{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:58.354Z","total":6,"returned":6,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft","title":"Cushman & Wakefield confirms vishing-triggered Salesforce data theft","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Cushman & Wakefield","sector":"Professional Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters; Qilin also claimed the victim","summary":"Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.","how_it_worked":"The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.","lessons":"Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.","confidence":"Confirmed","sources":[{"title":"Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim","url":"https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/","publisher":"Cybernews"},{"title":"Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped","url":"https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/","publisher":"Breached.Company"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"},{"slug":"2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack","title":"US ransomware negotiators charged with running their own BlackCat attacks","date":"2025-11-03","date_precision":"day","year":2025,"victim_org":"US medical device company, pharmaceutical firm, drone maker and other victims","sector":"Professional Services","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Extortion","Insider Access"],"loss_usd":1274000,"loss_kind":"ransom_paid","loss_note":"One victim, a Florida medical device company, paid about $1.27 million in bitcoin according to the indictment.","records_affected":null,"threat_actor":"ALPHV / BlackCat affiliates","summary":"US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.","how_it_worked":"This was a trusted-insider abuse rather than an external deception. The defendants worked in roles that put them inside the ransomware economy, negotiating on behalf of victims and responding to intrusions, which gave them privileged knowledge of how victims behave, what they pay and how affiliates operate. Prosecutors alleged they used that position to run attacks of their own with the ALPHV/BlackCat toolkit and extort the companies. The trust abused was institutional: organisations hand incident responders and negotiators deep access and complete candour during a crisis, and the employers' own vetting did not surface the conduct until federal investigators did.","lessons":"Firms handling victim data and ransom negotiations need separation of duties, monitored access to case material and periodic re-vetting of staff with that level of insight.","confidence":"Confirmed","sources":[{"title":"DOJ accuses US ransomware negotiators of launching their own ransomware attacks","url":"https://techcrunch.com/2025/11/03/doj-accuses-us-ransomware-negotiators-of-launching-their-own-ransomware-attacks/","publisher":"TechCrunch"},{"title":"Ransomware responders plead guilty to using ALPHV in attacks on US organizations","url":"https://therecord.media/ransomware-responders-guilty-plea-using-alphv-blackcat-us-attacks","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack"},{"title":"Arup Hong Kong office loses about $25 million in deepfake video call scam","date":"2024-02","date_precision":"month","victim_org":"Arup Group (Hong Kong office)","sector":"Professional Services","country":"Hong Kong","primary_vector":"Deepfake Video Call","secondary_vectors":["Business Email Compromise","Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":25000000,"loss_note":"HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.","records_affected":null,"threat_actor":null,"summary":"In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.","how_it_worked":"The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.","lessons":"High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.","confidence":"Confirmed","sources":[{"title":"Deepfaked video conference call makes employee send $25 million to scammers","url":"https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/","publisher":"Help Net Security"},{"title":"Arup Group (fraud incident section)","url":"https://en.wikipedia.org/wiki/Arup_Group","publisher":"Wikipedia"},{"title":"Business Email Compromise: Virtual Meeting Platforms","url":"https://www.ic3.gov/PSA/2022/PSA220216","publisher":"FBI IC3"},{"title":"Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee","url":"https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk","publisher":"CNN"},{"title":"'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage","publisher":"South China Morning Post"}],"entry_type":"incident","slug":"2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"},{"slug":"2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da","title":"SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data","date":"2023-08-19","date_precision":"day","year":2023,"victim_org":"Kroll","sector":"Professional Services","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.","how_it_worked":"The attacker convinced T-Mobile to port a Kroll employee's number to a SIM they controlled, a transfer carried out by a mobile carrier representative acting on a fraudulent request. Once the number was theirs, SMS-based authentication codes for the employee's accounts arrived on the attacker's device, letting them reset access and reach the claimant files Kroll held as bankruptcy administrator. The victims were bankrupt crypto platforms' creditors, a population whose names and contact details are immediately monetisable through targeted phishing about their claims, and several such phishing waves followed the breach.","lessons":"Remove SMS from the authentication path entirely for staff handling sensitive data, and place carrier-level port-out locks on corporate mobile numbers.","confidence":"Confirmed","sources":[{"title":"Kroll Employee SIM-Swapped for Crypto Investor Data","url":"https://krebsonsecurity.com/2023/08/kroll-employee-sim-swapped-for-crypto-investor-data/","publisher":"Krebs on Security"},{"title":"T-Mobile SIM-swapping attack on Kroll employee caused crypto platform data breach","url":"https://therecord.media/sim-swap-attack-caused-crypto-breach","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da"},{"title":"Tecnimont India loses $18.6 million to fake CEO conference calls","date":"2018-12","date_precision":"month","victim_org":"Tecnimont SpA (Indian subsidiary, Maire Tecnimont group)","sector":"Professional Services","country":"India","primary_vector":"Business Email Compromise","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"Impersonation on the conference calls was performed by live human actors; no synthetic voice was reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":18600000,"loss_note":"About 1.3 billion rupees, reported as roughly $18.5-18.6 million, sent in three installments to banks in Hong Kong.","records_affected":null,"threat_actor":"Group reported by the company to be operating from China","summary":"The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.","how_it_worked":"This scheme layered voice over email to defeat skepticism. Messages arrived from a domain closely resembling the group CEO's, describing a secret acquisition in China that had to be funded from India because regulatory constraints supposedly blocked transfers from Italy. To answer the obvious objection, the fraudsters convened conference calls in which multiple actors played the CEO, group executives and an external Swiss attorney, giving the transaction the texture of a real deal team. Secrecy was justified as regulatory sensitivity, which kept the India head from calling headquarters. Three tranches were wired to Hong Kong before the parent company discovered the deception.","lessons":"Verification must go through a channel the attacker does not control: a callback to headquarters' known switchboard would have collapsed the entire fake deal team.","confidence":"Reported","sources":[{"title":"Chinese group swindles $18.5 million from Indian arm of Italian company","url":"https://in.marketscreener.com/quote/stock/MAIRE-S-P-A-13369769/news/Maire-Tecnimont-Chinese-group-swindles-18-5-million-from-Indian-arm-of-Italian-company-Economic-27846733/","publisher":"The Economic Times via MarketScreener"},{"title":"BEC Scam Leads to Theft of $18.6 Million","url":"https://www.bankinfosecurity.com/bec-scam-leads-to-theft-186-million-fraud-a-11930","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls"},{"title":"Epsilon email marketing breach exposes address lists of banks and retailers","date":"2011-04","date_precision":"month","victim_org":"Epsilon Data Management and other email service providers","sector":"Professional Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":2000000,"loss_note":"The indictment alleged the defendants generated over $2 million from spam campaigns promoting counterfeit software using the stolen lists; downstream costs to the affected brands were not quantified.","records_affected":1000000000,"threat_actor":"Viet Quoc Nguyen, Giang Hoang Vu and David-Manuel Santos Da Silva (indicted March 2015)","summary":"In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.","how_it_worked":"The lead defendant sent targeted phishing emails to employees of email service providers. The messages carried links to sites built to exploit browser vulnerabilities and silently install malware, giving backdoor access to employee workstations and, from there, harvested access credentials for the marketing platforms. With those credentials he bulk-downloaded subscriber lists to a server he controlled in the Netherlands. Because the stolen records paired real names with the specific brands each person banked or shopped with, they were unusually valuable for follow-on spear phishing against consumers.","lessons":"Marketing platforms holding client subscriber lists need bulk-export alerting and least-privilege segregation, so one phished employee workstation cannot pull the entire customer database.","confidence":"Confirmed","sources":[{"title":"Feds Indict Three in 2011 Epsilon Hack","url":"https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail","year":2011,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail"}]}