{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:23:14.228Z","total":14,"returned":14,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ","title":"Levi Strauss files 8-K after social engineering compromises three employee computers","date":"2026-08-07","date_precision":"day","year":2026,"victim_org":"Levi Strauss & Co.","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.","how_it_worked":"Levi Strauss disclosed only that the vector was social engineering against employees, without naming the technique. The linkage Reuters drew to a crew running a five-week, 200-company spree matches the voice-phishing-plus-lookalike-portal pattern dominant through 2026, in which callers impersonating IT support harvest credentials and session tokens from individual staff. Access reached three endpoints and corporate data was taken before the company contained it. Levi Strauss activated incident response and engaged third-party specialists; consumer systems were reported unaffected.","lessons":"Phishing-resistant MFA plus rapid session revocation limits a three-endpoint compromise to exactly that; the 8-K filing over three laptops shows how cheaply this vector reaches material-disclosure territory.","confidence":"Confirmed","sources":[{"title":"Levi Strauss discloses data breach after social engineering attack on employees","url":"https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/","publisher":"CyberInsider"},{"title":"Levi Strauss describes contained cyber incident, LEVI 8-K filing","url":"https://www.stocktitan.net/sec-filings/LEVI/8-k-levi-strauss-co-reports-material-event-0f6321560e78.html","publisher":"StockTitan (SEC filing)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ"},{"title":"BlackFile extortion gang runs vishing campaign against retail and hospitality","date":"2026-02","date_precision":"month","victim_org":"Multiple retail and hospitality organisations (unnamed)","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.","records_affected":null,"threat_actor":"BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)","summary":"BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.","how_it_worked":"Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.","lessons":"Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.","confidence":"Confirmed","sources":[{"title":"New BlackFile extortion gang targets retail and hospitality orgs","url":"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"},{"slug":"2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the","title":"Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Kering (Gucci, Balenciaga, Alexander McQueen)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.","how_it_worked":"ShinyHunters told reporters the access came from the same telephone-based playbook it ran against dozens of consumer brands in 2025: a caller posing as internal IT or a SaaS vendor contacted staff with CRM access, cited a plausible support ticket, and guided them through granting a connected application permission in the customer-relationship platform. The identity impersonated was the victim's own IT function; the trust signal abused was a vendor-branded consent page that looked routine. No malware was deployed. Once approved by a human, the app was used to enumerate and export customer profiles, which were then used for private extortion demands.","lessons":"Retail and luxury CRM tenants should treat third-party app consent as a privileged administrative action requiring a second approver and out-of-band caller verification.","confidence":"Reported","sources":[{"title":"Company that owns Gucci, Balenciaga, other brands confirms hack","url":"https://techcrunch.com/2025/09/15/company-that-owns-gucci-balenciaga-other-brands-confirms-hack","publisher":"TechCrunch"},{"title":"Gucci, Balenciaga, McQueen confirm breach, ShinyHunters claim 7.4M customers' data stolen","url":"https://cybernews.com/news/gucci-balenciaga-kering-data-breach-7-million-customers-compromised-shiny-hunters/","publisher":"Cybernews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the"},{"slug":"2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach","title":"Chanel notifies US clients after third-party client-care database breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Chanel","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.","how_it_worked":"Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.","lessons":"Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.","confidence":"Reported","sources":[{"title":"Chanel Alerts Client of Third-Party Breach","url":"https://www.darkreading.com/cyberattacks-data-breaches/chanel-alerts-third-party-breach","publisher":"Dark Reading"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach"},{"slug":"2025-pandora-warns-customers-after-third-party-platform-breach","title":"Pandora warns customers after third-party platform breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Pandora A/S","sector":"Retail","country":"Denmark","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.","how_it_worked":"Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.","lessons":"Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.","confidence":"Reported","sources":[{"title":"Pandora and Chanel Customer Data Leaked in Third-Party Breaches","url":"https://www.pymnts.com/cybersecurity/2025/pandora-and-chanel-customer-data-leaked-in-breach/","publisher":"PYMNTS"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-pandora-warns-customers-after-third-party-platform-breach"},{"slug":"2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft","title":"LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave","date":"2025-07","date_precision":"month","year":2025,"victim_org":"LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040","summary":"Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.","how_it_worked":"The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.","lessons":"Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.","confidence":"Reported","sources":[{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"},{"title":"Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches","url":"https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"},{"title":"Harrods restricts internet access after intrusion attempts in UK retail wave","date":"2025-05-01","date_precision":"day","victim_org":"Harrods","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"Harrods disclosed no technical detail, so no assessment of AI involvement is possible.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.","how_it_worked":"Harrods has never described the mechanics, so the entry attempt is characterised here only by the campaign it belonged to. The wave that hit UK retail in April and May 2025 was driven by English-speaking crews who phoned retailer service desks impersonating staff to obtain password and MFA resets, then escalated inside the identity provider. Harrods' response, cutting external internet access at sites while investigating, is consistent with defending against credential-based lateral movement rather than a software exploit, but the company has confirmed nothing further.","lessons":"Fast containment helped here, but the durable control against this campaign is out-of-band identity proofing before any help desk credential or MFA reset.","confidence":"Alleged","sources":[{"title":"Luxury department store Harrods suffered a cyberattack","url":"https://securityaffairs.com/177330/cyber-crime/luxury-department-store-harrods-suffered-a-cyberattack.html","publisher":"Security Affairs"},{"title":"Harrods alerts customers to new data breach linked to third-party provider","url":"https://securityaffairs.com/182752/data-breach/harrods-alerts-customers-to-new-data-breach-linked-to-third-party-provider.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail"},{"slug":"2025-adidas-customer-data-stolen-through-third-party-customer-service-provide","title":"Adidas customer data stolen through third-party customer service provider","date":"2025-05","date_precision":"month","year":2025,"victim_org":"Adidas","sector":"Retail","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.","how_it_worked":"Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.","lessons":"Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.","confidence":"Reported","sources":[{"title":"April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider","url":"https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider","publisher":"Rescana"},{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"},{"title":"Marks & Spencer attack tied to social engineering of outsourced service desk","date":"2025-04-22","date_precision":"day","victim_org":"Marks & Spencer Group plc","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vendor / Supply Chain Impersonation","Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":null,"loss_note":"M&S publicly guided to a hit of around £300 million to operating profit before mitigation; no USD figure is asserted here.","records_affected":null,"threat_actor":"Scattered Spider, deploying DragonForce ransomware","summary":"Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.","how_it_worked":"Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.","lessons":"Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.","confidence":"Confirmed","sources":[{"title":"M&S hackers gained access through third-party Tata Consulting Services, sources say","url":"https://cybernews.com/news/marks-spencer-hackers-used-employee-login-tsc-tata-consulting-scattered-spider/","publisher":"Cybernews"},{"title":"M&S confirms month-long breach result of third-party vendor phishing attack","url":"https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/","publisher":"Cybernews"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Marks and Spencer confirms data breach after April cyber attack","url":"https://securityaffairs.com/177784/data-breach/marks-and-spencer-confirms-data-breach-after-april-cyber-attack.html","publisher":"Security Affairs"},{"title":"Marks & Spencer breach linked to Scattered Spider ransomware attack","url":"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de"},{"title":"Co-op loses £206m of revenue and 6.5 million members' data to DragonForce","date":"2025-04","date_precision":"month","victim_org":"Co-operative Group","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Service Disruption","Extortion"],"loss_usd":275000000,"loss_note":"Co-op reported a £206 million revenue loss, roughly $275 million, driven by weeks of food supply disruption.","records_affected":6500000,"threat_actor":"DragonForce, with Scattered Spider-aligned English-speaking affiliates; four people aged 17 to 20 were arrested by the UK NCA in July 2025","summary":"The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.","how_it_worked":"Co-op's account of the intrusion, given publicly by its leadership, is that the attackers impersonated an employee convincingly enough to have that employee's password reset, then used the re-issued credentials to enter the network. The Teams messages and follow-up phone calls to security staff show the same crew comfortable operating in the victim's own collaboration tools, negotiating and pressuring in real time. Co-op's decision to pull systems down aggressively contained the intrusion before encryption, which is why the damage landed as lost revenue and stolen data rather than ransomware.","lessons":"Caller verification at the service desk, and separate approval paths for resets on high-privilege accounts, would have removed the single conversation that granted access.","confidence":"Confirmed","sources":[{"title":"Cyberattack on Co-op leaves shelves empty, data stolen, and $275M in lost revenue","url":"https://securityaffairs.com/182713/security/cyberattack-on-co-op-leaves-shelves-empty-data-stolen-and-275m-in-lost-revenue.html","publisher":"Security Affairs"},{"title":"DragonForce group claims the theft of data after Co-op cyberattack","url":"https://securityaffairs.com/177376/cyber-crime/dragonforce-group-claims-the-theft-of-data-after-co-op-cyberattack.html","publisher":"Security Affairs"},{"title":"Data of all 6.5 million Co-op members stolen - CEO says she is 'incredibly sorry'","url":"https://www.techradar.com/pro/security/data-of-all-6-5-million-coop-members-stolen-ceo-is-incredibly-sorry","publisher":"TechRadar Pro"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce","year":2025,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce"},{"slug":"2022-bed-bath-beyond-discloses-data-breach-to-sec-after-an-employee-was-phish","title":"Bed Bath & Beyond discloses data breach to SEC after an employee was phished","date":"2022-10","date_precision":"month","year":2022,"victim_org":"Bed Bath & Beyond","sector":"Retail","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.","how_it_worked":"A single employee at the retailer was targeted with a phishing message and fell for it, handing the attacker access to that employee's account. What followed illustrates why one employee's compromise is rarely contained to one employee: the attacker reached not only files on the individual's own hard drive but also the shared network drives that the account had rights to open. Corporate shared drives accumulate years of departmental documents that no one has reviewed for sensitivity. The retailer disclosed the event as a material item to the SEC while investigation was still under way, and did not detail the phishing method used.","lessons":"Least-privilege access to shared drives and periodic review of what accumulates on them decide how much one phished account is actually worth.","confidence":"Confirmed","sources":[{"title":"Bed, Bath & Beyond confirms data breach following employee phishing attack","url":"https://techcrunch.com/2022/10/31/bed-bath-beyond-data-breach/","publisher":"TechCrunch"},{"title":"Bed Bath & Beyond Investigating Data Breach After Employee Falls for Phishing Attack","url":"https://www.securityweek.com/bed-bath-beyond-investigating-data-breach-after-employee-falls-phishing-attack/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-bed-bath-beyond-discloses-data-breach-to-sec-after-an-employee-was-phish"},{"slug":"2018-fin7-breach-of-saks-fifth-avenue-and-lord-taylor-exposes-5-million-payme","title":"FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards","date":"2018-04","date_precision":"month","year":2018,"victim_org":"Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor)","sector":"Retail","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000000,"threat_actor":"FIN7 / JokerStash (Fin7 syndicate)","summary":"In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.","how_it_worked":"FIN7's tradecraft against retail and hospitality victims was consistent: emails written to look like routine business correspondence, carrying a malicious attachment, sent to corporate staff, then reinforced by a phone call from a group member who referenced the message and urged the recipient to open it. Opening the document installed a backdoor and gave the group a corporate foothold from which they reached point-of-sale infrastructure and deployed card-scraping malware. At Hudson's Bay this produced roughly five million card records over about a year, which then surfaced for sale in tranches on an underground marketplace.","lessons":"Network segmentation between corporate email endpoints and payment infrastructure limits how far one opened attachment can travel.","confidence":"Reported","sources":[{"title":"Fin7 Syndicate Hacks Saks Fifth Avenue and Lord & Taylor","url":"https://geminiadvisory.io/fin7-syndicate-hacks-saks-fifth-avenue-and-lord-taylor/","publisher":"Gemini Advisory"},{"title":"Hackers steal payment card data of 5 million Saks, Lord & Taylor customers","url":"https://www.helpnetsecurity.com/2018/04/03/saks-breach/","publisher":"Help Net Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-fin7-breach-of-saks-fifth-avenue-and-lord-taylor-exposes-5-million-payme"},{"slug":"2016-sprouts-farmers-market-payroll-employee-emails-21-000-staff-w-2s-to-a-sc","title":"Sprouts Farmers Market payroll employee emails 21,000 staff W-2s to a scammer","date":"2016-03","date_precision":"month","year":2016,"victim_org":"Sprouts Farmers Market","sector":"Retail","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":21000,"threat_actor":null,"summary":"In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.","how_it_worked":"The attacker sent a short, plain email to a payroll staff member that appeared to come from a Sprouts executive and asked for all employee W-2 forms. The pretext matched the calendar: late March is the height of US tax season, when internal requests for wage data are entirely routine, so the ask raised no category alarm. The message used seniority as the trust signal and gave no reason for the request, which in a large organisation reads as normal executive brevity rather than suspicious. The employee replied with the file, handing over a complete identity-theft package for the workforce.","lessons":"Bulk employee tax or payroll data should only leave through a ticketed request in an HR system, never as an email attachment, regardless of who appears to be asking.","confidence":"Confirmed","sources":[{"title":"Employers Beware of Phishing Scams","url":"https://www.natlawreview.com/article/employers-beware-phishing-scams","publisher":"The National Law Review"},{"title":"Sprouts Farmers Market Class Actions Target W-2 Phishing Scam","url":"https://topclassactions.com/lawsuit-settlements/lawsuit-news/sprouts-farmers-market-class-actions-target-w-2-phishing-scam/","publisher":"Top Class Actions"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-sprouts-farmers-market-payroll-employee-emails-21-000-staff-w-2s-to-a-sc"},{"title":"Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical","date":"2013-12","date_precision":"month","victim_org":"Target Corporation","sector":"Retail","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Target reported cumulative gross breach expenses in the hundreds of millions of dollars across later filings; the sources cited here do not itemise a single figure, so no dollar value is asserted.","records_affected":110000000,"threat_actor":null,"summary":"Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.","how_it_worked":"Criminals emailed malware to staff at Fazio Mechanical, a refrigeration and HVAC contractor. Investigators believed the payload was Citadel, a password-stealing derivative of the ZeuS banking trojan; Fazio ran a free anti-malware product without real-time protection. The stolen credentials let attackers log into Target's external vendor-facing systems (Ariba and Partners Online), from which they pivoted into the internal network, deployed memory-scraping malware to point-of-sale registers, and staged and exfiltrated track data from cards swiped in US stores.","lessons":"Vendor portal accounts should be scoped to the billing and project functions they need, with no network path into card-processing segments, and third-party remote access should require phishing-resistant MFA.","confidence":"Reported","sources":[{"title":"Email Attack on Vendor Set Up Breach at Target","url":"https://krebsonsecurity.com/2014/02/email-attack-on-vendor-set-up-breach-at-target/","publisher":"Krebs on Security"},{"title":"A 'Kill Chain' Analysis of the 2013 Target Data Breach","url":"https://www.commerce.senate.gov/services/files/24d3c229-4f2f-405d-b8db-a3a67f183883","publisher":"US Senate Committee on Commerce, Science, and Transportation"},{"title":"Target Breach: Phishing Attack Implicated","url":"https://www.darkreading.com/cyberattacks-data-breaches/target-breach-phishing-attack-implicated","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic","year":2013,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic"}]}