{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:58.948Z","total":9,"returned":9,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account","title":"Crunchyroll support tickets stolen via compromised BPO agent SSO account","date":"2026-03-12","date_precision":"day","year":2026,"victim_org":"Crunchyroll","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.","how_it_worked":"The weak point was not Crunchyroll's own workforce but a third-party contact centre agent with standing access to the streaming service's ticketing system. The attacker said malware on the agent's machine captured their credentials, then used the resulting Okta session to authenticate into Zendesk as a legitimate support operator. Because helpdesk agents routinely open and read large numbers of tickets, bulk retrieval did not stand out immediately, and roughly 24 hours passed before access was cut. Some payment card details were exposed only where customers had typed them into tickets.","lessons":"Outsourced agent identities need the same phishing-resistant MFA and device-health enforcement as employees, plus per-agent ticket access rate limits so no single account can enumerate the whole queue.","confidence":"Reported","sources":[{"title":"Crunchyroll probes breach after hacker claims to steal 6.8M users' data","url":"https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/amp/","publisher":"BleepingComputer"},{"title":"1.2 million Crunchyroll users confirmed impacted by data breach","url":"https://cyberinsider.com/1-2-million-crunchyroll-users-confirmed-impacted-by-data-breach/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"},{"title":"SoundCloud hit as real-time vishing kits drive browsers through SSO logins","date":"2026-01","date_precision":"month","victim_org":"SoundCloud","sector":"Media & Entertainment","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":36000000,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.","how_it_worked":"The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.","lessons":"Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"},{"title":"WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read","date":"2024-05","date_precision":"month","victim_org":"WPP","sector":"Media & Entertainment","country":"United Kingdom","primary_vector":"Deepfake Video Call","secondary_vectors":["Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers set up a WhatsApp account using a publicly available image of chief executive Mark Read, then ran a Microsoft Teams meeting using YouTube footage of him alongside an AI voice clone.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.","how_it_worked":"The pretext was a new business opportunity that a chief executive might plausibly want to explore quietly with one trusted agency leader, which explained both the confidentiality and the unusual approach. The attackers assembled several weak trust signals into a convincing whole: a WhatsApp profile with Read's real photo, a Teams invite from an apparently senior source, video that showed his face and a synthetic voice on the line, and chat messages written in his persona. The technical staging papered over the gaps, with camera and audio problems used to explain why the video looked like recorded footage. The target was asked to move on money and personal information without touching normal corporate process.","lessons":"Verifying meeting invitations through the corporate directory rather than a messaging-app contact, and refusing to progress financial arrangements outside standard process, are what stopped this.","confidence":"Confirmed","sources":[{"title":"CEO of world's biggest ad firm targeted by deepfake scam","url":"https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam","publisher":"The Guardian"},{"title":"Scammers Reportedly Used AI Voice Clone and YouTube Footage to Impersonate WPP CEO","url":"https://incidentdatabase.ai/cite/983/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark"},{"slug":"2019-nikkei-america-employee-wires-29-million-on-fraudulent-management-instru","title":"Nikkei America employee wires $29 million on fraudulent management instructions","date":"2019-09","date_precision":"month","year":2019,"victim_org":"Nikkei Inc. (Nikkei America)","sector":"Media & Entertainment","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":29000000,"loss_kind":"direct_loss","loss_note":"About US$29 million (approximately 3.2 billion yen) transferred to a bank account controlled by the fraudsters; Nikkei said it was pursuing recovery.","records_affected":null,"threat_actor":null,"summary":"Japanese media group Nikkei disclosed in October 2019 that an employee at its US subsidiary, Nikkei America, had transferred about $29 million to a bank account controlled by fraudsters the previous month. The employee acted on instructions from someone impersonating a Nikkei management executive. Nikkei reported the matter to authorities in the United States and Hong Kong and said it was working to recover the funds.","how_it_worked":"Someone posing as a Nikkei management executive instructed an employee in the American subsidiary's finance function to make a large transfer, and the employee did so believing the request was a legitimate internal payment. The structure is the recurring one for cross-border subsidiary fraud: the target sits in an overseas office where head-office instructions arrive by email as a matter of course, where time-zone gaps make immediate verbal confirmation awkward, and where the seniority gradient discourages challenge. No independent check on the beneficiary account was performed before the money left, and the fraud surfaced afterwards during internal review.","lessons":"A hard rule that no single employee can release a transfer of this size without a second approver and a verified callback would have stopped it.","confidence":"Confirmed","sources":[{"title":"Media Giant Nikkei Loses $29 Million to BEC Scammers","url":"https://www.bleepingcomputer.com/news/security/media-giant-nikkei-loses-29-million-to-bec-scammers/","publisher":"BleepingComputer"},{"title":"Japanese media giant Nikkei says $29 million lost in BEC scam","url":"https://cyberscoop.com/nikkei-email-scam-bec-29-million/","publisher":"CyberScoop"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-nikkei-america-employee-wires-29-million-on-fraudulent-management-instru"},{"title":"Pathé Dutch branch wires €19 million in fake CEO acquisition scam","date":"2018-03","date_precision":"month","victim_org":"Pathé (Netherlands branch)","sector":"Media & Entertainment","country":"Netherlands","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":21500000,"loss_note":"More than €19 million (about $21.5 million) paid in multiple transfers, including from the Pathé group cash pool in France. Recovery not publicly confirmed.","records_affected":null,"threat_actor":null,"summary":"In March 2018 fraudsters impersonating the chief executive of French film company Pathé's parent persuaded the Dutch branch's leadership to make a series of payments totaling more than €19 million for a purported acquisition of a Dubai-based company. Branch director Dertje Meijer and CFO Edwin Slutter were both dismissed after the loss surfaced. An external investigation cleared them of involvement, and Slutter later won partial relief in a wrongful-termination suit.","how_it_worked":"The attackers opened with a low-key question about a KPMG contact to establish a plausible thread, then escalated to a confidential acquisition of a Dubai entity, insisting that all communication run through a spoofed personal address 'as a security measure' for sensitive transactions. When the CFO asked for verification, the fraudsters produced a forged authorization email from the Pathé France manager complete with copied signatures and an invoice from the supposed Dubai target. The CFO checked the signatures, which matched, and payments proceeded from several sources including the group cash pool. Small inconsistencies in the correspondence were noticed but not escalated until headquarters queried the withdrawals.","lessons":"Document-based verification is not verification when the attacker supplies the documents; approval for cross-border deal payments must be confirmed by voice with named group officers on known numbers.","confidence":"Confirmed","sources":[{"title":"BEC scammers stole €19m from film company Pathé","url":"https://www.helpnetsecurity.com/2018/11/14/pathe-bec-scam/","publisher":"Help Net Security"}],"entry_type":"incident","slug":"2018-pathe-dutch-branch-wires-19-million-in-fake-ceo-acquisition-scam","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-pathe-dutch-branch-wires-19-million-in-fake-ceo-acquisition-scam"},{"slug":"2018-cinema-group-pathe-loses-eur-19-2-million-to-ceo-fraud-dutch-executives","title":"Cinema group Pathe loses EUR 19.2 million to CEO fraud; Dutch executives dismissed","date":"2018-03","date_precision":"month","year":2018,"victim_org":"Pathe (Pathe Nederland)","sector":"Media & Entertainment","country":"Netherlands","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":21500000,"loss_kind":"direct_loss","loss_note":"EUR 19.2 million (about US$21.5 million at the time). A Dutch court later upheld the dismissal of the executives involved.","records_affected":null,"threat_actor":null,"summary":"Between March and May 2018 the Dutch arm of the French cinema chain Pathe transferred about EUR 19.2 million in a series of payments to accounts in Dubai, acting on emails purporting to come from Pathe's French head office. The company dismissed the managing director and financial director of Pathe Nederland; a Dutch court ruling later published details of the case and upheld the dismissals.","how_it_worked":"Emails presented as coming from Pathe's headquarters in France told the Dutch leadership that the group was making a confidential acquisition in Dubai and needed funds released quickly, with strict instructions not to discuss it internally because of regulatory sensitivity. The correspondence adopted the tone and structure of genuine group communications and continued over weeks, with follow-up messages managing the executives' doubts as the sums grew. The confidentiality clause was the key mechanism: it explained away every anomaly and stopped the one action, a phone call to Paris, that would have ended the fraud immediately.","lessons":"Any instruction whose own terms forbid verification should be treated as fraudulent by default; secrecy is the tell, not the credential.","confidence":"Confirmed","sources":[{"title":"Details of Pathe Nederland's EUR 19.2M Loss to CEO-fraud Revealed","url":"https://celluloidjunkie.com/2018/11/12/details-of-pathe-nederlands-e19-2m-loss-to-ceo-fraud-revealed/","publisher":"Celluloid Junkie"},{"title":"Dutch Film Boss Sacked After EUR 19m BEC Loss","url":"https://www.infosecurity-magazine.com/news/dutch-film-boss-sacked-after-19m/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-cinema-group-pathe-loses-eur-19-2-million-to-ceo-fraud-dutch-executives"},{"slug":"2016-milwaukee-bucks-employee-sends-players-and-staff-w-2s-to-an-impersonator","title":"Milwaukee Bucks employee sends players' and staff W-2s to an impersonator","date":"2016-04-26","date_precision":"day","year":2016,"victim_org":"Milwaukee Bucks (NBA)","sector":"Media & Entertainment","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"The NBA's Milwaukee Bucks disclosed in May 2016 that an employee had emailed 2015 W-2 tax documents for players and staff to an unknown party in response to a message impersonating the team's president. The documents included names, addresses, Social Security numbers and compensation figures. The team offered three years of credit monitoring to those affected.","how_it_worked":"On 26 April 2016 an email arrived that appeared to be from the Bucks' president requesting the organisation's W-2 forms. A staff member sent them. The pretext was the standard W-2 season request, and the impersonated identity was the single most senior person in the organisation, which suppresses the instinct to verify. A professional sports team is an unusually attractive target for this scheme because the compensation figures in the files are large and publicly interesting, and because players' Social Security numbers carry high resale value. Discovery came only after the request was later questioned internally.","lessons":"A named-executive request for the entire workforce's tax records should trigger a mandatory verification call, and payroll data should be exchanged only through controlled systems.","confidence":"Confirmed","sources":[{"title":"Milwaukee Bucks' tax information released by employee who fell for email scam","url":"https://www.washingtonpost.com/news/early-lead/wp/2016/05/19/milwaukee-bucks-tax-information-released-by-employee-who-fell-for-email-scam/","publisher":"The Washington Post"},{"title":"Bucks leak tax info of players, employees as result of email scam","url":"https://www.espn.com/nba/story/_/id/15615363/milwaukee-bucks-leak-tax-information-players-employees-result-email-scam","publisher":"ESPN"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-milwaukee-bucks-employee-sends-players-and-staff-w-2s-to-an-impersonator"},{"title":"Sony Pictures destructive hack preceded by fake Apple ID phishing emails","date":"2014-11-24","date_precision":"day","victim_org":"Sony Pictures Entertainment","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Service Disruption","Extortion","Espionage"],"loss_usd":null,"loss_note":"Sony disclosed investigation and remediation costs in the tens of millions of dollars; a settlement of up to about $8 million with former employees was also reported. No single authoritative total is asserted here.","records_affected":null,"threat_actor":"Guardians of Peace; attributed by the FBI to North Korea (Lazarus Group)","summary":"On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.","how_it_worked":"In September and October 2014 messages purporting to come from Apple warned recipients of unauthorised activity on their Apple ID and pointed to a lookalike verification page. Because many staff reused passwords between personal Apple accounts and Sony systems, harvested credentials could be replayed against corporate services. The intruders spent weeks inside the network collecting mail archives, unreleased films, salary and personnel files, then executed wiper malware that overwrote master boot records and disk volumes, disabling thousands of machines while the stolen data was published in stages.","lessons":"Blocking password reuse between personal and corporate accounts, plus MFA on remote access, removes the value of a harvested consumer credential.","confidence":"Reported","sources":[{"title":"Sony hackers targeted employees with fake Apple ID emails","url":"https://www.computerworld.com/article/1364510/sony-hackers-targeted-employees-with-fake-apple-id-emails.html","publisher":"Computerworld"},{"title":"Sony Hackers Used Apple ID Phishing Scheme, Researchers Claim at RSA","url":"https://www.eweek.com/security/sony-hackers-used-apple-id-phishing-scheme-researchers-claim-at-rsa/","publisher":"eWeek"},{"title":"Sony Hackers Used Phishing Emails to Breach Company Networks","url":"https://www.tripwire.com/state-of-security/sony-hackers-used-phishing-emails-to-breach-company-networks","publisher":"Tripwire State of Security"}],"entry_type":"incident","slug":"2014-sony-pictures-destructive-hack-preceded-by-fake-apple-id-phishing-emails","year":2014,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-sony-pictures-destructive-hack-preceded-by-fake-apple-id-phishing-emails"},{"title":"AP Twitter account hijacked, fake White House bombing tweet jolts markets","date":"2013-04-23","date_precision":"day","victim_org":"The Associated Press","sector":"Media & Entertainment","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media involvement was reported.","outcomes":["Credential Theft","Service Disruption"],"loss_usd":null,"loss_note":"No direct loss to AP was reported. The Dow Jones Industrial Average fell about 143 points within minutes before recovering.","records_affected":null,"threat_actor":"Syrian Electronic Army (claimed responsibility)","summary":"On 23 April 2013 the Associated Press's main Twitter account posted a false report of two explosions at the White House injuring President Obama. The Dow Jones Industrial Average dropped roughly 143 points in minutes before recovering once AP disavowed the tweet. AP said the account takeover was preceded by phishing attempts against its corporate network; the Syrian Electronic Army claimed responsibility, a claim that was not independently corroborated at the time.","how_it_worked":"Staff at AP received phishing emails aimed at the corporate network shortly before the hijack. The lure exploited newsroom urgency and normal internal circulation of story links, leading recipients toward a credential capture page. Harvested credentials gave the attackers control of the wire service's verified Twitter account, whose authority with algorithmic traders and human readers alike was the real payload. A single 12-word tweet asserting an attack on the President was enough to move equity markets before any verification could occur.","lessons":"Two-factor authentication on corporate social accounts, plus separation of newsroom publishing credentials from ordinary staff email, would have prevented a single phished mailbox from becoming a market-moving broadcast channel.","confidence":"Reported","sources":[{"title":"AP Twitter Account Hacked; Tweet About Obama Shakes Market","url":"https://www.npr.org/sections/thetwo-way/2013/04/23/178620410/ap-twitter-account-hacked-tweet-about-obama-shakes-market","publisher":"NPR"},{"title":"Hackers compromise AP Twitter account","url":"https://www.cbsnews.com/news/hackers-compromise-ap-twitter-account/","publisher":"CBS News"}],"entry_type":"incident","slug":"2013-ap-twitter-account-hijacked-fake-white-house-bombing-tweet-jolts-markets","year":2013,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2013-ap-twitter-account-hijacked-fake-white-house-bombing-tweet-jolts-markets"}]}