{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:29.817Z","total":12,"returned":12,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials","title":"MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices","date":"2026-05-06","date_precision":"day","year":2026,"victim_org":"Multiple organisations in the United States and MENA (unnamed)","sector":"Manufacturing","country":"United States and Middle East / North Africa","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"MuddyWater (Seedworm), assessed as linked to Iran's Ministry of Intelligence and Security, operating behind Chaos ransomware branding","summary":"Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.","how_it_worked":"The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.","lessons":"Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.","confidence":"Reported","sources":[{"title":"Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware","url":"https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/","publisher":"Rapid7 Labs"},{"title":"MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack","url":"https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"},{"title":"STAC4749 Teams vishing campaign led to Chaos ransomware in North America","date":"2026-02","date_precision":"month","victim_org":"Dozens of North American organisations (unnamed)","sector":"Manufacturing","country":"Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No ransom or loss totals were disclosed.","records_affected":null,"threat_actor":"STAC4749, deploying Chaos ransomware","summary":"Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.","how_it_worked":"The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.","lessons":"Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.","confidence":"Confirmed","sources":[{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","url":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america"},{"slug":"2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform","title":"Stellantis confirms customer data stolen from Salesforce platform","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Stellantis","sector":"Manufacturing","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered Lapsus$ Hunters (claimed)","summary":"Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.","how_it_worked":"The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.","lessons":"Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.","confidence":"Reported","sources":[{"title":"Automaker giant Stellantis confirms data breach after Salesforce hack","url":"https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/","publisher":"BleepingComputer"},{"title":"Stellantis confirms data breach involving customers' contact information","url":"https://www.engadget.com/big-tech/stellantis-confirms-data-breach-involving-customers-contact-information-194136744.html","publisher":"Engadget"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform"},{"title":"Orion S.A. discloses $60 million loss from fraudulently induced wire transfers","date":"2024-08-10","date_precision":"day","victim_org":"Orion S.A.","sector":"Manufacturing","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The company's SEC filing did not describe the impersonation technique or state whether AI-generated media was involved.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":60000000,"loss_note":"Approximately $60 million one-time pre-tax charge for unrecovered fraudulent transfers, per the company's Form 8-K. Orion said it would pursue recovery including through insurance.","records_affected":null,"threat_actor":null,"summary":"Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.","how_it_worked":"The disclosure describes the standard structure of a corporate payment-diversion fraud: a single employee inside the payments process was deceived into initiating a series of outbound wires rather than one large transfer, which keeps individual amounts within familiar approval bands and spreads them across banking cutoffs. The recipients were accounts controlled by unidentified third parties, consistent with mule networks that disperse funds quickly across jurisdictions. Orion identified the scheme after the transfers had been executed, concluded the loss was unrecoverable enough to book a $60 million charge, and reported that its systems and financial reporting controls were otherwise unaffected, indicating deception of a person rather than a technical compromise.","lessons":"Payment initiation by a single employee is a structural weakness; enforced dual authorization plus out-of-band verification and velocity alerting on new beneficiaries would have interrupted the sequence.","confidence":"Confirmed","sources":[{"title":"Orion S.A. Form 8-K, Item 8.01 (filed August 12, 2024)","url":"https://www.sec.gov/Archives/edgar/data/1609804/000095014224002170/eh240519238_8k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"},{"title":"Scammers dupe chemical company into wiring $60 million","url":"https://www.helpnetsecurity.com/2024/08/13/orion-fraudulent-wire-transfers-60-million/","publisher":"Help Net Security"}],"entry_type":"incident","slug":"2024-orion-s-a-discloses-60-million-loss-from-fraudulently-induced-wire-trans","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-orion-s-a-discloses-60-million-loss-from-fraudulently-induced-wire-trans"},{"title":"Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question","date":"2024-07","date_precision":"month","victim_org":"Ferrari","sector":"Manufacturing","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The caller used a synthetic voice that reproduced chief executive Benedetto Vigna's southern Italian accent; the target noticed slightly mechanical intonation.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.","how_it_worked":"The approach started on WhatsApp from an unfamiliar number, with the mismatch explained away by the claim that the deal was so sensitive it required a separate line, a pretext that turns a red flag into evidence of importance. The escalation to a voice call added the strongest trust signal available, the chief executive's distinctive accent and manner discussing an unannounced acquisition. Confidentiality supplied the reason not to consult anyone, and a currency hedge gave a technical, plausible-sounding financial action. The executive interrupted the frame by asking a shared-knowledge question with no public answer, which the synthetic caller could not handle.","lessons":"A pre-agreed challenge based on shared private knowledge, or a codeword for executive payment requests, reliably breaks a voice clone that cannot improvise.","confidence":"Reported","sources":[{"title":"Ferrari narrowly dodges deepfake scam simulating deal-hungry CEO","url":"https://www.spokesman.com/stories/2024/jul/26/ferrari-narrowly-dodges-deepfake-scam-simulating-d/","publisher":"Bloomberg via The Spokesman-Review"},{"title":"Ferrari CEO Deepfake Shows Growing Threat of AI Scams Impersonating Executives","url":"https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo","publisher":"Bloomberg"}],"entry_type":"incident","slug":"2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu"},{"title":"Clorox attack traced to help desk agents resetting passwords without verification","date":"2023-08-11","date_precision":"day","victim_org":"The Clorox Company","sector":"Manufacturing","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the complaint describes live phone calls.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":380000000,"loss_note":"$380 million is the total damages Clorox sought in its 2025 lawsuit against Cognizant, including about $49 million in direct remediation costs; it is a litigation claim, not an adjudicated loss.","records_affected":null,"threat_actor":"Scattered Spider","summary":"Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.","how_it_worked":"According to the complaint, the attacker called the Cognizant-run service desk multiple times claiming to be a Clorox employee and asked for a password reset. The agent reset the credential and the multifactor enrolment without confirming the caller's identity, and transcripts quoted in the filing show no verification step took place. The attacker used the same technique against a Clorox IT security employee, which yielded privileged network access. From there the intrusion progressed to network-wide disruption; Clorox took systems offline, reverted to manual order processing, and saw sales and shipments fall for months afterwards.","lessons":"Outsourced service desks need contractually mandated, auditable identity proofing before any credential or MFA reset, with higher-assurance checks for accounts holding privileged access.","confidence":"Confirmed","sources":[{"title":"Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit","url":"https://www.bleepingcomputer.com/news/security/hackers-fooled-cognizant-help-desk-says-clorox-in-380m-cyberattack-lawsuit/","publisher":"BleepingComputer"},{"title":"Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack","url":"https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor","publisher":"The Record"},{"title":"Clorox files $380 million suit blaming Cognizant for 2023 cyberattack","url":"https://www.cybersecuritydive.com/news/clorox-380-million-suit-cognizant-cyberattack/753837/","publisher":"Cybersecurity Dive"},{"title":"$380M lawsuit: intruder got Clorox's passwords from Cognizant simply by asking","url":"https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/","publisher":"The Register"},{"title":"Clorox estimates the costs of the August cyberattack will exceed $49 Million","url":"https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver"},{"title":"Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory","date":"2020-08","date_precision":"month","victim_org":"Tesla, Inc.","sector":"Manufacturing","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss occurred. The targeted employee reported the approach to Tesla and the FBI, and the plot was never executed.","records_affected":null,"threat_actor":"Egor Igorevich Kriuchkov (later pleaded guilty)","summary":"Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.","how_it_worked":"Kriuchkov built rapport with the employee in person over social meetings before naming the ask. The proposal was for the employee to run attacker-supplied ransomware inside the plant network, either by opening a malicious email attachment or plugging in an infected USB stick, while the conspirators ran a simultaneous distributed denial-of-service attack to occupy Tesla's security team. The group intended to exfiltrate Tesla files and extort the company for their non-release; Kriuchkov said the malware itself had cost $250,000 to develop. The scheme died at the first step because the employee, rather than accepting, told Tesla and then wore a wire for the FBI.","lessons":"A no-blame, clearly advertised channel for reporting bribery approaches is the control that actually catches insider recruitment, since no technical control sees the offer being made.","confidence":"Confirmed","sources":[{"title":"How a $1 million plot to hack Tesla failed","url":"https://www.technologyreview.com/2020/08/28/1007752/how-a-1-million-plot-to-hack-tesla-failed/","publisher":"MIT Technology Review"}],"entry_type":"incident","slug":"2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi"},{"title":"Toyota Boshoku European unit loses $37 million to payment-instruction BEC","date":"2019-08-14","date_precision":"day","victim_org":"Toyota Boshoku Corporation (European subsidiary)","sector":"Manufacturing","country":"Japan","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":37000000,"loss_note":"Approximately ¥4 billion, reported as about $37 million; the company said it was pursuing recovery of the funds.","records_affected":null,"threat_actor":null,"summary":"Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.","how_it_worked":"Attackers sent messages that impersonated a trading partner or an internal authority and instructed the subsidiary's finance function to redirect a large trade payment to a different bank account. Because the amount and the counterparty were consistent with the subsidiary's normal automotive supply-chain payments, the request did not stand out, and the transfer was executed on the strength of the emailed instruction alone. The loss was discovered after the fact, and Toyota Boshoku disclosed it to the market alongside a downward revision of expected results while pursuing legal recovery.","lessons":"Any instruction that changes payee bank details, even mid-transaction with a known partner, should require independent verification through an established contact and a second approver outside the requesting chain.","confidence":"Confirmed","sources":[{"title":"Over $37 Million Lost by Toyota Boshoku Subsidiary in BEC Scam","url":"https://www.bleepingcomputer.com/news/security/over-37-million-lost-by-toyota-boshoku-subsidiary-in-bec-scam/","publisher":"BleepingComputer"},{"title":"Toyota Parts Supplier Loses $37 Million in Email Scam","url":"https://www.tripwire.com/state-of-security/toyota-parts-supplier-loses-37-million-email-scam","publisher":"Tripwire State of Security"},{"title":"Toyota Boshoku Corporation lost over $37 Million following BEC attack","url":"https://securityaffairs.com/90955/cyber-crime/toyota-boshoku-corporation-bec.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec","year":2019,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec"},{"title":"Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer","date":"2019-03-19","date_precision":"day","victim_org":"Norsk Hydro ASA","sector":"Manufacturing","country":"Norway","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption"],"loss_usd":71000000,"loss_note":"Microsoft's account of the incident states the financial impact would eventually approach $71 million; Hydro's own quarterly disclosures gave figures in a similar range and the company was partly insured.","records_affected":null,"threat_actor":"LockerGoga operators","summary":"Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.","how_it_worked":"The attackers first compromised a customer's mailbox, then used that genuine business relationship to send a document attachment to a Hydro employee. Because the sender was a real, expected correspondent, the attachment was opened and installed a trojan. Over the following months the intruders escalated into Active Directory, obtained domain-level control and then pushed LockerGoga across the estate, which encrypted files and, in some variants, changed local account passwords and logged users out. Hydro's 35,000 employees across 40 countries lost access to IT systems; some smelters ran on paper procedures for weeks.","lessons":"Attachments from known senders still need detonation and macro controls, and tiered Active Directory administration prevents a single infected desktop from becoming domain-wide ransomware deployment.","confidence":"Reported","sources":[{"title":"Hackers hit Norsk Hydro with ransomware. The company responded with transparency","url":"https://news.microsoft.com/source/features/digital-transformation/hackers-hit-norsk-hydro-ransomware-company-responded-transparency/","publisher":"Microsoft Source"},{"title":"Norsk Hydro responds to ransomware attack with transparency","url":"https://www.microsoft.com/en-us/security/blog/2019/12/17/norsk-hydro-ransomware-attack-transparency/","publisher":"Microsoft Security Blog"},{"title":"Hydro Hit by LockerGoga Ransomware via Active Directory","url":"https://www.bankinfosecurity.com/hydro-hit-by-lockergoga-ransomware-via-active-directory-a-12207","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted","year":2019,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted"},{"title":"Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud","date":"2018-04","date_precision":"month","victim_org":"Unatrac Holding Limited (Caterpillar export sales affiliate)","sector":"Manufacturing","country":"United Kingdom","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":11000000,"loss_note":"Approximately $11 million in fraudulent transfer requests sent from the compromised CFO account in April 2018; DOJ cited about $11 million in known losses across the wider scheme.","records_affected":null,"threat_actor":"Obinwanne Okeke ('Invictus Obi') and co-conspirators, Nigeria","summary":"Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.","how_it_worked":"The crew sent a credential-phishing email to Unatrac's chief financial officer that harvested his Microsoft Office 365 login. With mailbox access, they read pending payment correspondence, then sent roughly fifteen fraudulent transfer requests and payment approvals over eight days in April 2018 that appeared to come directly from the CFO. Fake invoices and altered supplier banking details supported the requests, and finance staff processed them as ordinary executive-approved payments because they arrived from the genuine internal account. Funds were routed to overseas accounts. The company recognized the fraud only after the CFO's mailbox behavior and the missing payments were reconciled in June 2018.","lessons":"Multifactor authentication on executive mailboxes plus monitoring for anomalous mailbox rules and sign-ins would have blocked the takeover that made every downstream approval look authentic.","confidence":"Confirmed","sources":[{"title":"Nigerian National Sentenced to Prison for $11 Million Global Fraud Scheme","url":"https://www.justice.gov/usao-edva/pr/nigerian-national-sentenced-prison-11-million-global-fraud-scheme","publisher":"U.S. Department of Justice, E.D. Va."}],"entry_type":"incident","slug":"2018-obinwanne-okeke-sentenced-to-10-years-over-11-million-unatrac-bec-fraud","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-obinwanne-okeke-sentenced-to-10-years-over-11-million-unatrac-bec-fraud"},{"title":"Leoni AG Romanian subsidiary wires €40 million to fraudsters","date":"2016-08","date_precision":"month","victim_org":"Leoni AG (Bistrița, Romania subsidiary)","sector":"Manufacturing","country":"Romania","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":44000000,"loss_note":"About €40 million (roughly $44 million) transferred to an account in the Czech Republic. Recovery not confirmed.","records_affected":null,"threat_actor":null,"summary":"German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.","how_it_worked":"The attackers researched Leoni's internal payment culture before striking, and reporting indicated they knew that German group executives had previously requested transfers by email. They created lookalike sender identities for those executives and directed instructions to the Romanian subsidiary's finance director, who was accustomed to acting on such requests. The messages mimicked the format, tone and approval language of genuine intra-group transfers and were supported by falsified documents. Because the request pattern matched prior legitimate behavior, the finance director executed the wire to a Czech account without a callback to Germany, and the funds were dispersed before the group detected the loss.","lessons":"Intra-group cash movements need a codified verification protocol, ideally a signed treasury workflow rather than email, so that familiarity with past email requests cannot be weaponized.","confidence":"Confirmed","sources":[{"title":"Hackers steal EUR 40 mln from German group Leoni's subsidiary in Romania","url":"https://www.romania-insider.com/hackers-steal-eur-40-mln-german-group-leoni-subsidiary-romania","publisher":"Romania Insider"},{"title":"German wire supplier Leoni loses EUR 40m in email impersonation scam","url":"https://www.bitdefender.com/en-us/blog/businessinsights/leoni-fraud-email-impersonation-scam","publisher":"Bitdefender Business Insights"}],"entry_type":"incident","slug":"2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters"},{"title":"Austrian aerospace supplier FACC loses about €50 million to CEO fraud","date":"2016-01","date_precision":"month","victim_org":"FACC AG","sector":"Manufacturing","country":"Austria","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the impersonation was email-based, not a voice clone.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":54000000,"loss_note":"FACC reported damage of approximately €50 million (roughly US$54 million at the time); USD figures in press reports range from about $47 million to $56 million depending on exchange rate and date.","records_affected":null,"threat_actor":null,"summary":"FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.","how_it_worked":"Fraudsters sent email instructions that appeared to come from FACC's chief executive, framed around a confidential acquisition and directing finance staff to wire funds to foreign accounts. The framing discouraged the recipients from consulting colleagues, and the payments were released without independent confirmation. Part of the money was frozen in transit; the remainder was dispersed abroad. Austrian police later arrested an alleged accomplice tied to receiving accounts in Hong Kong. No malware or network intrusion was involved, which is why FACC described it as damage from a criminal act rather than a technical breach.","lessons":"A mandatory callback to a directory-listed number for any payment framed as confidential or urgent, plus dual sign-off on international transfers, defeats CEO fraud outright.","confidence":"Confirmed","sources":[{"title":"Austrian Firm Fires CEO After $56-million Cyber Scam","url":"https://www.securityweek.com/austrian-firm-fires-ceo-after-56-million-cyber-scam/","publisher":"SecurityWeek"},{"title":"Aerospace firm loses $47 million in cyber fraud, fires CEO","url":"https://www.bitdefender.com/en-us/blog/businessinsights/cyber-fraud-ceo-fired","publisher":"Bitdefender Business Insights"},{"title":"Cops nab accomplice in Austrian €50m caper","url":"https://www.thelocal.at/20160828/cops-nab-accomplice-in-austrian-50m-caper-facc-hong-kong/","publisher":"The Local Austria"}],"entry_type":"incident","slug":"2016-austrian-aerospace-supplier-facc-loses-about-50-million-to-ceo-fraud","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-austrian-aerospace-supplier-facc-loses-about-50-million-to-ceo-fraud"}]}