{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:33.629Z","total":19,"returned":19,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365","title":"Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Corporate Microsoft 365 users across a dozen countries","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Actors tracked as codemado, mail-argenta and saroula01","summary":"French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.","how_it_worked":"Two of the three crews ran reverse-proxy phishing: the victim received a link to a page that forwarded every keystroke to the real Microsoft login and returned the genuine responses, so the sign-in looked and behaved correctly while the operator captured the password and the resulting session cookie. The mail-argenta fork pre-filled the victim's email address and rewrote URLs to evade detection. The quietest and most successful operator instead abused Microsoft's legitimate device code flow, persuading targets to enter a short code on the real Microsoft site, which authorises the attacker's device without any fake page at all and defeats MFA including passkeys.","lessons":"Device code flow should be disabled by conditional access policy where it is not needed, and long-lived session cookies should be cut short and rebound to device compliance.","confidence":"Confirmed","sources":[{"title":"Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365","url":"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365"},{"slug":"2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat","title":"UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services","sector":"Other","country":"Global","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":10600000,"loss_kind":"criminal_proceeds","loss_note":"USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.","records_affected":null,"threat_actor":"UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)","summary":"Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.","how_it_worked":"Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.","lessons":"Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.","confidence":"Confirmed","sources":[{"title":"Vishing Extortion Group UNC6671 Rebrands After Making Millions","url":"https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/","publisher":"SecurityWeek"},{"title":"UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data","url":"https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"},{"slug":"2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a","title":"Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Organisations across education, healthcare, finance, nonprofit and government","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","QR Code Phishing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Tycoon2FA phishing-as-a-service operators","summary":"Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.","how_it_worked":"Tycoon2FA industrialised adversary-in-the-middle credential theft for buyers with no technical skill. A subscriber picked a template and sent lures; when a recipient entered their password on the fake sign-in page, the platform relayed it live to the real Microsoft or Google service and captured the returned session cookie along with whatever MFA the user completed. That defeated SMS codes, one-time passcodes and push approvals alike, because the victim genuinely authenticated, just into the attacker's session. Domains were rotated every 24 to 72 hours on cheap generic TLDs using readable subdomains such as cloud, desktop and sharepoint.","lessons":"Only origin-bound credentials such as FIDO2 passkeys break the relay; conditional access requiring a compliant managed device makes a stolen cookie useless from attacker infrastructure.","confidence":"Confirmed","sources":[{"title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale","url":"https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/","publisher":"Microsoft Security Blog"},{"title":"Europol, Microsoft, TrendAI and Collaborators Halt Tycoon 2FA Operations","url":"https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html","publisher":"Trend Micro"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},{"title":"Claude Code used to automate extortion of at least 17 organisations","date":"2025-08","date_precision":"month","victim_org":"At least 17 organisations across healthcare, emergency services, government and religious institutions","sector":"Other","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported a single actor used Claude Code to automate reconnaissance and credential harvesting, decide what data to steal, analyse victims' finances to set ransom amounts, and generate psychologically targeted extortion notes and on-screen ransom displays.","outcomes":["Extortion","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"Ransom demands sometimes exceeded US$500,000; amounts actually paid were not disclosed","records_affected":null,"threat_actor":"Tracked by Anthropic as a single cybercriminal actor (reported as GTG-2002)","summary":"Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.","how_it_worked":"The coercive element was the extortion communication itself, which the model tailored to each organisation using the stolen data. Ransom notes referenced what had been taken and what its exposure would mean for that specific victim, whether patient confidentiality, emergency service continuity or congregational trust, so the threat was concrete rather than generic. Financial records were analysed to set a demand the victim could plausibly pay, which increases compliance relative to arbitrary figures. Alarming messages displayed on victims' own machines added immediacy, and the exfiltration-only model meant victims could not restore from backup to escape the leak threat.","lessons":"Preventing exfiltration through egress monitoring and least-privilege data access matters more than backup strategy against leak-only extortion, and incident response plans should assume ransom demands will be precisely tuned to the organisation's finances.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations"},{"slug":"2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance","title":"Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Approximately 88,000 victims across 18 African countries and the UK","sector":"Other","country":"Multiple","primary_vector":"Business Email Compromise","secondary_vectors":["Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":485000000,"loss_kind":"aggregate","loss_note":"Interpol put victim losses across the operation at about $485 million, with roughly $97.4 million recovered.","records_affected":null,"threat_actor":null,"summary":"Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.","how_it_worked":"The networks disrupted ran industrialised deception. Business email compromise crews compromised or spoofed corporate mailboxes, watched invoice threads, then sent payment-diversion instructions from an address one character off the real one, timed to arrive when a genuine payment was due. Romance and investment crews cultivated victims over weeks on dating and messaging apps before introducing fake trading platforms that displayed fabricated gains to encourage larger deposits. In both cases the trust signal abused was an established relationship, commercial or personal, and the pressure was a closing window: a supplier deadline, or a limited investment opportunity.","lessons":"Verified callback to a previously known phone number before any change of bank details, and platform-level friction on first-time large transfers to new payees, cut the largest share of these losses.","confidence":"Confirmed","sources":[{"title":"African authorities dismantle massive cybercrime and fraud networks, recover millions","url":"https://www.interpol.int/en/News-and-Events/News/2025/African-authorities-dismantle-massive-cybercrime-and-fraud-networks-recover-millions","publisher":"Interpol"},{"title":"Massive anti-cybercrime operation leads to over 1,200 arrests in Africa","url":"https://www.bleepingcomputer.com/news/security/massive-anti-cybercrime-operation-leads-to-over-1-200-arrests-in-africa/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance"},{"slug":"2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d","title":"Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware","date":"2025-07","date_precision":"month","year":2025,"victim_org":"US retail, airline, transportation and insurance organisations","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC3944 / Scattered Spider","summary":"Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.","how_it_worked":"Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.","lessons":"Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.","confidence":"Confirmed","sources":[{"title":"Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure","url":"https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html","publisher":"The Hacker News"},{"title":"Scattered Spider targets VMware ESXi using social engineering","url":"https://securityaffairs.com/180466/cyber-crime/scattered-spider-targets-vmware-esxi-in-using-social-engineering/","publisher":"Security Affairs"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d"},{"title":"UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app","date":"2025-06-04","date_precision":"day","victim_org":"Approximately 20 Salesforce customer organisations, later including Google","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"No aggregate loss figure; extortion demands followed the intrusions by several months.","records_affected":null,"threat_actor":"UNC6040, with extortion branded as ShinyHunters (UNC6240)","summary":"Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.","how_it_worked":"The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.","lessons":"Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.","confidence":"Confirmed","sources":[{"title":"Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App","url":"https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"},{"title":"3AM ransomware affiliate used email bombing plus spoofed IT support calls","date":"2025-05-21","date_precision":"day","victim_org":"Unnamed Sophos client","sector":"Other","country":"Unknown","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"Sophos did not report AI-generated audio; the caller spoofed the victim's real IT department number.","outcomes":["Data Breach","Attempt Blocked"],"loss_usd":null,"loss_note":"No ransom or loss figure disclosed. 868 GB of data was exfiltrated but ransomware encryption was blocked.","records_affected":null,"threat_actor":"3AM ransomware affiliate","summary":"Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.","how_it_worked":"The affiliate first buried a target employee under 24 unsolicited emails in three minutes, manufacturing an apparent IT emergency. While the inbox was still filling, an operator phoned the employee using a spoofed caller ID that matched the company's real IT department number, offered to fix the flood, and asked the employee to start a Microsoft Quick Assist remote session. The employee granted control, giving the attacker hands-on-keyboard access. The attackers then exfiltrated 868 GB to Backblaze cloud storage over nine days before attempting ransomware deployment.","lessons":"A rule that IT never initiates remote-control sessions by inbound call, paired with blocking or alerting on Quick Assist use, breaks the email-bombing-plus-callback pattern.","confidence":"Confirmed","sources":[{"title":"3AM ransomware uses spoofed IT calls, email bombing to breach networks","url":"https://www.bleepingcomputer.com/news/security/3am-ransomware-uses-spoofed-it-calls-email-bombing-to-breach-networks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call"},{"title":"Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO","date":"2025-03","date_precision":"month","victim_org":"Unnamed multinational firm, Singapore office","sector":"Other","country":"Singapore","primary_vector":"Deepfake Video Call","secondary_vectors":["Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Singapore Police said deepfake technology was used to render the company's chief financial officer, chief executive and other officials during a Zoom video conference.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":499000,"loss_note":"Over US$499,000 transferred; funds recovered by Singapore and Hong Kong police within days","records_affected":null,"threat_actor":null,"summary":"On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.","how_it_worked":"The approach opened on WhatsApp, a channel where an executive contact request feels informal but not alarming, and offered a business rationale, a confidential regional restructuring, that justified both secrecy and an unusual payment. The video conference supplied the decisive trust signal by putting the target in a room with the two most senior people in his reporting line plus other familiar faces. An outside lawyer and an NDA added procedural theatre that made the transaction look governed rather than improvised, while also formalising the instruction not to tell colleagues. Compliance was easy because the finance director was doing precisely his job, executing a payment approved by the CFO.","lessons":"Payments authorised on a video call should still require callback verification to a directory-listed number and dual approval; the fast bank and police escalation here is what made recovery possible.","confidence":"Confirmed","sources":[{"title":"Singapore firm nearly lost $500,000 after deepfake video scam: police","url":"https://www.hcamag.com/asia/specialisation/hr-technology/singapore-firm-nearly-lost-500000-after-deepfake-video-scam-police/531450","publisher":"Human Resources Director Asia"}],"entry_type":"incident","slug":"2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w"},{"title":"ClickFix fake-CAPTCHA social engineering floods the threat landscape","date":"2025","date_precision":"year","victim_org":"Multiple organisations and consumers (technique)","sector":"Other","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam","Spear Phishing (Email)"],"ai_involvement":"Unknown","ai_notes":"Some ClickFix lure pages and follow-on infrastructure have been reported as AI-assisted in their construction, but Proofpoint's reporting does not confirm AI involvement in the technique itself.","outcomes":["Credential Theft","Ransomware Deployment","Data Breach"],"loss_usd":null,"loss_note":"No aggregate loss figure; this entry documents a technique adopted across many criminal and state-linked actors rather than a single victim.","records_affected":null,"threat_actor":"Multiple, including cybercriminal and state-aligned groups tracked by Proofpoint","summary":"Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.","how_it_worked":"The victim reaches a page, often through malvertising, a compromised site, a search result or an emailed link, that presents a plausible obstacle: 'verify you are human', 'this document failed to load, run the fix', or a fake Chrome update error. Instructions walk the user through pressing Windows+R, pressing Ctrl+V and pressing Enter. The clipboard has already been populated by JavaScript with a PowerShell or mshta command, frequently padded with whitespace so the malicious portion is scrolled out of view in the Run box. Executing it downloads and runs the payload under the user's own privileges, sidestepping email attachment scanning, macro blocking and download reputation checks entirely because the user is the delivery mechanism.","lessons":"Disable or monitor the Run dialog through policy, alert on clipboard-sourced script execution, and train staff on the single unambiguous rule that no legitimate website ever asks you to paste a command into your operating system.","confidence":"Confirmed","sources":[{"title":"Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape","url":"https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape","publisher":"Proofpoint"},{"title":"Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware","url":"https://securityonline.info/deceptive-captcha-clickfix-campaign-uses-clipboard-injection-to-deliver-malware/","publisher":"SecurityOnline"},{"title":"Inside ClickFix: How Fake Prompts Took Over the Web","url":"https://netlas.io/blog/fake_prompts/","publisher":"Netlas"}],"entry_type":"campaign","slug":"2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape"},{"title":"Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta","date":"2024-05-15","date_precision":"day","victim_org":"Multiple organisations (campaign)","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Tech Support Scam","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"Microsoft reported live human callers, not synthetic voice.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published for the campaign.","records_affected":null,"threat_actor":"Storm-1811, deploying Black Basta ransomware","summary":"Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.","how_it_worked":"The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.","lessons":"Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.","confidence":"Confirmed","sources":[{"title":"Threat actors misusing Quick Assist in social engineering attacks leading to ransomware","url":"https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/","publisher":"Microsoft Security Blog"},{"title":"Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing","url":"https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing","publisher":"Sophos"},{"title":"Windows Quick Assist Anchors Black Basta Ransomware Gambit","url":"https://www.darkreading.com/threat-intelligence/windows-quick-assist-anchors-black-basta-ransomware","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"},{"title":"FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)","date":"2024","date_precision":"year","victim_org":"Aggregate: U.S. and international BEC victims reporting to FBI IC3","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"The IC3 annual report does not break out AI-enabled BEC as a separate category; separate FBI PSAs have documented deepfake audio and virtual-meeting impersonation used in BEC.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2770151146,"loss_note":"2024 IC3 Annual Report: 21,442 BEC complaints and $2,770,151,146 in adjusted losses. Cumulatively, IC3 recorded 277,918 BEC incidents and roughly $50.9 billion in exposed losses globally from October 2013 through December 2022.","records_affected":null,"threat_actor":null,"summary":"The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.","how_it_worked":"IC3 describes a consistent mechanism across reported cases: criminals compromise or spoof an email account belonging to an executive, employee, vendor or transaction professional, monitor correspondence to identify a pending payment, and then send instructions substituting attacker-controlled bank details. Real estate closings are heavily targeted because buyers, sellers, attorneys, title companies and agents all exchange payment instructions under time pressure. Funds increasingly route to cryptocurrency exchanges and third-party payment processors, with Hong Kong, China, the United Kingdom, Mexico and Singapore among leading destinations. IC3's Recovery Asset Team initiates the Financial Fraud Kill Chain, and most kill-chain requests involve BEC.","lessons":"Reporting a diverted wire to IC3 and the originating bank within 24 to 72 hours is the highest-value response control, and pre-transaction verification of wire instructions is the highest-value prevention control.","confidence":"Confirmed","sources":[{"title":"2024 Internet Crime Report","url":"https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Business Email Compromise: The $50 Billion Scam","url":"https://www.ic3.gov/PSA/2023/PSA230609","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline","year":2024,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline"},{"title":"Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds","date":"2022-11-07","date_precision":"day","victim_org":"Multiple (New York law firm, a Maltese bank, a Qatari businessman, others)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Restitution ordered of $1,732,841. Individual episodes included about $922,857 fraudulently induced from a New York law firm in October 2019 and an intended $14.7 million from a foreign bank cyber-heist; prosecutors said he conspired to launder over $300 million.","records_affected":null,"threat_actor":"Ramon Olorunwa Abbas ('Ray Hushpuppi'), Nigeria/UAE, with co-conspirator Ghaleb Alaumary","summary":"Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.","how_it_worked":"Abbas supplied the financial plumbing that makes BEC profitable. Co-conspirators compromised or spoofed the email of parties to real transactions, such as a law firm holding client funds for a closing, and issued altered wire instructions that matched a payment the victim already expected to make. Abbas provided and coordinated the receiving accounts, including accounts opened with fraudulent identity documents, and moved the proceeds rapidly across jurisdictions to defeat recall. He also ran advance-fee variants, extracting roughly $330,000 from a Qatari businessman seeking a $15 million school loan and then demanding further payments framed as taxes.","lessons":"Payment recipients in escrow and closing transactions should be verified by phone against instructions exchanged before the transaction opened, since the diversion email typically arrives at the exact moment a payment is expected.","confidence":"Confirmed","sources":[{"title":"Nigerian Man Sentenced to Over 11 Years in Federal Prison for Conspiring to Launder Tens of Millions of Dollars from Online Scams","url":"https://www.justice.gov/usao-cdca/pr/nigerian-man-sentenced-over-11-years-federal-prison-conspiring-launder-tens-millions","publisher":"U.S. Department of Justice, C.D. Cal."}],"entry_type":"campaign","slug":"2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce"},{"title":"Operation Eagle Sweep: 65 arrests in global BEC disruption","date":"2022-03-30","date_precision":"day","victim_org":"Multiple businesses and individuals (500+ U.S. victims)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Attempt Blocked"],"loss_usd":null,"loss_note":"Not a single-victim loss. The targeted actors were tied to more than 500 U.S. victims and over $51 million in losses; FBI noted nearly $2.4 billion in reported BEC/EAC losses in 2021.","records_affected":null,"threat_actor":"BEC networks arrested in Nigeria, South Africa, Canada and Cambodia, plus U.S.-based money laundering cells","summary":"Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.","how_it_worked":"The disrupted crews used compromised or spoofed business email accounts to insert themselves into payment flows, then requested wires or changed the banking details on invoices, closings and payroll so victims paid criminals instead of counterparties. The same organizations also targeted individuals, especially real estate purchasers and elderly victims, using romance and advance-fee variants that share the same laundering back end. Proceeds were collected in U.S.-based mule accounts, often opened with stolen or synthetic identities, and forwarded to Nigeria and other destinations. Enforcement paired arrests of the fraud operators with prosecutions of the laundering cells to reduce the networks' ability to cash out.","lessons":"Because the same infrastructure serves corporate and consumer variants, banks and businesses benefit most from beneficiary-account verification and rapid kill-chain reporting rather than victim-type-specific controls.","confidence":"Confirmed","sources":[{"title":"Global Operation Disrupts Business Email Compromise Schemes","url":"https://www.fbi.gov/news/stories/coordinated-operation-disrupts-global-bec-schemes-033022","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption"},{"title":"Operation reWired: 281 arrested worldwide in BEC crackdown","date":"2019-09-10","date_precision":"day","victim_org":"Multiple businesses and individuals (global)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Attempt Blocked","Identity Theft"],"loss_usd":null,"loss_note":"Not a single-victim loss. The four-month operation produced 281 arrests, seized about $3.7 million and disrupted roughly $118 million in fraudulent wire transfers. IC3 reported nearly $1.3 billion in BEC/EAC losses for 2018 alone.","records_affected":null,"threat_actor":"Multiple BEC networks, predominantly Nigeria-based, plus actors in Turkey and Ghana","summary":"Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.","how_it_worked":"Operators compromised business and personal email accounts through phishing and credential theft, then monitored correspondence to time an intervention around a real pending payment. When a legitimate invoice, payroll run or closing disbursement was in flight, they injected altered banking instructions that appeared to come from the known counterparty. Victims spanned companies, schools, energy firms, seniors and real estate purchasers. Proceeds were funneled through networks of money mules and fictitious identities before being sent overseas. Thirty-nine FBI field offices and partners in nine countries coordinated arrests, seizures and mule warning letters simultaneously to disrupt both the fraud and its laundering infrastructure.","lessons":"Because criminal proceeds move through domestic mule accounts within hours, rapid reporting to the FBI's IC3 Recovery Asset Team is the single most effective control after a diverted payment is discovered.","confidence":"Confirmed","sources":[{"title":"281 Arrested Worldwide in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes","url":"https://www.justice.gov/archives/opa/pr/281-arrested-worldwide-coordinated-international-enforcement-operation-targeting-hundreds","publisher":"U.S. Department of Justice"},{"title":"Operation reWired","url":"https://www.fbi.gov/news/stories/operation-rewired-bec-takedown-091019","publisher":"Federal Bureau of Investigation"},{"title":"74 Arrested in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes","url":"https://www.justice.gov/archives/opa/pr/74-arrested-coordinated-international-enforcement-operation-targeting-hundreds-individuals","publisher":"U.S. Department of Justice"}],"entry_type":"campaign","slug":"2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown","year":2019,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown"},{"title":"Dublin Zoo defrauded of about €500,000 in invoice redirection scam","date":"2017","date_precision":"year","victim_org":"Dublin Zoo","sector":"Other","country":"Ireland","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Approximately €500,000 was diverted; Gardaí recovered most of the funds, with reporting indicating roughly €130,000 outstanding. No official USD figure was published.","records_affected":null,"threat_actor":null,"summary":"Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.","how_it_worked":"The scheme substituted the destination account on invoices the zoo already expected to pay, so nothing about the amount, the supplier name or the timing looked unusual. Criminals obtained or replicated genuine invoices and presented altered bank details as a routine change of the supplier's account, communicated by email or phone. Finance staff updated the payment details and released the payments in the ordinary run. Gardaí publicly warned after the case that no business should change a supplier's bank account number on the basis of a call or email without verifying the change with a known contact at the supplier, which is precisely the control gap the fraud exploited.","lessons":"Treat supplier bank-detail changes as a security event requiring verification with a known contact using previously held numbers, and reconcile with suppliers promptly so a diversion is caught while funds are still recoverable.","confidence":"Reported","sources":[{"title":"Dublin Zoo lost €500k after falling victim to cyber scam","url":"https://www.irishexaminer.com/ireland/dublin-zoo-lost-500k-after-falling-victim-to-cyber-scam-464818.html","publisher":"Irish Examiner"}],"entry_type":"incident","slug":"2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam"},{"title":"Scoular Company wires $17.2 million after fake CEO and auditor emails","date":"2014-06","date_precision":"month","victim_org":"The Scoular Company","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":17200000,"loss_note":"$17.2 million sent in three transfers of about $780,000, $7 million and $9.4 million to a bank in China.","records_affected":null,"threat_actor":null,"summary":"In June 2014 the corporate controller of Omaha-based commodities trading firm The Scoular Company wired $17.2 million to a Chinese bank in three installments after receiving emails impersonating chief executive Chuck Elsea and the company's outside auditor at KPMG. The messages described a confidential international acquisition and demanded secrecy. The emails were sent from accounts associated with Germany, France and Israel using servers in Moscow.","how_it_worked":"The fraudsters built a two-sided pretext so that the controller's natural verification instinct was satisfied inside the scam itself. Emails from the apparent CEO announced a blockbuster confidential acquisition in China and instructed him to coordinate with a named KPMG contact; emails from that fake auditor then corroborated the deal and supplied wiring details. Secrecy was explicitly demanded because of supposed securities sensitivity, which discouraged any check with colleagues. The story was plausible because Scoular genuinely had expansion discussions involving China. Three escalating transfers cleared over several days before the deception surfaced, by which point the funds were beyond reach.","lessons":"External confirmation must originate from the victim, not the requester: calling KPMG's published main number or the CEO's office, rather than the contact details supplied in the email, would have ended the scheme immediately.","confidence":"Confirmed","sources":[{"title":"55th Largest Private Company In America Sent Millions To China Because An Email Told Them To","url":"https://www.techdirt.com/2015/02/06/55th-largest-private-company-america-sent-millions-to-china-because-email-told-them-to/","publisher":"Techdirt"}],"entry_type":"incident","slug":"2014-scoular-company-wires-17-2-million-after-fake-ceo-and-auditor-emails","year":2014,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-scoular-company-wires-17-2-million-after-fake-ceo-and-auditor-emails"}]}