{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:33.029Z","total":4,"returned":4,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi","title":"Carnival confirms social engineering of an employee account exposed 6 million customers","date":"2026-04-14","date_precision":"day","year":2026,"victim_org":"Carnival Corporation","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5995277,"threat_actor":"ShinyHunters","summary":"Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.","how_it_worked":"Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.","lessons":"Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.","confidence":"Reported","sources":[{"title":"Carnival Cruise confirms data breach affecting nearly 6 million people","url":"https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/","publisher":"BleepingComputer"},{"title":"Carnival Data Breach Exposed 6 Million People","url":"https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/","publisher":"SecurityWeek"},{"title":"Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach","url":"https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach","publisher":"Office of the Texas Attorney General"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"},{"slug":"2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages","title":"Starbucks employee data stolen via cloned Partner Central login pages","date":"2026-01-19","date_precision":"day","year":2026,"victim_org":"Starbucks","sector":"Hospitality","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":900,"threat_actor":null,"summary":"Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.","how_it_worked":"Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.","lessons":"Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.","confidence":"Confirmed","sources":[{"title":"Starbucks Data Breach Impacts Employees","url":"https://www.securityweek.com/starbucks-data-breach-impacts-employees/","publisher":"SecurityWeek"},{"title":"Starbucks suffers data breach via employee portal clone sites","url":"https://cyberinsider.com/starbucks-suffers-data-breach-via-employee-portal-clone-sites/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"},{"slug":"2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing","title":"ShinyHunters claim 14M Panera Bread records after Entra SSO vishing","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Panera Bread","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.","how_it_worked":"The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.","lessons":"Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.","confidence":"Alleged","sources":[{"title":"ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach","url":"https://www.techrepublic.com/article/news-panera-bread-data-breach/","publisher":"TechRepublic"},{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing"},{"slug":"2017-chipotle-payment-card-breach-traced-to-fin7-phishing-emails-backed-by-ph","title":"Chipotle payment card breach traced to FIN7 phishing emails backed by phone calls","date":"2017-04","date_precision":"month","year":2017,"victim_org":"Chipotle Mexican Grill","sector":"Hospitality","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"FIN7 / Carbanak","summary":"Chipotle disclosed in May 2017 that point-of-sale malware had captured payment card track data at restaurants between 24 March and 18 April 2017, including cardholder name, card number, expiry date and verification code. The FBI attributed the intrusion to FIN7, naming Chipotle among the group's publicly disclosed US victims. FIN7 entered victim networks through phishing emails that employees opened, reinforced by follow-up phone calls.","how_it_worked":"FIN7 emailed restaurant corporate and store staff with messages written to read as ordinary business correspondence, such as catering orders or complaints, carrying an attached document. Group members then telephoned the recipient, referred to the email they had just sent and encouraged the employee to open the attachment, which is the detail that made the campaign so effective: the voice call converted a suspicious attachment into an expected one. Opening the document installed a backdoor, from which the group moved to point-of-sale systems and deployed card-scraping malware. Across its victims FIN7 took more than 15 million card records from over 6,500 terminals.","lessons":"Treat an unsolicited phone call that vouches for an emailed attachment as an escalation, not a reassurance, and block macro-enabled documents from external senders.","confidence":"Confirmed","sources":[{"title":"How Cyber Crime Group FIN7 Attacked and Stole Data from Hundreds of U.S. Companies","url":"https://www.fbi.gov/contact-us/field-offices/seattle/news/stories/how-cyber-crime-group-fin7-attacked-and-stole-data-from-hundreds-of-us-companies","publisher":"Federal Bureau of Investigation"},{"title":"Chipotle Mexican Grill Reports Findings from Investigation of Payment Card Security Incident","url":"https://newsroom.chipotle.com/2017-05-26-chipotle-mexican-grill-reports-findings-from-investigation-of-payment-card-security-incident","publisher":"Chipotle Mexican Grill"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-chipotle-payment-card-breach-traced-to-fin7-phishing-emails-backed-by-ph"}]}