{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:15:31.015Z","total":3,"returned":3,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-russian-state-linked-actors-phish-app-specific-passwords-from-academics","title":"Russian state-linked actors phish app-specific passwords from academics and critics","date":"2025-06","date_precision":"month","year":2025,"victim_org":"Academics, journalists and Russia critics (individuals not named)","sector":"Nonprofit","country":"Multiple","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC6293 (assessed linked to APT29 / Cozy Bear)","summary":"Google Threat Intelligence and Citizen Lab jointly documented a campaign in June 2025 in which a Russian government-linked cluster tracked as UNC6293 persuaded targets to create Google application-specific passwords and hand them over. Victims included prominent academics and critics of Russia. The technique bypassed multi-factor authentication entirely and gave the attackers durable mailbox access.","how_it_worked":"The operators impersonated US State Department officials and invited targets to private online consultations, sustaining polite, well-written correspondence over days or weeks and copying plausible-looking @state.gov addresses to make the exchange feel institutional. They then sent PDF instructions asking the target to generate a Google app-specific password, described as a way to join a secure State Department platform, and to send the sixteen-character string back. Because the victim generated it themselves inside their real Google account, nothing looked stolen and MFA was never challenged. The attackers used the password for ongoing, silent access to the mailbox.","lessons":"Disable app-specific passwords for at-risk users, enrol them in Google's Advanced Protection Program, and treat any request to generate an account credential for a third party as a red flag regardless of who is asking.","confidence":"Confirmed","sources":[{"title":"Same Sea, New Phish: Russian Government-Linked Social Engineering Targets App-Specific Passwords","url":"https://citizenlab.ca/research/russian-government-linked-social-engineering-targets-app-specific-passwords/","publisher":"The Citizen Lab"},{"title":"Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign","url":"https://thehackernews.com/2025/06/russian-apt29-exploits-gmail-app.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-russian-state-linked-actors-phish-app-specific-passwords-from-academics"},{"title":"One Treasure Island nonprofit loses $650,000 to hijacked email thread","date":"2021","date_precision":"year","victim_org":"One Treasure Island","sector":"Nonprofit","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":650000,"loss_note":"$650,000 diverted. Funds initially landed at a bank in Odessa, Texas; the nonprofit reported difficulty obtaining law enforcement and bank assistance and no recovery was confirmed in the cited reporting.","records_affected":null,"threat_actor":null,"summary":"One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.","how_it_worked":"The attackers took over the outsourced bookkeeper's mailbox, which sat at the center of the nonprofit's payment approvals, and then replied inside a live thread about a pending grant disbursement rather than starting fresh correspondence. Because the message carried the real address, the real subject line and the real transaction context, the substituted wiring instructions read as an ordinary administrative update. Staff sent the $650,000 grant payment to the criminals' account at a small out-of-state bank, which was then drained onward. The organization discovered the diversion only when the intended recipient reported non-receipt, and small-nonprofit resourcing left it largely on its own to chase the money.","lessons":"Thread hijacking beats sender-address checks, so any change of wire instructions inside an existing thread must trigger a verbal callback to a previously known number before funds move.","confidence":"Reported","sources":[{"title":"Scammed San Francisco Nonprofit Falls Victim to Costliest Type of Cybercrime","url":"https://www.cbsnews.com/sanfrancisco/news/scammed-san-francisco-nonprofit-falls-victim-to-costliest-type-of-cybercrime/","publisher":"CBS News Bay Area / Associated Press"},{"title":"A nonprofit that helps the poor lost $650,000 to scammers","url":"https://www.sfchronicle.com/crime/article/S-F-nonprofit-lost-650-000-to-hackers-and-a-16191669.php","publisher":"San Francisco Chronicle"}],"entry_type":"incident","slug":"2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread","year":2021,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread"},{"title":"Save the Children Federation loses nearly $1 million in charity BEC fraud","date":"2017-05","date_precision":"month","victim_org":"Save the Children Federation, Inc.","sector":"Nonprofit","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":1000000,"loss_note":"Approximately $1 million diverted; insurance covered most of it, leaving the charity with a net loss of about $112,000.","records_affected":null,"threat_actor":null,"summary":"In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.","how_it_worked":"The attacker first phished credentials and gained control of a legitimate internal mailbox, which removed the usual lookalike-domain tell from the fraud. Operating from inside the organization's own email, they generated invoices and supporting documentation for a plausible program expense, solar equipment for Pakistani health facilities, that matched the charity's real field activities. Approvals then flowed through normal internal channels because every message came from a trusted colleague's real address. Payment was directed to a bank account in Japan, a jurisdiction inconsistent with the stated project, and the funds were gone before the discrepancy was noticed during later reconciliation.","lessons":"Account takeover defeats sender-based trust, so payment approvals for program expenses need out-of-band confirmation plus a geography sanity check between the vendor, the project and the receiving bank.","confidence":"Confirmed","sources":[{"title":"Save the Children Charity Org Scammed for Almost $1 Million","url":"https://www.bleepingcomputer.com/news/security/save-the-children-charity-org-scammed-for-almost-1-million/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2017-save-the-children-federation-loses-nearly-1-million-in-charity-bec-fraud","year":2017,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-save-the-children-federation-loses-nearly-1-million-in-charity-bec-fraud"}]}