{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:29.567Z","total":7,"returned":7,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi","title":"Charter Communications breach of 4.9M accounts began with an Entra vishing call","date":"2026-04-01","date_precision":"day","year":2026,"victim_org":"Charter Communications (Spectrum)","sector":"Telecom","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4900000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.","how_it_worked":"The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.","lessons":"Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.","confidence":"Confirmed","sources":[{"title":"Charter Communications data breach affects 4.9 million accounts","url":"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/","publisher":"BleepingComputer"},{"title":"Charter confirms Spectrum data breach after ShinyHunters claims hack","url":"https://www.foxnews.com/tech/charter-breach-warning-customers-know","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi"},{"slug":"2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli","title":"Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido (and subsidiary Ben)","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.","how_it_worked":"Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.","lessons":"Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.","confidence":"Reported","sources":[{"title":"Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling","url":"https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling","publisher":"NOS"},{"title":"Major hack of Dutch telco Odido was a classic case of social engineering","url":"https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/","publisher":"Techzine"},{"title":"Odido data breach exposes personal info of 6.2 million customers","url":"https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"},{"slug":"2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo","title":"Odido: IT impersonation calls and MFA approval requests expose 6.2M customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.","how_it_worked":"The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.","lessons":"Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.","confidence":"Confirmed","sources":[{"title":"Odido hackers pretended to be an IT employee to breach corporate system","url":"https://cybernews.com/security/odido-hackers-phishing-attack/","publisher":"Cybernews"},{"title":"Odido Salesforce Hack: Up to 6M Customers' Data at Risk","url":"https://www.salesforceben.com/odido-salesforce-hack-up-to-6m-customers-data-at-risk/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo"},{"title":"Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders","date":"2025-11-20","date_precision":"day","victim_org":"AT&T and T-Mobile customers, including four Manhattan residents","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":435000,"loss_note":"$435,000 stolen from four Manhattan residents, with additional victims identified in other jurisdictions. The indictment covers conduct from October 2021 through July 2022.","records_affected":null,"threat_actor":"Eleven indicted defendants, including AT&T and T-Mobile retail employees Jadakiss Bonilla, Kendrah Vasquez, Amanda Rodado and Jared Moreland","summary":"Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.","how_it_worked":"Ringleaders identified targets and passed their account details to retail store employees on the inside. Rather than talk a rep into a fraudulent swap, the crew paid the reps directly: the store workers used their own authorised access to customer account information to execute the SIM swaps, and in some cases signed in under a coworker's credentials so the audit trail pointed at the wrong person. Once a victim's number was ported to a device the ring controlled, incoming SMS one-time passcodes and password-reset links let them take over bank and payment accounts and move money out through wire transfers and peer-to-peer payment apps before the victim understood why their handset had lost service.","lessons":"Carriers need per-employee SIM-change rate monitoring, mandatory customer confirmation on a second channel, and credential controls that make shared or borrowed logins impossible, since insider swaps look identical to legitimate ones.","confidence":"Alleged","sources":[{"title":"D.A. Bragg Announces Indictment Of SIM-Swapping ID Theft Ring, Including AT&T And T-Mobile Employees","url":"https://manhattanda.org/d-a-bragg-announces-indictment-of-sim-swapping-id-theft-ring-including-att-and-t-mobile-employees/","publisher":"Manhattan District Attorney's Office"}],"entry_type":"campaign","slug":"2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside"},{"slug":"2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so","title":"LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code","date":"2022-03","date_precision":"month","year":2022,"victim_org":"T-Mobile US","sector":"Telecom","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Credential Phishing Portal","Insider Recruitment","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Insider Access","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"LAPSUS$ (DEV-0537)","summary":"Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.","how_it_worked":"LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.","lessons":"Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.","confidence":"Confirmed","sources":[{"title":"Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code","url":"https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/","publisher":"Krebs on Security"},{"title":"T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code","url":"https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html","publisher":"The Hacker News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so"},{"title":"Mobile carrier employee took $500-a-day bribes to perform SIM swaps","date":"2018-10","date_precision":"month","victim_org":"Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Insider Access","Identity Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ did not state aggregate victim losses in the charging announcement. Defiore received approximately $2,325 across twelve bribe payments, at roughly $500 per day of swaps.","records_affected":19,"threat_actor":"Stephen Daniel Defiore and unnamed co-conspirators","summary":"A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.","how_it_worked":"The deceived party here was the carrier itself, not a customer. Rather than talk a retail rep into a fraudulent swap, the conspiracy simply put one on payroll. A co-conspirator messaged Defiore a target's phone number, account PIN and the SIM identifier to swap the line to; Defiore, who worked at the carrier from August 2017 to November 2018, used his legitimate employee access to execute the change and was paid roughly $500 per day. Because the change was made by an authorized account with a valid business reason on its face, none of the carrier's customer-facing verification controls applied. The hijacked numbers then received the victims' SMS authentication codes.","lessons":"SIM-change transactions need behavioral monitoring on the employee side, including per-rep swap-rate baselining and out-of-band customer confirmation, since insider abuse looks identical to authorized work in the logs.","confidence":"Confirmed","sources":[{"title":"Former Phone Company Employee Charged for Role in SIM Swap Scam That Targeted at Least 19 Customers","url":"https://www.justice.gov/usao-edla/pr/former-phone-company-employee-charged-rolein-sim-swap-scam-targeted-least-19-customers","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps","year":2018,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps"},{"title":"Kevin Mitnick's telecom pretexting campaign and 1995 arrest","date":"1995-02-15","date_precision":"day","victim_org":"Pacific Bell, Digital Equipment Corporation and other telecommunications and computer firms","sector":"Telecom","country":"United States","primary_vector":"Physical Pretexting","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the era predates generative tooling.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"Loss estimates in the case were heavily disputed at the time and are not stated here.","records_affected":null,"threat_actor":"Kevin Mitnick","summary":"Kevin Mitnick was arrested by the FBI in Raleigh, North Carolina on 15 February 1995 and found with cloned cellular phones, more than 100 cloned cellular phone codes and multiple pieces of false identification. In 1999 he pleaded guilty to four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting wire communications, and admitted copying proprietary software from large cellular telephone and computer companies. He was sentenced to 46 months plus 22 months for violating supervised release. His case is the formative reference point for social engineering as a discipline.","how_it_worked":"Mitnick's intrusions leaned far more on telephone pretexting than on exploits. He would call employees while posing as a colleague from another department, a vendor engineer or an internal support technician, using accurate internal jargon, employee names and project references gathered from earlier calls and from discarded documents. Each call extracted a small, individually harmless item, a dial-in number, a system name, a temporary password reset, and those items compounded into working access. The lever was deference to apparent internal authority and the desire to be helpful to a co-worker under time pressure.","lessons":"Identity verification for any internal request must be independent of the caller's own claims, and password resets should require an out-of-band confirmation the caller cannot supply by talking.","confidence":"Reported","sources":[{"title":"Kevin Mitnick","url":"https://en.wikipedia.org/wiki/Kevin_Mitnick","publisher":"Wikipedia"}],"entry_type":"incident","slug":"1995-kevin-mitnick-s-telecom-pretexting-campaign-and-1995-arrest","year":1995,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/1995-kevin-mitnick-s-telecom-pretexting-campaign-and-1995-arrest"}]}