{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:39.343Z","total":10,"returned":10,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf","title":"Air France and KLM disclose breach of third-party customer service platform","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Air France-KLM","sector":"Transportation & Logistics","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.","how_it_worked":"Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.","lessons":"Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.","confidence":"Reported","sources":[{"title":"Air France and KLM disclose data breaches impacting customers","url":"https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/","publisher":"BleepingComputer"},{"title":"Air France, KLM Say Hackers Accessed Customer Data","url":"https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"},{"title":"Qantas contact centre platform breached after help desk tricked into adding MFA","date":"2025-07-01","date_precision":"day","victim_org":"Qantas Airways","sector":"Transportation & Logistics","country":"Australia","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.","records_affected":5700000,"threat_actor":"Scattered Spider / Muddled Libra (reported)","summary":"Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.","how_it_worked":"The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.","lessons":"Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.","confidence":"Confirmed","sources":[{"title":"Qantas data breach impacted 5.7 million individuals","url":"https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html","publisher":"Security Affairs"},{"title":"Qantas confirms customer data breach amid Scattered Spider attacks","url":"https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html","publisher":"Security Affairs"},{"title":"Update on Qantas cyber incident: Wednesday 9 July 2025","url":"https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025","publisher":"Qantas Newsroom"},{"title":"Tech support scam caused massive data breach at Australian airline Qantas","url":"https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267","publisher":"The Register"}],"entry_type":"incident","slug":"2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"},{"title":"Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector","date":"2025-06-26","date_precision":"day","victim_org":"Hawaiian Airlines","sector":"Transportation & Logistics","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported in this intrusion.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944 / Muddled Libra)","summary":"Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.","how_it_worked":"Scattered Spider's standard aviation playbook is to impersonate an employee or contractor in a call to the IT help desk and persuade the agent to reset credentials or enrol a new authenticator. The group also registers unauthorised devices against compromised accounts as a way of defeating multi-factor authentication, so that later logins look legitimate. Because airlines run large outsourced service desks covering shift workers and contractors around the clock, a caller claiming to be locked out mid-shift is a routine and hard-to-challenge request.","lessons":"Strict, scripted caller-verification for account recovery and alerting on new device registrations against existing accounts are the controls that surface this pattern early.","confidence":"Reported","sources":[{"title":"Scattered Spider appears to pivot toward aviation sector","url":"https://www.cybersecuritydive.com/news/scattered-spider-appears-to-pivot-toward-aviation-sector/751917/","publisher":"Cybersecurity Dive"}],"entry_type":"incident","slug":"2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector"},{"slug":"2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password","title":"WestJet breach of 1.2 million passengers began with a help desk password reset","date":"2025-06-13","date_precision":"day","year":2025,"victim_org":"WestJet","sector":"Transportation & Logistics","country":"Canada","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1200000,"threat_actor":null,"summary":"Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.","how_it_worked":"The attackers used social engineering to have an employee's password reset, then signed in to the corporate network through Citrix. The pretext was that of a legitimate employee locked out of their account, and the identity impersonated was a staff member whose details had been researched beforehand. The trust signal abused was the help desk's willingness to restore access on the strength of knowledge-based answers, and the pressure applied was a worker unable to do their job. From that foothold the intruders moved into the Windows domain and Microsoft cloud tenant and exfiltrated passenger records over several days before detection.","lessons":"Identity-proofing at the service desk, using video verification or a manager-approved out-of-band challenge before any password or MFA reset, is the single control that would have stopped this.","confidence":"Confirmed","sources":[{"title":"WestJet data breach exposes travel details of 1.2 million customers","url":"https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/","publisher":"BleepingComputer"},{"title":"Data breach at Canadian airline WestJet affects 1.2M passengers","url":"https://techcrunch.com/2025/10/01/data-breach-at-canadian-airline-westjet-affects-1-2m-passengers/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password"},{"title":"Transport for London hit by Scattered Spider teens in a £29m intrusion","date":"2024-09-01","date_precision":"day","victim_org":"Transport for London","sector":"Transportation & Logistics","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Service Disruption","Data Breach","Credential Theft"],"loss_usd":39000000,"loss_note":"TfL put the cost at about £29 million (roughly $39 million); prosecutors said a complete shutdown could have caused up to £56 billion of economic damage.","records_affected":null,"threat_actor":"Scattered Spider; Thalha Jubair and Owen Flowers were each sentenced to five and a half years in July 2026","summary":"Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.","how_it_worked":"TfL has not published the entry vector, and the prosecution described Scattered Spider's general reliance on phone, email and SMS social engineering rather than a specific script for this intrusion. What the response reveals is the assumption TfL made about the attackers' capability: the organisation judged that remote password resets could themselves be abused, and required roughly 27,000 staff to attend in person with identity documents to re-establish credentials. That is the signature countermeasure to help-desk impersonation, adopted precisely because remote identity proofing could no longer be trusted.","lessons":"In-person or strongly verified credential re-issuance for staff, and phishing-resistant MFA for remote administrative access, are the controls TfL was forced to adopt reactively.","confidence":"Reported","sources":[{"title":"Transport for London (TfL) is dealing with an ongoing cyberattack","url":"https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html","publisher":"Security Affairs"},{"title":"Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack","url":"https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion","year":2024,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion"},{"title":"Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks","date":"2024-04-12","date_precision":"day","victim_org":"US drivers and toll customers (multi-victim campaign)","sector":"Transportation & Logistics","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"The IC3 alert does not attribute the campaign to AI tooling.","outcomes":["Identity Theft","Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":null,"loss_note":"IC3 did not publish an aggregate loss figure for the toll smishing campaign.","records_affected":2000,"threat_actor":null,"summary":"On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.","how_it_worked":"Recipients received a text stating that an outstanding toll amount of $12.51 had been noticed on their record and that visiting a link would settle the balance and avoid a $50 late fee. The lever is a small, plausible, low-stakes debt: the sum is too trivial to warrant checking with the tolling authority, and the late fee creates just enough urgency to act immediately. The linked site cloned the state tolling agency's branding and collected card details and personal information for payment fraud and identity theft. Attackers rotated the impersonated agency by recipient area code, so the message named a tolling authority the target plausibly uses.","lessons":"Never transact from a link in an unsolicited text; navigate to the tolling agency independently. Carrier-level detection of newly registered look-alike tolling domains is the scalable control.","confidence":"Confirmed","sources":[{"title":"Smishing Scam Regarding Debt for Road Toll Services","url":"https://www.ic3.gov/PSA/2024/PSA240412","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"campaign","slug":"2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee"},{"title":"Uber breached after MFA push bombing and a WhatsApp message posing as IT","date":"2022-09-15","date_precision":"day","victim_org":"Uber Technologies","sector":"Transportation & Logistics","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Insider Access","Service Disruption"],"loss_usd":null,"loss_note":"No monetary loss disclosed; Uber said no public-facing systems or user accounts were accessed.","records_affected":null,"threat_actor":"Lapsus$ (an 18-year-old member was later convicted in the UK)","summary":"In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.","how_it_worked":"With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.","lessons":"Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.","confidence":"Confirmed","sources":[{"title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack","url":"https://www.darkreading.com/cyberattacks-data-breaches/uber-breach-external-contractor-mfa-bombing-attack","publisher":"Dark Reading"},{"title":"Lessons to learn from the Uber security breach","url":"https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/09/27-september-2022-lessons-to-learn-from-the-uber-security-breach.pdf.coredownload.inline.pdf","publisher":"KPMG"},{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Security Update","url":"https://www.uber.com/newsroom/security-update/","publisher":"Uber"},{"title":"Uber links breach to Lapsus$ group, blames contractor for hack","url":"https://www.bleepingcomputer.com/news/security/uber-links-breach-to-lapsus-group-blames-contractor-for-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it"},{"title":"DoorDash customer data exposed through phished third-party vendor employees","date":"2022-08-25","date_precision":"day","victim_org":"DoorDash","sector":"Transportation & Logistics","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (the campaign that also hit Twilio)","summary":"DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.","how_it_worked":"The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.","lessons":"Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.","confidence":"Confirmed","sources":[{"title":"DoorDash hit by data breach linked to Twilio hackers","url":"https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/","publisher":"TechCrunch"},{"title":"DoorDash discloses new data breach tied to Twilio hackers","url":"https://www.bleepingcomputer.com/news/security/doordash-discloses-new-data-breach-tied-to-twilio-hackers/","publisher":"BleepingComputer"},{"title":"DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others","url":"https://www.securityweek.com/doordash-data-compromised-following-twilio-hack/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ"},{"slug":"2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m","title":"American Airlines discloses breach after phishing compromised employee mailboxes","date":"2022-07","date_precision":"month","year":2022,"victim_org":"American Airlines","sector":"Transportation & Logistics","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1708,"threat_actor":null,"summary":"American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.","how_it_worked":"Attackers phished American Airlines employees and captured their mailbox credentials. The consequences ran in two directions. Inbound, the mailboxes held correspondence containing customer and employee identity documents, passport and driver's licence numbers among them, which is what made a small number of accounts a reportable data breach. Outbound, the attackers used the genuine airline accounts to send more phishing, because a message that actually originates from an American Airlines address passes authentication checks and carries the brand's credibility with recipients. The airline said it had no evidence of misuse but notified affected individuals and offered identity protection.","lessons":"MFA on corporate mail plus data-loss controls that keep identity documents out of mailboxes limit both the exposure and the reuse of the account for onward phishing.","confidence":"Confirmed","sources":[{"title":"American Airlines discloses data breach after employee email compromise","url":"https://www.bleepingcomputer.com/news/security/american-airlines-discloses-data-breach-after-employee-email-compromise/","publisher":"BleepingComputer"},{"title":"American Airlines Says Personal Data Exposed After Email Phishing Attack","url":"https://www.securityweek.com/american-airlines-says-personal-data-exposed-after-email-phishing-attack/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m"},{"title":"Ryanair loses nearly $5 million from fuel account via fraudulent transfer","date":"2015-04","date_precision":"month","victim_org":"Ryanair Holdings plc","sector":"Transportation & Logistics","country":"Ireland","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":5000000,"loss_note":"About €4.6 million (just under $5 million) transferred out of an aircraft fuel account via a Chinese bank; Ryanair said the funds were frozen and it expected repayment.","records_affected":null,"threat_actor":null,"summary":"In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.","how_it_worked":"The fraud targeted a single-purpose corporate account used for high-value, recurring commodity purchases, where large outbound payments are normal and unlikely to stand out. An unauthorized electronic transfer instruction moved nearly €4.6 million out of the fuel account and into the banking system via a Chinese institution, a common laundering corridor for payment-diversion fraud in that period. Ryanair identified the loss quickly enough for Irish authorities and their Asian counterparts to reach the receiving bank and freeze the balance. The airline declined to describe the precise attack vector, citing legal proceedings, and said corrective measures had been put in place.","lessons":"High-value commodity payment accounts need transaction-level anomaly alerting and a dedicated approval path, so that a single unexpected instruction cannot drain them before anyone reviews it.","confidence":"Reported","sources":[{"title":"Ryanair Loses $5m in Bank Hack","url":"https://www.infosecurity-magazine.com/news/ryanair-loses-5-million-in-bank/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer"}]}