{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:16:45.083Z","total":52,"returned":50,"limit":50,"offset":0,"next":"https://global-social-engineering-impact-da.vercel.app/api/incidents?sector=Technology&offset=50&limit=50","note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ReliaQuest blocks ShinyHunters vishing attack with device-trust controls","date":"2026-08-24","date_precision":"day","victim_org":"ReliaQuest","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"ReliaQuest did not state whether synthetic voice was used on the calls.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; no customer data was accessed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.","how_it_worked":"The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.","lessons":"Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.","confidence":"Confirmed","sources":[{"title":"ReliaQuest confirms failed data-theft attack after ShinyHunters breach","url":"https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"},{"slug":"2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai","title":"RingCentral data on 1.6M accounts leaked after social engineering campaign","date":"2026-07","date_precision":"month","year":2026,"victim_org":"RingCentral","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1600000,"threat_actor":"ShinyHunters","summary":"Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.","how_it_worked":"RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.","lessons":"Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.","confidence":"Confirmed","sources":[{"title":"RingCentral data breach exposed info of 1.6 million accounts","url":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","publisher":"BleepingComputer"},{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","url":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai"},{"title":"Identity protection firm Aura breached in vishing attack; ~900,000 records taken","date":"2026-03","date_precision":"month","victim_org":"Aura","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call that compromised the employee account.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":900000,"threat_actor":"ShinyHunters","summary":"Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.","how_it_worked":"The attackers targeted a single employee account with a voice phishing call, the same pattern the group used against Okta and Microsoft Entra single sign-on accounts throughout early 2026: pose as internal IT, offer help with an authentication task, and capture credentials and a one-time code through a lookalike login page. The compromised account was live for only about an hour, but that was long enough to export a marketing database wholesale. The stolen combination of name, address, phone and email is itself high-quality raw material for follow-on phishing and vishing.","lessons":"Short-lived access still enables bulk export; rate-limiting and alerting on large database exports would have caught the theft inside the one-hour window.","confidence":"Reported","sources":[{"title":"Aura data breach","url":"https://en.wikipedia.org/wiki/Aura_data_breach","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records"},{"slug":"2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors","title":"Contagious Interview: fake developer job interviews deliver backdoors","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Software developers at enterprise solution, media and communications firms","sector":"Technology","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Cryptocurrency Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.","how_it_worked":"The pretext is a career opportunity, and the trust signal is the ordinary shape of a developer hiring process: a recruiter approach, a screening call, then a take-home coding exercise. The malicious step is disguised as the exercise itself, because cloning a repository and running it locally is exactly what a candidate is expected to do. Payloads fire automatically from task configuration files when the repository is opened in Visual Studio Code, so no obviously suspicious action is needed. The malware then harvests API tokens, cloud credentials, cryptocurrency wallets, password manager databases, private keys, source code and clipboard contents.","lessons":"Candidate exercises and any unvetted repository should be run only in a disposable sandbox with no access to corporate credentials, wallets or password vaults.","confidence":"Confirmed","sources":[{"title":"Contagious Interview: Malware delivered through fake developer job interviews","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"},{"slug":"2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod","title":"CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes","date":"2026-02-13","date_precision":"day","year":2026,"victim_org":"CarGurus","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.","how_it_worked":"Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.","lessons":"One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.","confidence":"Reported","sources":[{"title":"CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach","url":"https://news.dealershipguy.com/p/cargurus-probes-cyberattack-shinyhunters-theft-1-7-million-records-data-breach-2026-02-23","publisher":"Dealership Guy News"},{"title":"CarGurus Reported Data Breach","url":"https://complyauto.com/cargurus-reported-data-breach/","publisher":"ComplyAuto"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod"},{"title":"Optimizely confirms data breach after vishing attack on employees","date":"2026-02-11","date_precision":"day","victim_org":"Optimizely","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"Optimizely did not state whether synthetic voice was used on the calls.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed; the company said there was no disruption to business operations.","records_affected":null,"threat_actor":"Likely ShinyHunters-affiliated","summary":"Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.","how_it_worked":"Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.","lessons":"Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.","confidence":"Confirmed","sources":[{"title":"Ad tech firm Optimizely confirms data breach after vishing attack","url":"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees"},{"slug":"2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill","title":"Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records","date":"2026-01-29","date_precision":"day","year":2026,"victim_org":"Match Group (Match, Hinge, OkCupid)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":10000000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.","how_it_worked":"The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.","lessons":"Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.","confidence":"Reported","sources":[{"title":"Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match","url":"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/","publisher":"BleepingComputer"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill"},{"slug":"2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec","title":"Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Crunchbase","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":2000000,"threat_actor":"ShinyHunters","summary":"Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.","how_it_worked":"The attackers called Crunchbase staff and posed as internal IT support, using a pretext about an account or access issue that required the employee to sign in while the caller stayed on the line. The employee entered Okta single sign-on credentials and read back the one-time code, which the caller replayed against the live Okta login within its validity window, producing an authenticated session under a legitimate staff identity. The trust signals abused were the routine familiarity of an IT support call and the employee's own genuine Okta prompt; the pressure was urgency framed as fixing a problem already affecting the employee's access.","lessons":"Phishing-resistant, origin-bound authenticators remove the readable one-time code these calls depend on, and a standing rule that IT never requests codes by phone gives staff a clean refusal script.","confidence":"Reported","sources":[{"title":"Crunchbase Confirms Data Breach After Hacking Claims","url":"https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/","publisher":"SecurityWeek"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"},{"title":"ShinyHunters claims 2 Million Crunchbase records; company confirms breach","url":"https://securityaffairs.com/187340/data-breach/shinyhunters-claims-2-million-crunchbase-records-company-confirms-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec"},{"slug":"2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands","title":"CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Users of malicious Chrome extension impersonating uBlock Origin Lite","sector":"Technology","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.","how_it_worked":"The lure inverted the usual ClickFix pattern. Rather than a fake CAPTCHA, the attackers manufactured a real, visible fault: the installed extension broke the victim's browser, then presented a repair prompt that looked like a security notice. Because the user had genuinely just experienced a crash, the instruction to paste a command into a terminal read as a fix rather than an attack. Operators showed selectivity, deploying extra backdoors only where the compromised host was domain-joined, indicating they were filtering for enterprise environments worth returning to.","lessons":"Blocking clipboard-to-shell execution patterns and restricting extension installation to an allowlist stops the paste step, which is the only point where the user's action is required.","confidence":"Confirmed","sources":[{"title":"New ClickFix variant 'CrashFix' deploying Python Remote Access Trojan","url":"https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands"},{"slug":"2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c","title":"Five plead guilty to helping North Korean IT workers infiltrate 136 US companies","date":"2025-11","date_precision":"month","year":2025,"victim_org":"136 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":2200000,"loss_kind":"criminal_proceeds","loss_note":"About $2.2 million in revenue generated for the North Korean government through the roles obtained; one defendant agreed to forfeit more than $1.4 million.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.","how_it_worked":"Three of the defendants let overseas workers use their real US identities to apply for and hold remote IT jobs, so background checks returned clean results for genuine Americans. Others hosted company-issued laptops at their homes and installed remote desktop software so workers abroad appeared to be sitting at a US desk. A fourth trafficked stolen and rented identities through a website marketed at overseas jobseekers. The deception targeted HR and IT onboarding rather than any technical control: the trust signals abused were verified identity documents, a US shipping address and a US-looking network origin, all of which onboarding processes treat as proof of presence.","lessons":"Tie identity verification to a live check at onboarding and re-verify periodically; monitor corporate laptops for remote-control tooling and for logins whose network geography does not match the employee's stated location.","confidence":"Confirmed","sources":[{"title":"Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies","url":"https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html","publisher":"The Hacker News"},{"title":"Ukrainian national pleads guilty in 'laptop farm' scheme that generated income for North Korean IT workers","url":"https://www.justice.gov/usao-dc/pr/ukrainian-pleads-guilty-dc-laptop-farm-scheme-generated-income-north-korean-it-workers","publisher":"US Department of Justice"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c"},{"slug":"2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se","title":"Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service","date":"2025-09-16","date_precision":"day","year":2025,"victim_org":"Microsoft 365 customers in 94 countries, including US healthcare organisations","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000,"threat_actor":"Storm-2246 / RaccoonO365 (Nigeria-based operator named by Microsoft)","summary":"Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.","how_it_worked":"Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.","lessons":"Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.","confidence":"Confirmed","sources":[{"title":"Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service","url":"https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/","publisher":"Microsoft On the Issues"},{"title":"Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service","url":"https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"},{"title":"Workday discloses CRM breach after social engineering of employees","date":"2025-08-06","date_precision":"day","victim_org":"Workday","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign","summary":"Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.","how_it_worked":"Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.","lessons":"Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.","confidence":"Confirmed","sources":[{"title":"Workday hit by social engineering data breach targeting its CRM platform","url":"https://therecord.media/workday-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Human resources firm Workday disclosed a data breach","url":"https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-workday-discloses-crm-breach-after-social-engineering-of-employees","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"},{"title":"North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs","date":"2025-08","date_precision":"month","victim_org":"US Fortune 500 technology companies employing fraudulent remote workers","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.","outcomes":["Insider Access","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Salaries paid to fraudulent workers fund DPRK weapons programmes; amounts not quantified in this report","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.","how_it_worked":"The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.","lessons":"Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"},{"slug":"2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm","title":"Cisco confirms vishing call gave attacker access to its third-party CRM instance","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (Salesforce vishing wave)","summary":"Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.","how_it_worked":"The attacker telephoned a Cisco representative and, using an internal-sounding pretext, persuaded them to authorise access to the company's instance of a third-party cloud CRM platform. This is the pattern Google's threat intelligence team documented as UNC6040: callers impersonate IT support and talk the target through granting a connected application or completing a sign-in that hands the caller an authenticated CRM session. The trust signals abused were a plausible internal support identity and the ordinariness of the request, and the abuse was quick and quiet enough that the export was complete before the account activity was identified.","lessons":"Restricting who can authorise connected applications in the CRM, and requiring a call-back through a verified internal directory number before any access-granting action, closes the path a single persuaded employee opens.","confidence":"Confirmed","sources":[{"title":"Vishing Attack Impacting Third-Party CRM System","url":"https://sec.cloudapps.cisco.com/security/center/resources/CRM-vishing","publisher":"Cisco (company advisory)"},{"title":"Cisco discloses data breach impacting Cisco.com user accounts","url":"https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm"},{"slug":"2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f","title":"Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"More than 300 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_kind":"criminal_proceeds","loss_note":"Approximately $17 million in wages and revenue generated for North Korea through the scheme; the defendant was ordered to forfeit roughly $284,000 and pay about $177,000 in restitution.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.","how_it_worked":"Overseas operatives applied for remote IT roles using stolen or borrowed US identities and forged documents, passing HR checks and video screening because the identity paperwork was genuine and the impersonation was rehearsed. Companies shipped corporate laptops to what they believed was the employee's US home address; in fact the machines were racked at the facilitator's house, where remote access software let workers in Asia operate them from apparently American IP addresses. The trust signals abused were a valid Social Security number, a plausible US address and a working corporate device. Payroll then flowed to US accounts before being laundered abroad.","lessons":"Verify remote hires with live identity proofing tied to the device shipping address, and alert on remote-management software or geographic mismatch on corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced in $17M IT worker fraud scheme that illegally generated revenue for North Korea","url":"https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north","publisher":"US Department of Justice"},{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f"},{"title":"US sweep seizes 200 computers from North Korean IT worker laptop farms","date":"2025-06-30","date_precision":"day","victim_org":"More than 100 US companies, including many Fortune 500 firms","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"DOJ described stolen and fraudulent identities; the announcement reviewed did not specify AI-generated personas.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access","Espionage","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ cited at least $3 million in victim-company losses for legal fees and remediation, more than $5 million in revenue in one Massachusetts scheme, roughly $915,000 in virtual currency stolen in a Georgia case, and a civil forfeiture action covering over $7.74 million in digital assets. US facilitators received at least $696,000.","records_affected":null,"threat_actor":"DPRK remote IT worker networks and US-based facilitators (Zhenxing 'Danny' Wang, Kejia Wang and others)","summary":"On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.","how_it_worked":"North Korean workers obtained remote US employment using stolen and fabricated identities that cleared employer background checks. US-based facilitators supplied the American presence the scheme needed: they registered shell companies and fraudulent websites so the identities had verifiable employment history, received the employers' shipped laptops, and installed keyboard-video-mouse switches and remote access software so overseas operators could drive the machines as though sitting in front of them. From inside those employers the workers drew salaries routed to the DPRK, and in several cases went further, exfiltrating sensitive data including export-controlled military technology and stealing virtual currency from employer systems.","lessons":"Employers need live identity proofing tied to the government ID at hire, verification that the issued device is physically where the employee claims to be, and alerting on KVM or remote-access hardware attached to corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers","url":"https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote","publisher":"U.S. Department of Justice"},{"title":"U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms","url":"https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html","publisher":"The Hacker News"}],"entry_type":"campaign","slug":"2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms"},{"title":"Google's own Salesforce instance hit by UNC6040 IT-support vishing","date":"2025-06","date_precision":"month","victim_org":"Google","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.","records_affected":null,"threat_actor":"UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'","summary":"Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.","how_it_worked":"Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.","lessons":"Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.","confidence":"Confirmed","sources":[{"title":"Salesforce customers duped by series of social-engineering attacks","url":"https://cyberscoop.com/google-unc6040-salesforce-attacks/","publisher":"CyberScoop"},{"title":"Google confirms Salesforce CRM breach, faces extortion threat","url":"https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html","publisher":"Security Affairs"},{"title":"FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups","url":"https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html","publisher":"Security Affairs"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"},{"title":"ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications","url":"https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications","publisher":"EclecticIQ"}],"entry_type":"incident","slug":"2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"},{"title":"North Korean operatives adopt real-time deepfakes to pass remote job interviews","date":"2025-04","date_precision":"month","victim_org":"Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Deepfake Video Call","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.","how_it_worked":"The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.","lessons":"Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.","confidence":"Confirmed","sources":[{"title":"False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation","url":"https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/","publisher":"Palo Alto Networks Unit 42"},{"title":"North Korean Operatives Use Deepfakes in IT Job Interviews","url":"https://www.darkreading.com/remote-workforce/north-korean-operatives-deepfakes-it-job-interviews","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int"},{"title":"Rippling sues Deel over a manager allegedly recruited as a corporate spy","date":"2025-03-17","date_precision":"day","victim_org":"Rippling","sector":"Technology","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was alleged.","outcomes":["Insider Access","Espionage","Data Breach"],"loss_usd":null,"loss_note":"No loss figure has been established. The complaint alleges payment to the employee laundered through an intermediary; the allegations are contested and litigation is ongoing.","records_affected":null,"threat_actor":"Alleged: a Rippling employee acting on behalf of competitor Deel. Deel disputes the allegations; a related DOJ inquiry has been reported.","summary":"On March 17, 2025 Rippling sued rival HR and payroll company Deel in the Northern District of California, alleging Deel cultivated a Rippling employee as a spy. The complaint says the employee searched Rippling systems for 'Deel' an average of 23 times a day over four months and accessed Slack channels more than 6,000 times without business justification, funnelling sales pipeline data, pricing, customer churn lists and employee contact details to Deel. Deel denies wrongdoing and the litigation continues.","how_it_worked":"The alleged access was entirely legitimate on its face. A person in a management role at a Rippling affiliate used their normal credentials to run searches and read Slack channels, activity that generated no security alerts because none of it was unauthorised in a technical sense; the abuse was in volume and purpose. Rippling exposed it with a honeypot rather than a detection rule: it sent a letter to three Deel executives referencing a Slack channel called 'd-defectors' that existed but had never contained a single message. Within hours the employee searched for that never-used channel for the first time, which Rippling argues shows the letter's contents were relayed to him. He was confronted when court-appointed solicitors sought his phone.","lessons":"Insider risk programmes need behavioural baselining on internal search and channel access, since a recruited insider's activity is authorised by definition and only its pattern gives it away.","confidence":"Alleged","sources":[{"title":"Lawsuit Alleges $12 Billion 'Unicorn' Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor","url":"https://www.rippling.com/blog/lawsuit-alleges-12-billion-unicorn-deel-cultivated-spy-orchestrated-long-running-trade-secret-theft-corporate-espionage-against-competitor","publisher":"Rippling"},{"title":"Rippling accuses competitor Deel of corporate espionage","url":"https://www.hr-brew.com/stories/2025/03/20/rippling-deel-corporate-espionage","publisher":"HR Brew"}],"entry_type":"incident","slug":"2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy"},{"title":"Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport","date":"2024-10","date_precision":"month","victim_org":"Wiz","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers built a voice clone of chief executive Assaf Rappaport from audio of a conference talk and sent synthetic voice messages to dozens of employees seeking their credentials.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.","how_it_worked":"The attackers scaled a single cloned sample across dozens of recipients, betting that at least one employee would act on what sounded like a direct request from the chief executive. Voice messages rather than live calls removed the risk of interactive questions and let the same recording be reused, while the boss's authority supplied the pressure to comply quickly with a credential request. The flaw was in the source material: the only clean public audio was a conference keynote, so the clone inherited a projected, presentational tone that colleagues who hear Rappaport daily immediately found off. Employees compared notes and reported the messages rather than responding.","lessons":"Credential requests should never be actionable from a voice message, and mass-distribution patterns across many employees should trigger automated correlation and alerting.","confidence":"Confirmed","sources":[{"title":"Wiz CEO says company was targeted with deepfake attack that used his voice","url":"https://techcrunch.com/2024/10/28/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice/","publisher":"TechCrunch"},{"title":"Hackers Sent a Deepfake of Wiz CEO to Dozens of Employees","url":"https://www.entrepreneur.com/business-news/hackers-sent-a-deepfake-of-wiz-ceo-to-dozens-of-employees/482027","publisher":"Entrepreneur"}],"entry_type":"incident","slug":"2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa"},{"title":"KnowBe4 hired a North Korean fake IT worker who loaded malware on day one","date":"2024-07-15","date_precision":"day","victim_org":"KnowBe4","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The candidate's profile photo was a stock image manipulated with AI to match a stolen US identity, and KnowBe4 described the persona as an AI deepfake that held up across four video interviews.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"No loss occurred. KnowBe4 stated no data was accessed and no systems were compromised.","records_affected":null,"threat_actor":"DPRK state-sponsored fake IT worker, confirmed with Mandiant and the FBI","summary":"Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.","how_it_worked":"The persona was assembled rather than invented: a real US person's identity supplied the details that background and reference checks validated, and a stock photograph enhanced with AI supplied a face consistent enough to survive four video calls. The shipping address was not a home but an IT mule laptop farm, so the corporate workstation arrived at a location that would keep it online in the US while the operative connected in by VPN from North Korea or nearby, working nights to match US hours. Within minutes of receipt the operative used a Raspberry Pi to download malware onto the workstation and began manipulating session history files. Challenged by the SOC, they claimed router troubleshooting, then went silent.","lessons":"Live identity verification against the government ID during interviews, plus device shipment to a verified address and endpoint monitoring that treats day-one activity as high-risk, are what turned this into a contained incident rather than a breach.","confidence":"Confirmed","sources":[{"title":"How a North Korean Fake IT Worker Tried to Infiltrate Us","url":"https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us","publisher":"KnowBe4"},{"title":"KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware","url":"https://www.securityweek.com/knowbe4-hires-fake-north-korean-it-worker-catches-new-employee-planting-malware/","publisher":"SecurityWeek"},{"title":"Cyber firm KnowBe4 hired a fake IT worker from North Korea","url":"https://cyberscoop.com/cyber-firm-knowbe4-hired-a-fake-it-worker-from-north-korea/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on"},{"title":"Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs","date":"2024-04-01","date_precision":"day","victim_org":"Cisco Duo (via an unnamed telephony supplier)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.","how_it_worked":"The attack did not target Duo at all; it targeted the intermediary that physically delivers Duo's SMS one-time codes, an organisation most Duo customers had never heard of. A single employee's credentials were enough to reach the message log store. The stolen data is second-order ammunition rather than direct access: knowing which phone number belongs to which enterprise user, on which carrier, and when they authenticate, is precisely what a SIM-swap or help-desk-impersonation crew needs to build a convincing call and to time it against a real login.","lessons":"Move off SMS as an MFA channel where possible, and require phishing-resistant authentication and log-access controls from downstream communications suppliers.","confidence":"Confirmed","sources":[{"title":"Cisco Duo warns telephony supplier data breach exposed MFA SMS logs","url":"https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs"},{"title":"LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO","date":"2024-04","date_precision":"month","victim_org":"LastPass","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.","how_it_worked":"The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.","lessons":"A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.","confidence":"Confirmed","sources":[{"title":"Attempted Audio Deepfake Call Targets LastPass Employee","url":"https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee","publisher":"LastPass"},{"title":"LastPass: Hackers targeted employee in failed deepfake CEO call","url":"https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/","publisher":"BleepingComputer"},{"title":"LastPass employee targeted via an audio deepfake call","url":"https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"},{"title":"Arizona laptop farm placed North Korean IT workers at 309 US companies","date":"2023-10","date_precision":"month","victim_org":"309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The DOJ case documents describe stolen real identities rather than AI-generated personas; no AI use was specified in the sentencing reporting.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_note":"The scheme generated approximately $17 million in revenue for the North Korean government. Chapman was ordered to forfeit $284,555.92 intended for North Korea and to pay a $176,850 fine.","records_affected":68,"threat_actor":"DPRK IT worker network, facilitated by Christina Marie Chapman","summary":"From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.","how_it_worked":"North Korean operatives applied for remote IT roles under the identities of real Americans, clearing background checks because the identities were genuine. When each employer shipped a work laptop to the address on file, that address was Chapman's house. She installed remote access software on each machine and kept them running so the workers could connect daily and appear on the employer's network from a US residential IP on US business hours. Chapman also received the direct-deposit wages, forged payroll checks and filed tax returns in the stolen names before moving the money overseas. Employers saw nothing anomalous because the device, the network location and the paperwork were all genuinely American.","lessons":"Verifying that a shipped device is actually in the hands of the person hired, through live video identity checks at onboarding and device-location attestation, is what breaks the laptop farm model.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record (Recorded Future News)"},{"title":"Arizona woman imprisoned for $17M North Korean remote workers scheme","url":"https://www.upi.com/Top_News/US/2025/07/24/chapman-north-korea-remote-workers-fraud/7551753396658/","publisher":"UPI"}],"entry_type":"incident","slug":"2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies","year":2023,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies"},{"title":"Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee","date":"2023-08-27","date_precision":"day","victim_org":"Retool","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Voice Clone / Audio Deepfake","Vishing (Voice Phishing)","Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Retool stated the caller used a deepfaked voice imitating a specific member of its IT team, whom the target employee knew. This is one of the earliest well-documented uses of voice cloning in a corporate intrusion.","outcomes":["Data Breach","Cryptocurrency Theft","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Retool reported no loss of its own; downstream, cryptocurrency customer Fortress Trust separately reported a theft of roughly $15 million tied to the compromise, a figure attributed to Fortress Trust rather than confirmed by Retool.","records_affected":27,"threat_actor":null,"summary":"Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.","how_it_worked":"The employee received a text claiming to be from Retool IT about a payroll and healthcare enrolment issue, with a link to a page cloning the company's internal identity portal. After the employee submitted credentials and an MFA code, the attacker phoned them; the voice was a deepfake of a specific IT team member the employee recognised, and the caller was familiar with office layout, colleagues and internal processes. During the call the employee provided an additional MFA code, which let the attacker add their own device to the employee's Okta account. From there they reached the employee's Google account, where Authenticator's cloud sync had backed up OTP seeds, and used those to pivot into internal admin systems and alter customer accounts.","lessons":"Voice is no longer an identity proof; hardware security keys plus a policy that MFA codes are never read aloud, and disabling authenticator cloud sync on enterprise accounts, close both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Retool blames breach on Google Authenticator MFA cloud sync feature","url":"https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/","publisher":"BleepingComputer"},{"title":"Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients","url":"https://thehackernews.com/2023/09/retool-falls-victim-to-sms-based.html","publisher":"The Hacker News"},{"title":"Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks","url":"https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/","publisher":"SecurityWeek"},{"title":"When MFA isn't actually MFA","url":"https://retool.com/blog/mfa-isnt-mfa","publisher":"Retool"}],"entry_type":"incident","slug":"2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp"},{"title":"Okta warns of a coordinated campaign against US customers' IT service desks","date":"2023-08","date_precision":"month","victim_org":"Multiple US-based Okta customer organizations","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in Okta's advisory.","outcomes":["Credential Theft","Data Breach","Insider Access"],"loss_usd":null,"loss_note":"Okta did not name victims or quantify losses in this advisory.","records_affected":null,"threat_actor":"Actor consistent with Scattered Spider / Muddled Libra (unnamed in the advisory)","summary":"Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.","how_it_worked":"The caller arrived already holding something: either the password to a privileged account or the ability to manipulate delegated authentication. That partial knowledge is what makes the help desk call succeed, because the agent hears a caller who knows their own username, manager and internal jargon, and treats an MFA reset as routine. Once the factors were reset the actor enrolled their own, signed in from anonymising proxies on unfamiliar devices, escalated to Super Administrator and stood up a second identity provider so they could impersonate arbitrary users through federation.","lessons":"Identity-proofing the caller out of band, such as manager attestation or video verification, plus admin-console policies that require phishing-resistant factors and known devices, breaks the reset-to-takeover chain.","confidence":"Confirmed","sources":[{"title":"Cross-Tenant Impersonation: Prevention and Detection","url":"https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/","publisher":"Okta Security"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"campaign","slug":"2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des"},{"slug":"2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro","title":"EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts","date":"2023-08","date_precision":"month","year":2023,"victim_org":"More than 100 organisations worldwide (Proofpoint-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.","how_it_worked":"Emails impersonated widely trusted services such as Adobe, DocuSign and Concur, and pushed recipients through redirect chains to an EvilProxy page that relayed the real Microsoft 365 log-in. Victims entered their password and completed their genuine MFA challenge, and the proxy captured the resulting session cookie, so MFA provided no protection. The campaign filtered its own traffic, screening out non-target regions and security-research infrastructure, and deliberately concentrated on executives whose mailboxes carry payment authority and confidential deal information. Successful intrusions were consolidated by enrolling an attacker-controlled MFA method, converting a one-time theft into durable access.","lessons":"Phishing-resistant FIDO2 credentials for high-value roles, and alerting whenever a new MFA method is registered on an executive account, are the controls that matter here.","confidence":"Confirmed","sources":[{"title":"EvilProxy Phishing Used for Cloud Account Takeover Campaign","url":"https://www.proofpoint.com/us/blog/email-and-cloud-threats/cloud-account-takeover-campaign-leveraging-evilproxy-targets-top-level","publisher":"Proofpoint"},{"title":"EvilProxy phishing campaign targets 120,000 Microsoft 365 users","url":"https://www.bleepingcomputer.com/news/security/evilproxy-phishing-campaign-targets-120-000-microsoft-365-users/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro"},{"slug":"2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d","title":"Dragos intrusion began with the hijacked personal email of an employee due to start work","date":"2023-05-08","date_precision":"day","year":2023,"victim_org":"Dragos","sector":"Technology","country":"United States","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"No ransom paid; Dragos refused to engage with the extortion attempt.","records_affected":null,"threat_actor":null,"summary":"Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.","how_it_worked":"The attacker targeted the gap that exists before a new hire's first day, when the person has an accepted offer but no corporate identity yet. Having taken over the recruit's personal email, the criminal completed the onboarding steps in their name, receiving credentials and access as the company believed it was equipping its own new starter. That produced legitimate access to onboarding-tier resources including SharePoint and a contract system. When ransomware deployment failed, the group escalated to personal pressure, contacting executives' private accounts and naming relatives to force negotiation. Dragos's SIEM alerts surfaced the activity and the account was blocked.","lessons":"Onboarding must verify identity through a channel independent of the address on the offer letter, and new-hire accounts should start with minimal access under heightened monitoring.","confidence":"Confirmed","sources":[{"title":"Deconstructing a Cybersecurity Event","url":"https://www.dragos.com/blog/deconstructing-a-cybersecurity-event","publisher":"Dragos"},{"title":"Cybersecurity firm Dragos discloses cybersecurity incident, extortion attempt","url":"https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d"},{"title":"3CX supply chain attack began with a trojanised X_TRADER installer on staff PC","date":"2023-03-29","date_precision":"day","victim_org":"3CX Ltd.","sector":"Technology","country":"Cyprus","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure published; 3CX said it had over 600,000 customer companies, though only a subset installed the trojanised builds.","records_affected":null,"threat_actor":"UNC4736 / Lazarus-linked North Korean cluster (Mandiant attribution)","summary":"In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.","how_it_worked":"The employee retrieved what appeared to be a legitimate, digitally signed X_TRADER installer from the vendor's website in 2022. The package carried the VEILEDSIGNAL backdoor, giving the attackers a foothold and the employee's 3CX corporate credentials. Using those credentials the intruders moved into 3CX's network, reached the Windows and macOS build systems, and inserted malicious code into the desktop app build pipeline so that shipped, code-signed updates carried a downloader. Affected customer installations fetched encrypted payloads hidden in icon files on GitHub and, for a small number of selected targets, received a second-stage infostealer. Some reporting has also referred to fake-recruiter lures against 3CX staff, but the confirmed initial vector is the trojanised installer.","lessons":"Build systems should be reachable only from hardened, managed workstations with no personal software installation, and installers from any vendor should be validated against a known-good hash and detonated before use.","confidence":"Confirmed","sources":[{"title":"3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise","url":"https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise","publisher":"Mandiant / Google Cloud"},{"title":"3CX Breach Was a Double Supply Chain Compromise","url":"https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/","publisher":"Krebs on Security"},{"title":"Security Update 20 April 2023 - Initial Intrusion Vector Found","url":"https://www.3cx.com/blog/news/mandiant-security-update2/","publisher":"3CX"}],"entry_type":"incident","slug":"2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st"},{"title":"Reddit source code stolen via a phishing site cloning its intranet gateway","date":"2023-02-05","date_precision":"day","victim_org":"Reddit","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.","how_it_worked":"The campaign sent plausible-sounding prompts to employees pointing at a cloned intranet gateway login page. One employee entered their credentials and their second-factor token into the clone; because the token was relayed immediately, the attacker completed a session on the real gateway. During a limited window the intruder accessed internal documents, limited source code, some internal dashboards and contact information for a few hundred current and former employees, plus information on advertisers. The employee self-reported quickly, which let Reddit revoke the session and lock the account, limiting dwell time to hours rather than weeks.","lessons":"Phishing-resistant MFA defeats token-relay pages outright, and a blame-free self-reporting culture is what turned this into hours of exposure rather than months.","confidence":"Confirmed","sources":[{"title":"Reddit says limited amount of source code, employee data accessed in phishing attack","url":"https://www.cybersecuritydive.com/news/reddit-source-code-employee-data-phishing/642510/","publisher":"Cybersecurity Dive"},{"title":"Reddit Suffers Security Breach Exposing Internal Documents and Source Code","url":"https://thehackernews.com/2023/02/reddit-suffers-security-breach-exposing.html","publisher":"The Hacker News"},{"title":"Reddit discloses security breach that exposed source code and internal docs","url":"https://securityaffairs.com/142071/data-breach/reddit-security-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-reddit-source-code-stolen-via-a-phishing-site-cloning-its-intranet-gatew","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-reddit-source-code-stolen-via-a-phishing-site-cloning-its-intranet-gatew"},{"title":"Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers","date":"2023-01-11","date_precision":"day","victim_org":"Mailchimp (Intuit)","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published; downstream Trezor customers were subsequently targeted by wallet-draining phishing.","records_affected":null,"threat_actor":null,"summary":"Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.","how_it_worked":"Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.","lessons":"Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.","confidence":"Confirmed","sources":[{"title":"Mailchimp suffers another data breach after social engineering attack on employees","url":"https://www.computing.co.uk/news/4063093/mailchimp-suffers-breach-social-engineering-attack-employees","publisher":"Computing"},{"title":"DigitalOcean says customer email addresses were exposed","url":"https://techcrunch.com/2022/08/16/digitalocean-emails-mailchimp-breach/","publisher":"TechCrunch"},{"title":"Impact to DigitalOcean customers resulting from Mailchimp security incident","url":"https://www.digitalocean.com/blog/digitalocean-response-to-mailchimp-security-incident","publisher":"DigitalOcean"},{"title":"Mailchimp suffers third breach in 12 months","url":"https://www.computerweekly.com/news/252529368/Mailchimp-suffers-third-breach-in-12-months","publisher":"Computer Weekly"},{"title":"IOTW: Mailchimp suffers another social engineering attack","url":"https://www.cshub.com/attacks/news/iotw-mailchimp-suffers-another-social-engineering-attack","publisher":"Cyber Security Hub"},{"title":"Mailchimp discloses a new security breach, the second one in 6 months","url":"https://securityaffairs.com/140997/data-breach/mailchimp-security-breach.html","publisher":"Security Affairs"},{"title":"Companies impacted by Mailchimp data breach warn their customers","url":"https://securityaffairs.com/141203/data-breach/companies-impacted-by-mailchimp-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor"},{"title":"Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing","date":"2022-10-14","date_precision":"day","victim_org":"Dropbox","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.","how_it_worked":"The lure imitated CircleCI, a service Dropbox developers used and which legitimately prompts users to sign in with GitHub, so the request to authenticate looked routine. The phishing page collected the GitHub username, password and the time-based one-time passcode, which the attacker replayed immediately to establish a session. With developer access they cloned 130 private repositories containing modified third-party libraries, internal prototypes, and some security team tools and configuration files, along with a few thousand names and email addresses for employees, current and past customers, sales leads and vendors. Dropbox rotated credentials and moved to accelerate its rollout of hardware security keys.","lessons":"Time-based one-time passcodes are phishable in real time; WebAuthn keys on source-control accounts, and machine-to-machine tokens scoped per repository, remove both halves of this attack.","confidence":"Confirmed","sources":[{"title":"130 Dropbox code repos plundered after successful phishing attack","url":"https://www.helpnetsecurity.com/2022/11/02/dropbox-data-breach/","publisher":"Help Net Security"},{"title":"Dropbox Suffers Data Breach From Phishing Attack, Exposing Customer and Employee Emails","url":"https://blog.gitguardian.com/dropbox-breach-hack-github-circleci/","publisher":"GitGuardian"},{"title":"Dropbox confirms serious security breach in which hackers stole code from 130 GitHub repositories","url":"https://betanews.com/2022/11/02/dropbox-confirms-serious-security-breach-in-which-hackers-stole-code-from-130-github-repositories/","publisher":"BetaNews"}],"entry_type":"incident","slug":"2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing"},{"title":"Zendesk breach followed successful SMS phishing of employees","date":"2022-10","date_precision":"month","victim_org":"Zendesk","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.","how_it_worked":"Employees received text messages that led to a page impersonating Zendesk's single sign-on portal. Several staff entered their credentials, which the attacker used to authenticate to internal systems. Because Zendesk operates a support ticketing platform for other businesses, mailboxes and ticket stores can contain customer correspondence, attachments and account details belonging to Zendesk's own clients, which is what created the downstream exposure. Zendesk described the incident as a sophisticated SMS phishing campaign, disabled the affected accounts and notified customers whose service data may have been reached.","lessons":"SaaS providers holding tenant data should mandate phishing-resistant MFA for all staff and alert on employee logins from unfamiliar devices to tenant-facing consoles.","confidence":"Reported","sources":[{"title":"Zendesk Hacked After Employees Fall for Phishing Attack","url":"https://www.securityweek.com/zendesk-hacked-after-employees-fall-for-phishing-attack/","publisher":"SecurityWeek"},{"title":"Compromised Zendesk Employee Credentials Lead to Breach","url":"https://www.darkreading.com/application-security/compromised-zendesk-employee-credentials-breach","publisher":"Dark Reading"},{"title":"Zendesk hit by phishing-related data breach","url":"https://www.scworld.com/brief/zendesk-hit-by-phishing-related-data-breach","publisher":"SC Media"}],"entry_type":"incident","slug":"2022-zendesk-breach-followed-successful-sms-phishing-of-employees","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-zendesk-breach-followed-successful-sms-phishing-of-employees"},{"slug":"2022-github-warns-of-phishing-campaign-impersonating-circleci-to-steal-develo","title":"GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials","date":"2022-09-16","date_precision":"day","year":2022,"victim_org":"GitHub users and customer organisations (GitHub-reported campaign)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.","how_it_worked":"Developers received emails claiming that CircleCI's terms of service and privacy policy had changed and that they needed to sign in to their GitHub account to keep using the service. The link led to a convincing GitHub log-in page under attacker control, which relayed the entered username, password and TOTP code to the real GitHub in real time. The pretext worked because CircleCI is a legitimate part of many developers' daily toolchain and a policy-update notice is mundane, while the audience, engineers with repository and token privileges, is exactly the population whose accounts unlock source code and downstream software supply chains.","lessons":"Hardware security keys are the only MFA form that survives a real-time relay, and organisations should alert on new personal access tokens, OAuth grants and SSH keys added to developer accounts.","confidence":"Confirmed","sources":[{"title":"Security alert: new phishing campaign targets GitHub users","url":"https://github.blog/news-insights/company-news/security-alert-new-phishing-campaign-targets-github-users/","publisher":"The GitHub Blog"},{"title":"Hackers Using Fake CircleCI Notifications to Hack GitHub Accounts","url":"https://thehackernews.com/2022/09/hackers-using-fake-circleci.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-github-warns-of-phishing-campaign-impersonating-circleci-to-steal-develo"},{"title":"Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers","date":"2022-08-04","date_precision":"day","victim_org":"Twilio","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the kit relayed credentials to operators via Telegram in real time.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published across the affected organisations.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (tracked by Okta and Group-IB; overlaps with Scattered Spider reporting)","summary":"In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.","how_it_worked":"The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.","lessons":"SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.","confidence":"Confirmed","sources":[{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Twilio confirms data breach after its employees got phished","url":"https://www.helpnetsecurity.com/2022/08/09/twilio-phished-data-breach/","publisher":"Help Net Security"},{"title":"Twilio says breach also compromised Authy two-factor app users","url":"https://techcrunch.com/2022/08/26/twilio-breach-authy/","publisher":"TechCrunch"},{"title":"Incident Report: Employee and Customer Account Compromise","url":"https://www.twilio.com/en-us/blog/archive/2022/august-2022-social-engineering-attack","publisher":"Twilio"}],"entry_type":"incident","slug":"2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust"},{"slug":"2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai","title":"Klaviyo employee phished; attacker used internal tools to take crypto mailing lists","date":"2022-08-03","date_precision":"day","year":2022,"victim_org":"Klaviyo","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.","how_it_worked":"The employee's log-in credentials were captured through a phishing attack, giving the attacker an authenticated session inside Klaviyo's internal support environment. From there the operation was pure search: the attacker queried the customer base specifically for cryptocurrency companies and pulled their subscriber lists. The objective was never Klaviyo itself but the audience data its crypto customers had entrusted to it, because a verified list of a crypto exchange's subscribers is a ready-made target set for wallet-draining phishing. Klaviyo subsequently restricted employee access to internal tooling and improved detection of anomalous internal behaviour.","lessons":"Phishing-resistant MFA on staff accounts plus alerting on unusual cross-tenant queries in support tools would have caught a search pattern this specific.","confidence":"Confirmed","sources":[{"title":"Klaviyo security incident","url":"https://www.klaviyo.com/blog/august-2022-security-incident","publisher":"Klaviyo"},{"title":"Email marketing firm hacked to steal crypto-focused mailing lists","url":"https://www.bleepingcomputer.com/news/security/email-marketing-firm-hacked-to-steal-crypto-focused-mailing-lists/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai"},{"slug":"2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org","title":"0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations","date":"2022-08","date_precision":"month","year":2022,"victim_org":"Over 130 organisations targeted (Group-IB tracked campaign)","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":9931,"threat_actor":"0ktapus (linked to Scattered Spider / UNC3944 activity)","summary":"Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.","how_it_worked":"Employees received text messages, often outside working hours, claiming their VPN session had expired or that a schedule change required immediate action, with a link to what looked like their employer's Okta single sign-on page. The pages were cloned per target company, so each recipient saw their own branding. Victims typed their username, password and then the one-time MFA code, all of which were relayed to the operators in real time and used to log in before the code expired. SMS was chosen deliberately: it arrives on a phone, outside corporate email defences, and reads as urgent IT housekeeping rather than an attack.","lessons":"Only phishing-resistant authentication such as FIDO2 security keys defeats a real-time relay of passwords and one-time codes; SMS-delivered lures also need out-of-band IT verification channels staff actually know to use.","confidence":"Confirmed","sources":[{"title":"Roasting 0ktapus: The phishing campaign going after Okta identity credentials","url":"https://www.group-ib.com/blog/0ktapus/","publisher":"Group-IB"},{"title":"0ktapus Phishing Campaign Targets Okta Identity Credentials","url":"https://www.infosecurity-magazine.com/news/0ktapus-phishing-targets-okta/","publisher":"Infosecurity Magazine"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org"},{"title":"Cloudflare blocks the same SMS phishing attack that breached Twilio","date":"2022-07-20","date_precision":"day","victim_org":"Cloudflare","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; the intrusion attempt failed at the authentication step.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (same actor as the Twilio campaign)","summary":"On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.","how_it_worked":"The SMS lures directed staff to a convincing clone of Cloudflare's Okta sign-in page. Credentials typed into the clone were relayed in real time over Telegram, and the page also prompted for the second factor so operators could complete the login within the code's validity window. It additionally attempted to push AnyDesk remote access software to visitors for persistence if the credential path failed. Three employees submitted credentials, but the hardware keys are bound to the legitimate origin and would not produce a valid assertion for the attacker's domain, so no session was ever established. Cloudflare Gateway also blocked the malicious domain on corporate devices, and none of the targets installed the remote access tool.","lessons":"This is the control demonstration for the whole category: origin-bound hardware security keys make credential relay structurally impossible, regardless of how convincing the lure is.","confidence":"Confirmed","sources":[{"title":"The mechanics of a sophisticated phishing scam and how we stopped it","url":"https://blog.cloudflare.com/2022-07-sms-phishing-attacks/","publisher":"Cloudflare Blog"},{"title":"Cloudflare employees also hit by hackers behind Twilio breach","url":"https://www.bleepingcomputer.com/news/security/cloudflare-employees-also-hit-by-hackers-behind-twilio-breach/","publisher":"BleepingComputer"},{"title":"Cloudflare scuppers Twilio-like cyber attack with hardware keys","url":"https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys","publisher":"IT Pro"}],"entry_type":"incident","slug":"2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio"},{"slug":"2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or","title":"Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations","date":"2022-07-12","date_precision":"day","year":2022,"victim_org":"More than 10,000 organisations targeted (Microsoft-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Business Email Compromise","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.","how_it_worked":"Targets received phishing emails, often disguised as voice message notifications, linking to a proxy server that displayed the genuine Microsoft log-in page. The victim typed their real password and completed their real MFA challenge, both of which were passed straight through to Microsoft, so the experience was indistinguishable from a normal log-in. The proxy captured the resulting session cookie, which the attacker replayed to enter the mailbox without any further authentication. Microsoft observed operators moving to payment fraud within minutes, hunting invoice threads, adding hidden mailbox rules to suppress replies and emailing the victim's suppliers with altered bank details.","lessons":"Standard MFA is not proof against session-token theft; phishing-resistant credentials bound to the origin, plus conditional access on device compliance and token protection, are what break the proxy.","confidence":"Confirmed","sources":[{"title":"From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud","url":"https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/","publisher":"Microsoft Security Blog"},{"title":"Microsoft: 10,000 Organizations Targeted in Large-Scale Phishing Campaign","url":"https://www.securityweek.com/microsoft-10000-organizations-targeted-large-scale-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or"},{"title":"Cisco breached after vishing and MFA fatigue against an employee","date":"2022-05-24","date_precision":"day","victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No financial loss disclosed; Cisco said no impact to its business operations, products or supply chain.","records_affected":null,"threat_actor":"Initial access broker linked to UNC2447, Lapsus$ and Yanluowang","summary":"Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.","how_it_worked":"Credentials saved in Chrome were synchronised to the employee's personal Google account, which the attacker compromised. Holding valid corporate credentials, the attacker triggered a stream of MFA push prompts to wear the user down, while simultaneously calling them in English with a plausible accent posing as support from trusted organisations. The employee eventually approved one push, giving the attacker VPN access. They then enrolled new MFA devices, escalated to administrative privileges, added backdoor accounts, and used remote access tooling and LogMeIn/TeamViewer to maintain persistence, repeatedly attempting to return after eviction.","lessons":"Number matching or FIDO2 keys instead of simple push approval, plus blocking browser credential sync to personal accounts on managed devices, would have closed both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Cisco Talos shares insights related to recent cyber attack on Cisco","url":"https://blog.talosintelligence.com/recent-cyber-attack/","publisher":"Cisco Talos"},{"title":"Cisco Confirms Network Breach Via Hacked Employee Google Account","url":"https://threatpost.com/cisco-network-breach-google/180385/","publisher":"Threatpost"},{"title":"Cisco network hack: Voice phishing and MFA fatigue gave attacker access","url":"https://www.thestack.technology/cisco-network-hack-voice-phishing-mfa-fatigue/","publisher":"The Stack"}],"entry_type":"incident","slug":"2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee"},{"slug":"2022-hubspot-employee-account-compromised-exposing-customer-data-at-crypto-fi","title":"HubSpot employee account compromised, exposing customer data at crypto firms","date":"2022-03-18","date_precision":"day","year":2022,"victim_org":"HubSpot","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Supply Chain Compromise","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.","how_it_worked":"The attacker gained control of a single HubSpot employee's account and then used the internal support tooling that comes with it. That tooling is designed to let staff assist customers by reaching into their portals, so once inside there was no further exploitation required, only the normal use of a legitimate function. The attacker moved directly to cryptocurrency customers, exported their marketing contact lists, and thereby obtained the names, email addresses and in some cases phone numbers of people known to hold crypto, which is precisely the targeting list for follow-on phishing. Downstream customers had no visibility into the vendor account that held their data.","lessons":"Internal support tooling that can read customer data needs per-access justification, strict scoping and export alerting, so one compromised staff account cannot silently harvest many tenants.","confidence":"Confirmed","sources":[{"title":"Cryptocurrency Services Hit by Data Breach at CRM Company HubSpot","url":"https://www.securityweek.com/cryptocurrency-services-hit-data-breach-crm-company-hubspot/","publisher":"SecurityWeek"},{"title":"HubSpot Data Breach Ripples Through Cryptocurrency Industry","url":"https://threatpost.com/hubspot-data-breach-crytocurrency-industry/179086/","publisher":"Threatpost"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-hubspot-employee-account-compromised-exposing-customer-data-at-crypto-fi"},{"title":"Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling","date":"2022-01-21","date_precision":"day","victim_org":"Okta (via subprocessor Sitel/Sykes)","sector":"Technology","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Okta did not disclose a financial loss figure.","records_affected":null,"threat_actor":"Lapsus$","summary":"A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.","how_it_worked":"Lapsus$ specialised in abusing the human layer of outsourced IT: support agents at business-process outsourcers hold standing, broadly scoped access to customer tenants but sit outside the customer's own security controls. Having taken over a Sitel engineer's workstation, the actor inherited that trusted seat and drove the Okta SuperUser console as the agent, in the agent's session, from the agent's device. No password or MFA prompt was presented to the attacker because the legitimate operator had already satisfied them. The blast radius was limited only by what the support role could do.","lessons":"Outsourced support seats need the same scrutiny as privileged internal admins: just-in-time, scoped, session-recorded access with device trust, rather than standing tenant-wide impersonation rights.","confidence":"Confirmed","sources":[{"title":"Okta Concludes its Investigation Into the January 2022 Compromise","url":"https://www.okta.com/blog/company-and-culture/okta-concludes-its-investigation-into-the-january-2022-compromise/","publisher":"Okta"},{"title":"Okta says hundreds of companies impacted by security breach","url":"https://techcrunch.com/2022/03/23/okta-breach-sykes-sitel/","publisher":"TechCrunch"}],"entry_type":"incident","slug":"2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling"},{"title":"Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed","date":"2020-07-23","date_precision":"day","victim_org":"Garmin Ltd.","sector":"Technology","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Extortion"],"loss_usd":null,"loss_note":"Garmin never confirmed a ransom payment or a loss figure; press reporting of a multimillion-dollar payment is unverified.","records_affected":null,"threat_actor":"Evil Corp (WastedLocker operators)","summary":"Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.","how_it_worked":"In the WastedLocker campaigns of 2020 as documented by researchers, users browsing legitimate but compromised news and business websites were served a fake browser or Flash update overlay. Accepting the prompt downloaded a JavaScript-based loader, after which operators escalated privileges, moved laterally with Cobalt Strike and PowerShell, disabled security tooling and deployed WastedLocker across servers. For Garmin, only the ransomware family and the operational impact were publicly established; the entry point was never disclosed by the company or by law enforcement, so the human-deception element in this specific case is inferred from the campaign pattern rather than confirmed.","lessons":"Blocking user-initiated software updates from browser prompts and enforcing application control on workstations removes the fake-update lure that this ransomware family relied on.","confidence":"Alleged","sources":[{"title":"Garmin outage caused by confirmed WastedLocker ransomware attack","url":"https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/","publisher":"BleepingComputer"},{"title":"WastedLocker explained: How this targeted ransomware extorts millions from victims","url":"https://www.csoonline.com/article/569859/wastedlocker-explained-how-this-targeted-ransomware-extorts-millions-from-victims.html","publisher":"CSO Online"},{"title":"LockerGoga and WastedLocker ransomware insight","url":"https://www.recordedfuture.com/blog/lockergoga-ransomware-insight","publisher":"Recorded Future"}],"entry_type":"incident","slug":"2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c"},{"title":"Twitter's July 2020 account takeover started with phone spear phishing of employees","date":"2020-07-15","date_precision":"day","victim_org":"Twitter, Inc.","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"The callers used ordinary voice social engineering and pre-collected personal details; no synthetic voice was reported.","outcomes":["Cryptocurrency Theft","Data Breach","Credential Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":118000,"loss_note":"The New York Department of Financial Services investigation report puts the bitcoin obtained through the scam tweets at approximately $118,000.","records_affected":130,"threat_actor":"Graham Ivan Clark and co-conspirators (later criminally charged)","summary":"On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.","how_it_worked":"Callers rang Twitter staff claiming to be from the internal help desk and offering to fix VPN connectivity problems, a plausible complaint during the shift to remote working. They used personal information gathered in advance about each employee to sound credible, then directed the target to a site that mirrored Twitter's real VPN portal. As the employee typed their credentials and MFA code, the attackers entered the same values into the genuine portal, completing the login inside the code's validity window. From there they reached internal account-management tooling and used it to reset the email addresses and disable MFA on high-profile accounts.","lessons":"Phishing-resistant FIDO2/WebAuthn authenticators would have broken the real-time credential relay, and out-of-band callback verification for any unsolicited IT help desk contact would have stopped the pretext at the first call.","confidence":"Confirmed","sources":[{"title":"Twitter Investigation Report","url":"https://www.dfs.ny.gov/system/files/documents/2026/07/Twitter-Investigation-Report.pdf","publisher":"New York State Department of Financial Services"},{"title":"Department of Financial Services Calls for Regulation of Social Media Giants After Twitter Hack Investigation","url":"https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202010141","publisher":"New York State Department of Financial Services"},{"title":"Twitter breach: Staff tricked by 'phone spear phishing'","url":"https://www.welivesecurity.com/2020/07/31/twitter-breach-staff-tricked-phone-spear-phishing/","publisher":"ESET WeLiveSecurity"},{"title":"New York regulator faults Twitter for lax security measures prior to big account breach","url":"https://cyberscoop.com/twitter-hack-social-engineering-new-york-financial-services/","publisher":"CyberScoop"},{"title":"Twitter Investigation Report","url":"https://www.dfs.ny.gov/Twitter_Report","publisher":"New York State Department of Financial Services"},{"title":"Twitter says hackers used a telephone to fool staff and gain access","url":"https://www.nbcnews.com/business/business-news/twitter-says-hackers-used-telephone-fool-staff-gain-access-n1235466","publisher":"NBC News"}],"entry_type":"incident","slug":"2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o","year":2020,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o"},{"slug":"2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu","title":"Wipro employee accounts phished and used to attack the IT giant's own customers","date":"2019-04","date_precision":"month","year":2019,"victim_org":"Wipro Limited","sector":"Technology","country":"India","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Supply Chain Compromise","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.","how_it_worked":"Attackers ran a phishing campaign against Wipro staff and captured credentials for a number of corporate accounts. The value of those accounts was not Wipro's own data but Wipro's position as a trusted outsourcing provider with standing access into client environments. Emails sent from genuine Wipro addresses to client contacts carry an authority that no spoofed domain can match, so the compromised mailboxes became the delivery mechanism for attacks on downstream customers. The follow-on activity was financially motivated, centring on gift-card and payment fraud at the affected clients rather than espionage.","lessons":"Managed service providers need phishing-resistant MFA on all staff accounts and customer-side monitoring of provider access, because a phished MSP mailbox is a trusted channel into every client.","confidence":"Confirmed","sources":[{"title":"Wipro admits to potential breach to employee accounts by phishing attack","url":"https://www.computerweekly.com/news/252461760/Wipro-admits-to-potential-breach-to-employee-accounts-by-phishing-attack","publisher":"Computer Weekly"},{"title":"How Not to Acknowledge a Data Breach","url":"https://krebsonsecurity.com/2019/04/how-not-to-acknowledge-a-data-breach/comment-page-1/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu"},{"title":"Seagate CEO-impersonation phish exposes every US employee's W-2","date":"2016-03-01","date_precision":"day","victim_org":"Seagate Technology","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No direct wire loss; downstream harm was tax refund fraud exposure for employees.","records_affected":null,"threat_actor":null,"summary":"On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.","how_it_worked":"The attacker spoofed the display name and writing style of a senior executive and emailed payroll or HR staff during tax season with a short, direct request for the complete W-2 file. Two levers combined: the authority of a named chief executive and the seasonal normality of the request, since W-2 handling is exactly what payroll does in early March. The employee attached the full file and replied. Because W-2s pair Social Security numbers with income and address data, the single reply produced everything needed to file fraudulent tax refunds in each employee's name.","lessons":"Bulk employee tax or PII files should never be releasable by email reply; a workflow requiring release through an authenticated HR system with a second approver would have blocked it.","confidence":"Confirmed","sources":[{"title":"Seagate Phish Exposes All Employee W-2's","url":"https://krebsonsecurity.com/2016/03/seagate-phish-exposes-all-employee-w-2s/","publisher":"Krebs on Security"},{"title":"Snapchat and Seagate fall prey to new W-2 scam","url":"https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/","publisher":"CBS News"}],"entry_type":"incident","slug":"2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2"},{"title":"Snapchat payroll staff phished by fake CEO request for employee W-2s","date":"2016-02-28","date_precision":"day","victim_org":"Snapchat, Inc.","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No wire loss reported; exposure was employee payroll and identity data.","records_affected":null,"threat_actor":null,"summary":"On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.","how_it_worked":"The message was a classic CEO-fraud W-2 lure: a spoofed executive sender, minimal detail, an implied deadline, and a request that fell squarely inside the recipient's normal duties during US tax season. The lever was hierarchical authority combined with the reluctance of a junior payroll employee to question a terse instruction that appears to come from the founder. The extracted action was a single email attachment containing employees' names, addresses, Social Security numbers and wage data, which criminals use to file fraudulent federal tax returns and claim refunds before the real employee files.","lessons":"Enforce a standing rule that no bulk tax or identity data leaves the organisation by email, backed by outbound DLP inspection for W-2 patterns and mandatory verbal verification of executive data requests.","confidence":"Confirmed","sources":[{"title":"Snapchat and Seagate fall prey to new W-2 scam","url":"https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/","publisher":"CBS News"}],"entry_type":"incident","slug":"2016-snapchat-payroll-staff-phished-by-fake-ceo-request-for-employee-w-2s","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-snapchat-payroll-staff-phished-by-fake-ceo-request-for-employee-w-2s"},{"title":"Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise","date":"2015-06-05","date_precision":"day","victim_org":"Ubiquiti Networks","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; impersonation was text-based email spoofing.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":46700000,"loss_note":"Ubiquiti disclosed $46.7 million transferred; $8.1 million was recovered at the time of disclosure and the company said additional sums were subject to legal injunction and expected to be recovered.","records_affected":null,"threat_actor":null,"summary":"In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.","how_it_worked":"Fraudsters used spoofed email addresses and forged requests that appeared to come from senior Ubiquiti executives and from an external business counterparty, instructing the finance team of the company's Hong Kong subsidiary to make a series of international transfers. There was no malware or network compromise; the deception rode entirely on the apparent authority of the sender and on a payments process that accepted email as sufficient authorisation. The fraud was discovered only after the transfers had been made, and Ubiquiti moved to recover funds through legal injunctions in the receiving jurisdictions.","lessons":"Out-of-band verification by known phone number for any payment instruction above a threshold, and dual authorisation for changes to beneficiary details, would have caught the fraudulent requests before the wires left.","confidence":"Confirmed","sources":[{"title":"Tech Firm Ubiquiti Suffers $46M Cyberheist","url":"https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/","publisher":"Krebs on Security"},{"title":"Networking Manufacturer Ubiquiti Lost $46.7M after Falling for Elaborate Impersonation Scam","url":"https://www.nextgov.com/cybersecurity/2015/08/breach/143746/","publisher":"Nextgov/FCW"},{"title":"Ubiquiti Networks says it was victim of $47 million cyber scam","url":"https://www.nbcnews.com/tech/security/ubiquiti-networks-says-it-was-victim-47-million-cyber-scam-n406201","publisher":"NBC News"},{"title":"Ubiquiti Networks Form 8-K, August 2015","url":"https://www.sec.gov/Archives/edgar/data/1511737/000157104915006288/t1501817_8k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email"},{"slug":"2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto","title":"Yahoo network breached via spear-phishing email, 500 million accounts stolen","date":"2014","date_precision":"year","year":2014,"victim_org":"Yahoo! Inc.","sector":"Technology","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":500000000,"threat_actor":"Russian FSB officers Dmitry Dokuchaev and Igor Sushchin with criminal hackers Alexsey Belan and Karim Baratov (per 2017 DOJ indictment)","summary":"In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.","how_it_worked":"The operation opened with a spear-phishing email sent to Yahoo staff in early 2014. The message carried custom content tailored to the recipient so it read as ordinary internal or business correspondence, and required only a single click on a malicious link to succeed. Once a foothold existed, one of the criminal hackers moved laterally to Yahoo's User Database and its Account Management Tool, then minted forged authentication cookies that let the group open targeted mailboxes without any password. The intelligence-service sponsors used that capability to read the mail of journalists, officials and company executives of interest.","lessons":"Phishing-resistant authentication on administrative tooling, plus segmentation so a single employee foothold cannot reach the master user database, would have contained the initial click.","confidence":"Reported","sources":[{"title":"Inside the Russian hack of Yahoo: How they did it","url":"https://www.csoonline.com/article/560623/inside-the-russian-hack-of-yahoo-how-they-did-it.html","publisher":"CSO Online"},{"title":"Four Men Charged With Hacking 500M Yahoo Accounts","url":"https://krebsonsecurity.com/2017/03/four-men-charged-with-hacking-500m-yahoo-accounts/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto"},{"title":"Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million","date":"2013","date_precision":"year","victim_org":"Google LLC and Facebook, Inc.","sector":"Technology","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media was reported; the scheme relied on forged paper documents and lookalike corporate identity.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":120000000,"loss_note":"DOJ states the scheme caused more than $120 million in losses to the two victim companies. Rimasauskas was ordered to forfeit $49,738,559.41 and pay $26,479,079.24 in restitution.","records_affected":null,"threat_actor":"Evaldas Rimasauskas (Lithuanian national) and co-conspirators","summary":"From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.","how_it_worked":"The fraud abused the accounts payable relationship between two technology giants and a legitimate Taiwanese hardware manufacturer. Rimasauskas incorporated a shell company bearing the supplier's name in Latvia, opened bank accounts in its name, and sent phishing and invoice emails from addresses designed to look like the supplier's. He supported the requests with forged invoices, contracts and letters carrying counterfeit corporate stamps and executive signatures, which satisfied the victims' vendor verification paperwork. Because the amounts matched real ongoing supplier business, finance staff processed the wires as routine vendor payments, and the funds were quickly moved across Latvian, Cypriot and other accounts.","lessons":"Bank-detail changes for existing suppliers must be verified by callback to a phone number already on file, and payment files should be reconciled against master vendor records rather than against details supplied in the invoice email.","confidence":"Confirmed","sources":[{"title":"Lithuanian Man Sentenced To 5 Years In Prison For Theft Of Over $120 Million In Fraudulent Business Email Compromise Scheme","url":"https://www.justice.gov/usao-sdny/pr/lithuanian-man-sentenced-5-years-prison-theft-over-120-million-fraudulent-business","publisher":"U.S. Department of Justice, S.D.N.Y."},{"title":"Ringleader of Business Email Compromise Scheme Sentenced","url":"https://www.fbi.gov/news/stories/ringleader-of-business-email-compromise-scheme-sentenced-012820","publisher":"Federal Bureau of Investigation"},{"title":"Lithuanian Man Arrested For Theft Of Over $100 Million In Fraudulent Email Compromise Scheme","url":"https://www.justice.gov/usao-sdny/pr/lithuanian-man-arrested-theft-over-100-million-fraudulent-email-compromise-scheme","publisher":"U.S. Department of Justice"},{"title":"Lithuanian Man Sentenced to Prison Over BEC Scheme Targeting Facebook, Google","url":"https://www.securityweek.com/lithuanian-man-sentenced-prison-over-bec-scheme-targeting-facebook-google/","publisher":"SecurityWeek"},{"title":"How this scammer used phishing emails to steal over $100 million from Google and Facebook","url":"https://www.cnbc.com/2019/03/27/phishing-email-scam-stole-100-million-from-facebook-and-google.html","publisher":"CNBC"},{"title":"Lithuanian scammer gets 5 years for defrauding Google, Facebook of $120 million","url":"https://cyberscoop.com/facebook-google-scam-man-sentenced/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2013-rimasauskas-bec-scheme-defrauds-google-and-facebook-of-over-120-million","year":2013,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2013-rimasauskas-bec-scheme-defrauds-google-and-facebook-of-over-120-million"}]}