political.","records_affected":null,"threat_actor":"Fancy Bear / APT28, identified in the July 2018 US indictment as GRU Unit 26165","summary":"On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.","how_it_worked":"The message imitated Google's 'Someone has your password' notification and carried a Bitly link masking an attacker-controlled domain that rendered a pixel-perfect Google account login page. A campaign IT aide replied that the mail was legitimate, later saying he had meant to write 'illegitimate,' and the link was clicked and the password entered. With mailbox access the operators archived the account's contents. The same infrastructure was used across hundreds of targets; because Bitly statistics were public, researchers were later able to reconstruct the target list and confirm the operator's identity.","lessons":"Hardware security keys on campaign and executive Google accounts make a harvested password worthless, and a defined out-of-band process for verifying security alerts avoids relying on a hurried email reply.","confidence":"Confirmed","sources":[{"title":"Is this the email that hacked John Podesta's account?","url":"https://www.cnn.com/2016/10/28/politics/phishing-email-hack-john-podesta-hillary-clinton-wikileaks/index.html","publisher":"CNN"},{"title":"How hackers broke into John Podesta, DNC Gmail accounts","url":"https://news.sophos.com/en-us/2016/10/25/how-hackers-broke-into-john-podesta-dnc-gmail-accounts/","publisher":"Sophos Naked Security"},{"title":"How John Podesta's Emails Were Hacked And How To Prevent It From Happening To You","url":"https://www.forbes.com/sites/kevinmurnane/2016/10/21/how-john-podestas-emails-were-hacked-and-how-to-prevent-it-from-happening-to-you/","publisher":"Forbes"}],"entry_type":"incident","slug":"2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201"},{"title":"GRU spearphishing of the Clinton campaign, DNC and DCCC","date":"2016","date_precision":"year","victim_org":"Hillary Clinton presidential campaign, Democratic National Committee and Democratic Congressional Campaign Committee","sector":"Government","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in the indictment.","outcomes":["Espionage","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No monetary loss; the outcome was mass exfiltration and staged public release of emails and documents.","records_affected":null,"threat_actor":"Russian GRU Units 26165 and 74455 (twelve officers indicted)","summary":"A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.","how_it_worked":"The unit sent targeted emails to campaign staff and party employees that harvested account usernames and passwords. Compromised mailboxes yielded further contact lists and internal context that made subsequent lures more credible, letting the operation spread laterally from volunteers to senior staff. Stolen credentials were then used to access other computers on the committees' networks, where the officers monitored employee activity and installed malware for persistent collection. The exfiltrated correspondence was subsequently staged and released publicly to maximise political effect during the campaign.","lessons":"Hardware security keys for all campaign and party staff, which several campaigns adopted afterwards, defeat credential-harvesting pages regardless of how convincing the lure is.","confidence":"Confirmed","sources":[{"title":"Grand Jury Indicts 12 Russian Intelligence Officers for Hacking Offenses Related to the 2016 Election","url":"https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-election","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc"},{"title":"IRS 'Get Transcript' abused to pull 334,000 taxpayer transcripts","date":"2015-08-17","date_precision":"day","victim_org":"US taxpayers via the Internal Revenue Service (multi-victim campaign)","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; attackers answered static knowledge-based questions.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"The IRS did not publish a fraudulent-refund total tied specifically to this incident in the August 2015 disclosure.","records_affected":334000,"threat_actor":null,"summary":"In August 2015 the IRS disclosed that criminals had successfully retrieved prior-year tax transcripts for roughly 334,000 taxpayers through its online Get Transcript service, having attempted access against about 610,000 taxpayers. The Treasury Inspector General later put the potentially compromised total higher. Attackers defeated the service's knowledge-based authentication rather than breaching IRS systems.","how_it_worked":"Get Transcript authenticated the requester with a name, date of birth, Social Security number and filing status, followed by four multiple-choice knowledge-based questions supplied by a credit bureau about matters such as previous addresses and loan amounts. Criminals already holding identity data from earlier breaches supplied the first tier and then guessed or looked up the multiple-choice answers, which were drawn from commercially available credit-header data. Success rates exceeded half of attempts. A retrieved transcript contains the prior year's income and withholding detail, which is exactly what is needed to file a convincing fraudulent refund claim.","lessons":"Static knowledge-based authentication should not gate access to sensitive government records once bulk consumer data is in criminal hands; identity proofing needs a possession or biometric factor.","confidence":"Confirmed","sources":[{"title":"IRS: 330K Taxpayers Hit by 'Get Transcript' Scam","url":"https://krebsonsecurity.com/2015/08/irs-330k-taxpayers-hit-by-get-transcript-scam/","publisher":"Krebs on Security"}],"entry_type":"campaign","slug":"2015-irs-get-transcript-abused-to-pull-334-000-taxpayer-transcripts","year":2015,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-irs-get-transcript-abused-to-pull-334-000-taxpayer-transcripts"},{"title":"Sarah Palin Yahoo email account taken over via password-reset questions","date":"2008-09","date_precision":"month","victim_org":"Sarah Palin (then Governor of Alaska and vice-presidential candidate)","sector":"Government","country":"United States","primary_vector":"Physical Pretexting","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the attack relied on publicly available biographical facts.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss reported; the harm was disclosure of private correspondence during a national election campaign.","records_affected":null,"threat_actor":"David C. Kernell (convicted)","summary":"During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.","how_it_worked":"Kernell did not exploit a software flaw. He used the provider's self-service password reset flow, which authenticated the requester by asking knowledge-based security questions such as birth date, postal code and where the account holder met her spouse. Because the account holder was a sitting governor and national candidate, all of those answers were recoverable from publicly published biography and news coverage. Supplying them let him set a new password and read the mailbox, and he then published screenshots, turning a consumer account recovery convenience into a national political disclosure.","lessons":"Knowledge-based authentication is unusable for public figures whose life details are published; account recovery should use possession-based factors such as a registered device or hardware key.","confidence":"Confirmed","sources":[{"title":"Tennessee Man Sentenced for Illegally Accessing Former Governor Sarah Palin's E-mail Account","url":"https://www.justice.gov/archives/opa/pr/tennessee-man-sentenced-illegally-accessing-former-governor-sarah-palin-s-e-mail-account-and","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions","year":2008,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions"}]}