{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:15:27.741Z","total":47,"returned":47,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec","title":"Dickinson Public Schools loses $4.92M to vendor-impersonation BEC","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Dickinson Public Schools","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4920000,"loss_kind":"direct_loss","loss_note":"USD; two payments diverted from the district's restricted building fund. No recovery reported at time of disclosure.","records_affected":null,"threat_actor":null,"summary":"Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.","how_it_worked":"The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.","lessons":"Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.","confidence":"Confirmed","sources":[{"title":"North Dakota School District Loses $4.9M to Email Scam","url":"https://www.govtech.com/education/k-12/north-dakota-school-district-loses-4-9m-to-email-scam","publisher":"Government Technology"},{"title":"North Dakota school district loses nearly $5 million in sophisticated email scam","url":"https://www.valleynewslive.com/2026/02/11/north-dakota-school-district-loses-nearly-5-million-sophisticated-email-scam/","publisher":"Valley News Live"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"},{"slug":"2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance","title":"Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Approximately 88,000 victims across 18 African countries and the UK","sector":"Other","country":"Multiple","primary_vector":"Business Email Compromise","secondary_vectors":["Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":485000000,"loss_kind":"aggregate","loss_note":"Interpol put victim losses across the operation at about $485 million, with roughly $97.4 million recovered.","records_affected":null,"threat_actor":null,"summary":"Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.","how_it_worked":"The networks disrupted ran industrialised deception. Business email compromise crews compromised or spoofed corporate mailboxes, watched invoice threads, then sent payment-diversion instructions from an address one character off the real one, timed to arrive when a genuine payment was due. Romance and investment crews cultivated victims over weeks on dating and messaging apps before introducing fake trading platforms that displayed fabricated gains to encourage larger deposits. In both cases the trust signal abused was an established relationship, commercial or personal, and the pressure was a closing window: a supplier deadline, or a limited investment opportunity.","lessons":"Verified callback to a previously known phone number before any change of bank details, and platform-level friction on first-time large transfers to new payees, cut the largest share of these losses.","confidence":"Confirmed","sources":[{"title":"African authorities dismantle massive cybercrime and fraud networks, recover millions","url":"https://www.interpol.int/en/News-and-Events/News/2025/African-authorities-dismantle-massive-cybercrime-and-fraud-networks-recover-millions","publisher":"Interpol"},{"title":"Massive anti-cybercrime operation leads to over 1,200 arrests in Africa","url":"https://www.bleepingcomputer.com/news/security/massive-anti-cybercrime-operation-leads-to-over-1-200-arrests-in-africa/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance"},{"slug":"2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre","title":"Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility","date":"2025-07","date_precision":"month","year":2025,"victim_org":"HPS Investment Partners (BlackRock)","sector":"Financial Services","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_kind":"direct_loss","loss_note":"USD. HPS extended more than $400 million against the disputed receivables, part of roughly $430 million of loans, with BNP Paribas providing leverage on about half. HPS is pursuing recovery through Delaware court action and related bankruptcy proceedings, so the final unrecovered amount has not been published.","records_affected":null,"threat_actor":"Bankim Brahmbhatt and affiliated telecom entities (alleged)","summary":"HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.","how_it_worked":"The borrower supplied invoices purporting to come from large international telecom carriers as collateral for a revolving credit facility, backed by supporting correspondence from email domains crafted to look like those carriers. Credit analysts and underwriters accepted the documents as third-party confirmation of real receivables, and the pattern held for roughly five years because each new drawdown was validated against the same fabricated paper trail. The deception unravelled only when an HPS analyst compared the email domains on the invoices against the real carriers' domains and found mismatches, then found the same discrepancy repeatedly across the portfolio.","lessons":"Out-of-band verification of receivables directly with the named obligor, using contact details sourced independently rather than from the borrower's own documents, would have exposed the fabricated counterparties years earlier.","confidence":"Reported","sources":[{"title":"US Probes Telecom Firms After BlackRock's HPS Uncovers Alleged $400M Fraud","url":"https://www.usnews.com/news/top-news/articles/2025-11-17/us-probes-telecom-firms-after-blackrocks-hps-uncovers-alleged-400m-fraud-financial-times-reports","publisher":"U.S. News / Reuters"},{"title":"How Fake Invoices Duped BlackRock Unit Into a $400 Million Loan (WSJ)","url":"https://www.securitiesdocket.com/2026/02/11/how-fake-invoices-duped-blackrock-unit-into-a-400-million-loan-wsj/","publisher":"Securities Docket / The Wall Street Journal"},{"title":"BlackRock Unit Flags Suspected $400 Million Fraud, Triggering U.S. Probe of Telecom Firms","url":"https://finance.yahoo.com/news/blackrock-unit-flags-suspected-400-150656293.html","publisher":"Yahoo Finance / Bloomberg"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre"},{"title":"Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO","date":"2025-03","date_precision":"month","victim_org":"Unnamed multinational firm, Singapore office","sector":"Other","country":"Singapore","primary_vector":"Deepfake Video Call","secondary_vectors":["Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Singapore Police said deepfake technology was used to render the company's chief financial officer, chief executive and other officials during a Zoom video conference.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":499000,"loss_note":"Over US$499,000 transferred; funds recovered by Singapore and Hong Kong police within days","records_affected":null,"threat_actor":null,"summary":"On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.","how_it_worked":"The approach opened on WhatsApp, a channel where an executive contact request feels informal but not alarming, and offered a business rationale, a confidential regional restructuring, that justified both secrecy and an unusual payment. The video conference supplied the decisive trust signal by putting the target in a room with the two most senior people in his reporting line plus other familiar faces. An outside lawyer and an NDA added procedural theatre that made the transaction look governed rather than improvised, while also formalising the instruction not to tell colleagues. Compliance was easy because the finance director was doing precisely his job, executing a payment approved by the CFO.","lessons":"Payments authorised on a video call should still require callback verification to a directory-listed number and dual approval; the fast bank and police escalation here is what made recovery possible.","confidence":"Confirmed","sources":[{"title":"Singapore firm nearly lost $500,000 after deepfake video scam: police","url":"https://www.hcamag.com/asia/specialisation/hr-technology/singapore-firm-nearly-lost-500000-after-deepfake-video-scam-police/531450","publisher":"Human Resources Director Asia"}],"entry_type":"incident","slug":"2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w"},{"title":"Orion S.A. discloses $60 million loss from fraudulently induced wire transfers","date":"2024-08-10","date_precision":"day","victim_org":"Orion S.A.","sector":"Manufacturing","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The company's SEC filing did not describe the impersonation technique or state whether AI-generated media was involved.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":60000000,"loss_note":"Approximately $60 million one-time pre-tax charge for unrecovered fraudulent transfers, per the company's Form 8-K. Orion said it would pursue recovery including through insurance.","records_affected":null,"threat_actor":null,"summary":"Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.","how_it_worked":"The disclosure describes the standard structure of a corporate payment-diversion fraud: a single employee inside the payments process was deceived into initiating a series of outbound wires rather than one large transfer, which keeps individual amounts within familiar approval bands and spreads them across banking cutoffs. The recipients were accounts controlled by unidentified third parties, consistent with mule networks that disperse funds quickly across jurisdictions. Orion identified the scheme after the transfers had been executed, concluded the loss was unrecoverable enough to book a $60 million charge, and reported that its systems and financial reporting controls were otherwise unaffected, indicating deception of a person rather than a technical compromise.","lessons":"Payment initiation by a single employee is a structural weakness; enforced dual authorization plus out-of-band verification and velocity alerting on new beneficiaries would have interrupted the sequence.","confidence":"Confirmed","sources":[{"title":"Orion S.A. Form 8-K, Item 8.01 (filed August 12, 2024)","url":"https://www.sec.gov/Archives/edgar/data/1609804/000095014224002170/eh240519238_8k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"},{"title":"Scammers dupe chemical company into wiring $60 million","url":"https://www.helpnetsecurity.com/2024/08/13/orion-fraudulent-wire-transfers-60-million/","publisher":"Help Net Security"}],"entry_type":"incident","slug":"2024-orion-s-a-discloses-60-million-loss-from-fraudulently-induced-wire-trans","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-orion-s-a-discloses-60-million-loss-from-fraudulently-induced-wire-trans"},{"title":"LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO","date":"2024-04","date_precision":"month","victim_org":"LastPass","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.","how_it_worked":"The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.","lessons":"A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.","confidence":"Confirmed","sources":[{"title":"Attempted Audio Deepfake Call Targets LastPass Employee","url":"https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee","publisher":"LastPass"},{"title":"LastPass: Hackers targeted employee in failed deepfake CEO call","url":"https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/","publisher":"BleepingComputer"},{"title":"LastPass employee targeted via an audio deepfake call","url":"https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"},{"title":"Arup Hong Kong office loses about $25 million in deepfake video call scam","date":"2024-02","date_precision":"month","victim_org":"Arup Group (Hong Kong office)","sector":"Professional Services","country":"Hong Kong","primary_vector":"Deepfake Video Call","secondary_vectors":["Business Email Compromise","Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":25000000,"loss_note":"HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.","records_affected":null,"threat_actor":null,"summary":"In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.","how_it_worked":"The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.","lessons":"High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.","confidence":"Confirmed","sources":[{"title":"Deepfaked video conference call makes employee send $25 million to scammers","url":"https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/","publisher":"Help Net Security"},{"title":"Arup Group (fraud incident section)","url":"https://en.wikipedia.org/wiki/Arup_Group","publisher":"Wikipedia"},{"title":"Business Email Compromise: Virtual Meeting Platforms","url":"https://www.ic3.gov/PSA/2022/PSA220216","publisher":"FBI IC3"},{"title":"Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee","url":"https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk","publisher":"CNN"},{"title":"'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage","publisher":"South China Morning Post"}],"entry_type":"incident","slug":"2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"},{"title":"FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)","date":"2024","date_precision":"year","victim_org":"Aggregate: U.S. and international BEC victims reporting to FBI IC3","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"The IC3 annual report does not break out AI-enabled BEC as a separate category; separate FBI PSAs have documented deepfake audio and virtual-meeting impersonation used in BEC.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2770151146,"loss_note":"2024 IC3 Annual Report: 21,442 BEC complaints and $2,770,151,146 in adjusted losses. Cumulatively, IC3 recorded 277,918 BEC incidents and roughly $50.9 billion in exposed losses globally from October 2013 through December 2022.","records_affected":null,"threat_actor":null,"summary":"The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.","how_it_worked":"IC3 describes a consistent mechanism across reported cases: criminals compromise or spoof an email account belonging to an executive, employee, vendor or transaction professional, monitor correspondence to identify a pending payment, and then send instructions substituting attacker-controlled bank details. Real estate closings are heavily targeted because buyers, sellers, attorneys, title companies and agents all exchange payment instructions under time pressure. Funds increasingly route to cryptocurrency exchanges and third-party payment processors, with Hong Kong, China, the United Kingdom, Mexico and Singapore among leading destinations. IC3's Recovery Asset Team initiates the Financial Fraud Kill Chain, and most kill-chain requests involve BEC.","lessons":"Reporting a diverted wire to IC3 and the originating bank within 24 to 72 hours is the highest-value response control, and pre-transaction verification of wire instructions is the highest-value prevention control.","confidence":"Confirmed","sources":[{"title":"2024 Internet Crime Report","url":"https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Business Email Compromise: The $50 Billion Scam","url":"https://www.ic3.gov/PSA/2023/PSA230609","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline","year":2024,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline"},{"slug":"2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro","title":"EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts","date":"2023-08","date_precision":"month","year":2023,"victim_org":"More than 100 organisations worldwide (Proofpoint-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.","how_it_worked":"Emails impersonated widely trusted services such as Adobe, DocuSign and Concur, and pushed recipients through redirect chains to an EvilProxy page that relayed the real Microsoft 365 log-in. Victims entered their password and completed their genuine MFA challenge, and the proxy captured the resulting session cookie, so MFA provided no protection. The campaign filtered its own traffic, screening out non-target regions and security-research infrastructure, and deliberately concentrated on executives whose mailboxes carry payment authority and confidential deal information. Successful intrusions were consolidated by enrolling an attacker-controlled MFA method, converting a one-time theft into durable access.","lessons":"Phishing-resistant FIDO2 credentials for high-value roles, and alerting whenever a new MFA method is registered on an executive account, are the controls that matter here.","confidence":"Confirmed","sources":[{"title":"EvilProxy Phishing Used for Cloud Account Takeover Campaign","url":"https://www.proofpoint.com/us/blog/email-and-cloud-threats/cloud-account-takeover-campaign-leveraging-evilproxy-targets-top-level","publisher":"Proofpoint"},{"title":"EvilProxy phishing campaign targets 120,000 Microsoft 365 users","url":"https://www.bleepingcomputer.com/news/security/evilproxy-phishing-campaign-targets-120-000-microsoft-365-users/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro"},{"title":"Nature's Sunshine loses $4.8 million in BEC against Synergy Japan unit","date":"2023-02","date_precision":"month","victim_org":"Nature's Sunshine Products, Inc. (Synergy Japan)","sector":"Consumer","country":"Japan","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The company's filing did not describe the impersonation technique or reference AI.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4800000,"loss_note":"$4.8 million in fraudulently induced wire transfers between February 1 and February 17, 2023. Recovery amount not disclosed.","records_affected":null,"threat_actor":null,"summary":"Nature's Sunshine Products disclosed in a Form 8-K filed February 24, 2023 that a criminal scheme involving employee impersonation and fraudulent requests targeting its Synergy Japan operations produced a series of fraudulently induced wire transfers totaling $4.8 million between February 1 and February 17, 2023. The company discovered the fraud on February 17, 2023, contacted its bank and law enforcement to attempt recovery, and said it had identified no additional fraudulent activity.","how_it_worked":"The attackers focused on a foreign subsidiary, where distance from group finance, language differences and time-zone gaps weaken verification. Impersonating company personnel, they submitted payment requests over a seventeen-day window rather than a single lump sum, letting each transfer pass as an ordinary local disbursement while the cumulative total reached $4.8 million. Because the requests appeared internal and no technical compromise of company systems was reported, they moved through the subsidiary's normal approval path unchallenged. The pattern was recognized only when the cluster of transfers was reviewed together, after which the parent engaged its bank and law enforcement and reviewed controls across its international units.","lessons":"Cumulative velocity monitoring across a subsidiary's outbound payments, not just per-transaction limits, is what surfaces a drip-feed impersonation scheme before it reaches millions.","confidence":"Confirmed","sources":[{"title":"Nature's Sunshine Products, Inc. Form 8-K, Item 8.01 (filed February 24, 2023)","url":"https://www.sec.gov/Archives/edgar/data/275053/000027505323000003/natr-20230217.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2023-nature-s-sunshine-loses-4-8-million-in-bec-against-synergy-japan-unit","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-nature-s-sunshine-loses-4-8-million-in-bec-against-synergy-japan-unit"},{"title":"Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds","date":"2022-11-07","date_precision":"day","victim_org":"Multiple (New York law firm, a Maltese bank, a Qatari businessman, others)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Restitution ordered of $1,732,841. Individual episodes included about $922,857 fraudulently induced from a New York law firm in October 2019 and an intended $14.7 million from a foreign bank cyber-heist; prosecutors said he conspired to launder over $300 million.","records_affected":null,"threat_actor":"Ramon Olorunwa Abbas ('Ray Hushpuppi'), Nigeria/UAE, with co-conspirator Ghaleb Alaumary","summary":"Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.","how_it_worked":"Abbas supplied the financial plumbing that makes BEC profitable. Co-conspirators compromised or spoofed the email of parties to real transactions, such as a law firm holding client funds for a closing, and issued altered wire instructions that matched a payment the victim already expected to make. Abbas provided and coordinated the receiving accounts, including accounts opened with fraudulent identity documents, and moved the proceeds rapidly across jurisdictions to defeat recall. He also ran advance-fee variants, extracting roughly $330,000 from a Qatari businessman seeking a $15 million school loan and then demanding further payments framed as taxes.","lessons":"Payment recipients in escrow and closing transactions should be verified by phone against instructions exchanged before the transaction opened, since the diversion email typically arrives at the exact moment a payment is expected.","confidence":"Confirmed","sources":[{"title":"Nigerian Man Sentenced to Over 11 Years in Federal Prison for Conspiring to Launder Tens of Millions of Dollars from Online Scams","url":"https://www.justice.gov/usao-cdca/pr/nigerian-man-sentenced-over-11-years-federal-prison-conspiring-launder-tens-millions","publisher":"U.S. Department of Justice, C.D. Cal."}],"entry_type":"campaign","slug":"2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce"},{"slug":"2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or","title":"Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations","date":"2022-07-12","date_precision":"day","year":2022,"victim_org":"More than 10,000 organisations targeted (Microsoft-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Business Email Compromise","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.","how_it_worked":"Targets received phishing emails, often disguised as voice message notifications, linking to a proxy server that displayed the genuine Microsoft log-in page. The victim typed their real password and completed their real MFA challenge, both of which were passed straight through to Microsoft, so the experience was indistinguishable from a normal log-in. The proxy captured the resulting session cookie, which the attacker replayed to enter the mailbox without any further authentication. Microsoft observed operators moving to payment fraud within minutes, hunting invoice threads, adding hidden mailbox rules to suppress replies and emailing the victim's suppliers with altered bank details.","lessons":"Standard MFA is not proof against session-token theft; phishing-resistant credentials bound to the origin, plus conditional access on device compliance and token protection, are what break the proxy.","confidence":"Confirmed","sources":[{"title":"From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud","url":"https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/","publisher":"Microsoft Security Blog"},{"title":"Microsoft: 10,000 Organizations Targeted in Large-Scale Phishing Campaign","url":"https://www.securityweek.com/microsoft-10000-organizations-targeted-large-scale-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or"},{"title":"FBI: business email compromise exposed $43 billion in losses across 177 countries","date":"2022-05-04","date_precision":"day","victim_org":"Businesses, government entities and individuals worldwide (multi-victim campaign)","sector":"Financial Services","country":"Global","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"The 2022 advisory does not describe AI-enabled BEC.","outcomes":["Wire Fraud / Financial Loss","Data Breach","Cryptocurrency Theft"],"loss_usd":43312749946,"loss_note":"$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.","records_affected":241206,"threat_actor":null,"summary":"On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.","how_it_worked":"BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.","lessons":"Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.","confidence":"Confirmed","sources":[{"title":"Business Email Compromise: The $43 Billion Scam","url":"https://www.ic3.gov/PSA/2022/PSA220504","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co","year":2022,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"},{"title":"Operation Eagle Sweep: 65 arrests in global BEC disruption","date":"2022-03-30","date_precision":"day","victim_org":"Multiple businesses and individuals (500+ U.S. victims)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Attempt Blocked"],"loss_usd":null,"loss_note":"Not a single-victim loss. The targeted actors were tied to more than 500 U.S. victims and over $51 million in losses; FBI noted nearly $2.4 billion in reported BEC/EAC losses in 2021.","records_affected":null,"threat_actor":"BEC networks arrested in Nigeria, South Africa, Canada and Cambodia, plus U.S.-based money laundering cells","summary":"Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.","how_it_worked":"The disrupted crews used compromised or spoofed business email accounts to insert themselves into payment flows, then requested wires or changed the banking details on invoices, closings and payroll so victims paid criminals instead of counterparties. The same organizations also targeted individuals, especially real estate purchasers and elderly victims, using romance and advance-fee variants that share the same laundering back end. Proceeds were collected in U.S.-based mule accounts, often opened with stolen or synthetic identities, and forwarded to Nigeria and other destinations. Enforcement paired arrests of the fraud operators with prosecutions of the laundering cells to reduce the networks' ability to cash out.","lessons":"Because the same infrastructure serves corporate and consumer variants, banks and businesses benefit most from beneficiary-account verification and rapid kill-chain reporting rather than victim-type-specific controls.","confidence":"Confirmed","sources":[{"title":"Global Operation Disrupts Business Email Compromise Schemes","url":"https://www.fbi.gov/news/stories/coordinated-operation-disrupts-global-bec-schemes-033022","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption"},{"slug":"2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak","title":"Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover","date":"2021-07","date_precision":"month","year":2021,"victim_org":"Town of Peterborough, New Hampshire","sector":"Government","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2300000,"loss_kind":"direct_loss","loss_note":"About US$2.3 million diverted, roughly 15 percent of the town's annual budget; the US Secret Service recovered US$594,331 that had not yet been converted to cryptocurrency.","records_affected":null,"threat_actor":null,"summary":"The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.","how_it_worked":"After taking over a town finance employee's email account, the attackers read the genuine correspondence with two payees, the regional school district and a bridge construction contractor, both of which had asked to be paid by electronic transfer. They then inserted themselves into those live threads with revised banking details, and deleted the payees' incoming emails so that the real counterparties' queries never reached town staff. The town had procedures requiring notarised change forms and confirmatory phone calls, but staff who were supposed to check each other's work did not follow them, which is what let the diverted payments clear.","lessons":"Existing verification procedures only work if they are enforced; mailbox rule creation and mass deletion in a finance account should also raise an automatic alert.","confidence":"Confirmed","sources":[{"title":"Peterborough payment scam: Single compromised email account led to $2.3M theft","url":"https://ledgertranscript.com/2021/10/05/pbscam-ml-100521-42830401/","publisher":"Monadnock Ledger-Transcript"},{"title":"Cyber-thieves Scam New Hampshire Town Out of $2.3m","url":"https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak"},{"title":"Sequoia Capital investor data exposed after employee falls for phishing email","date":"2021-02","date_precision":"month","victim_org":"Sequoia Capital","sector":"Financial Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed; the associated fraudulent transfer attempt was reported as unsuccessful.","records_affected":null,"threat_actor":null,"summary":"Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.","how_it_worked":"An employee at the firm received and acted on a phishing email, handing over credentials that gave the attacker access to their corporate mailbox. The intruder used that mailbox to read stored correspondence containing investor personal and financial details, and attempted to leverage the account for fraudulent payment instructions in the style of a business email compromise, which was not successful. Sequoia notified affected limited partners, engaged outside investigators and law enforcement, and offered credit monitoring. No malware deployment or wider network intrusion was reported.","lessons":"Phishing-resistant MFA on cloud mailboxes plus alerting on anomalous mailbox rules and sign-in locations catches this pattern in hours rather than weeks.","confidence":"Reported","sources":[{"title":"Scoop: Sequoia Capital says it was hacked","url":"https://www.axios.com/2021/02/20/sequoia-capital-says-it-was-hacked","publisher":"Axios"},{"title":"VC Giant Sequoia Capital Informs Investors of Data Breach","url":"https://www.securityweek.com/vc-giant-sequoia-capital-informs-investors-data-breach/","publisher":"SecurityWeek"},{"title":"VC giant Sequoia Capital discloses data breach after failed BEC attack","url":"https://www.bleepingcomputer.com/news/security/vc-giant-sequoia-capital-discloses-data-breach-after-failed-bec-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing"},{"title":"One Treasure Island nonprofit loses $650,000 to hijacked email thread","date":"2021","date_precision":"year","victim_org":"One Treasure Island","sector":"Nonprofit","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":650000,"loss_note":"$650,000 diverted. Funds initially landed at a bank in Odessa, Texas; the nonprofit reported difficulty obtaining law enforcement and bank assistance and no recovery was confirmed in the cited reporting.","records_affected":null,"threat_actor":null,"summary":"One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.","how_it_worked":"The attackers took over the outsourced bookkeeper's mailbox, which sat at the center of the nonprofit's payment approvals, and then replied inside a live thread about a pending grant disbursement rather than starting fresh correspondence. Because the message carried the real address, the real subject line and the real transaction context, the substituted wiring instructions read as an ordinary administrative update. Staff sent the $650,000 grant payment to the criminals' account at a small out-of-state bank, which was then drained onward. The organization discovered the diversion only when the intended recipient reported non-receipt, and small-nonprofit resourcing left it largely on its own to chase the money.","lessons":"Thread hijacking beats sender-address checks, so any change of wire instructions inside an existing thread must trigger a verbal callback to a previously known number before funds move.","confidence":"Reported","sources":[{"title":"Scammed San Francisco Nonprofit Falls Victim to Costliest Type of Cybercrime","url":"https://www.cbsnews.com/sanfrancisco/news/scammed-san-francisco-nonprofit-falls-victim-to-costliest-type-of-cybercrime/","publisher":"CBS News Bay Area / Associated Press"},{"title":"A nonprofit that helps the poor lost $650,000 to scammers","url":"https://www.sfchronicle.com/crime/article/S-F-nonprofit-lost-650-000-to-hackers-and-a-16191669.php","publisher":"San Francisco Chronicle"}],"entry_type":"incident","slug":"2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread","year":2021,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread"},{"title":"Scattered Canary floods Washington's pandemic unemployment system with fake claims","date":"2020-05","date_precision":"month","victim_org":"Washington State Employment Security Department","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Reported as hundreds of millions of dollars; the state had not determined a final figure at the time of reporting, and a substantial portion was later recovered.","records_affected":null,"threat_actor":"Scattered Canary (Nigeria-based fraud ring)","summary":"In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.","how_it_worked":"The ring assembled identity packages from earlier consumer data breaches, giving them the Social Security numbers, dates of birth and addresses of real Washington workers. They registered claims using disposable email services and Gmail address variations so that a single controlled inbox could receive correspondence for many claimants, and they targeted the enhanced $600 weekly federal supplement, which raised the payout per fraudulent claim. Benefit payments were then directed to out-of-state bank accounts held by recruited mules. The pretext succeeded because the agency, overwhelmed by unprecedented claim volume, had relaxed verification to speed payments.","lessons":"Identity proofing and cross-matching against employer wage records must not be suspended under surge conditions; duplicate-contact and out-of-state-payee detection would have surfaced the ring early.","confidence":"Reported","sources":[{"title":"How missed 'red flags' helped Nigerian fraud ring 'Scattered Canary' bilk Washington's unemployment system amid coronavirus chaos","url":"https://www.spokesman.com/stories/2020/may/25/how-missed-red-flags-helped-nigerian-fraud-ring-sc/","publisher":"The Spokesman-Review / The Seattle Times"}],"entry_type":"incident","slug":"2020-scattered-canary-floods-washington-s-pandemic-unemployment-system-with-f","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-scattered-canary-floods-washington-s-pandemic-unemployment-system-with-f"},{"title":"Puerto Rico government agency sends $2.6 million to fraudulent account","date":"2020-01-17","date_precision":"day","victim_org":"Puerto Rico Industrial Development Company (PRIDCO)","sector":"Government","country":"Puerto Rico","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2600000,"loss_note":"$2.6 million transferred on January 17, 2020. Recovery outcome not confirmed in the cited reporting.","records_affected":null,"threat_actor":null,"summary":"Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.","how_it_worked":"The scheme exploited an inter-agency remittance payment process in which large periodic transfers are routine and the receiving party is trusted. The fraudulent email announced a change of banking details for those remittances, a message finance staff had reason to expect from time to time, and gave no cause for alarm because it referenced a genuine payment relationship. Officials updated the destination details and executed the scheduled payment of $2.6 million into the criminals' account. The loss surfaced only when the legitimate recipient's non-receipt was noticed, by which time the funds had left the account, prompting a complaint to police and a wider review of government payment controls.","lessons":"Government payment offices need a standing rule that account-change notices are never actioned from email alone, plus periodic reconciliation with recipients to catch a diversion within days rather than weeks.","confidence":"Confirmed","sources":[{"title":"Official says Puerto Rico government lost $2.6M in phishing scam","url":"https://www.pbs.org/newshour/nation/official-says-puerto-rico-government-lost-2-6m-in-phishing-scam","publisher":"PBS NewsHour / Associated Press"}],"entry_type":"incident","slug":"2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account","year":2020,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account"},{"title":"Cloned company director's voice used in US$35M bank transfer fraud","date":"2020","date_precision":"year","victim_org":"Unnamed company and its bank; investigated by UAE authorities","sector":"Financial Services","country":"United Arab Emirates","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Business Email Compromise","Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"UAE investigators stated in court filings that the fraudsters used 'deep voice' technology to clone a company director's speech for the phone call. The specific tooling was not established publicly.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":35000000,"loss_note":"Up to US$35 million per UAE court documents; US$400,000 traced to two US accounts at Centennial Bank","records_affected":null,"threat_actor":null,"summary":"In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.","how_it_worked":"The pretext was a confidential corporate acquisition that required the branch to release large sums quickly. The channel was a phone call from a person whose voice the manager had heard before, reinforced by a parallel email thread from the same director and from an outside lawyer retained to coordinate the deal, which is a familiar and legitimising pattern in M&A work. Secrecy was built into the story, so the manager had a reason not to ask colleagues. The layered corroboration between a recognised voice and matching documentation removed his doubt, and the transfers were executed before anyone verified through an independent channel.","lessons":"Any acquisition-related payment instruction should require verification through a pre-established channel with a named counterparty, not the contact details supplied inside the request itself.","confidence":"Reported","sources":[{"title":"Fraudsters Cloned Company Director's Voice In $35 Million Bank Heist, Police Find","url":"https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/","publisher":"Forbes"},{"title":"Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme","url":"https://incidentdatabase.ai/cite/147/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud","year":2020,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud"},{"title":"Operation reWired: 281 arrested worldwide in BEC crackdown","date":"2019-09-10","date_precision":"day","victim_org":"Multiple businesses and individuals (global)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Attempt Blocked","Identity Theft"],"loss_usd":null,"loss_note":"Not a single-victim loss. The four-month operation produced 281 arrests, seized about $3.7 million and disrupted roughly $118 million in fraudulent wire transfers. IC3 reported nearly $1.3 billion in BEC/EAC losses for 2018 alone.","records_affected":null,"threat_actor":"Multiple BEC networks, predominantly Nigeria-based, plus actors in Turkey and Ghana","summary":"Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.","how_it_worked":"Operators compromised business and personal email accounts through phishing and credential theft, then monitored correspondence to time an intervention around a real pending payment. When a legitimate invoice, payroll run or closing disbursement was in flight, they injected altered banking instructions that appeared to come from the known counterparty. Victims spanned companies, schools, energy firms, seniors and real estate purchasers. Proceeds were funneled through networks of money mules and fictitious identities before being sent overseas. Thirty-nine FBI field offices and partners in nine countries coordinated arrests, seizures and mule warning letters simultaneously to disrupt both the fraud and its laundering infrastructure.","lessons":"Because criminal proceeds move through domestic mule accounts within hours, rapid reporting to the FBI's IC3 Recovery Asset Team is the single most effective control after a diverted payment is discovered.","confidence":"Confirmed","sources":[{"title":"281 Arrested Worldwide in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes","url":"https://www.justice.gov/archives/opa/pr/281-arrested-worldwide-coordinated-international-enforcement-operation-targeting-hundreds","publisher":"U.S. Department of Justice"},{"title":"Operation reWired","url":"https://www.fbi.gov/news/stories/operation-rewired-bec-takedown-091019","publisher":"Federal Bureau of Investigation"},{"title":"74 Arrested in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes","url":"https://www.justice.gov/archives/opa/pr/74-arrested-coordinated-international-enforcement-operation-targeting-hundreds-individuals","publisher":"U.S. Department of Justice"}],"entry_type":"campaign","slug":"2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown","year":2019,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown"},{"slug":"2019-nikkei-america-employee-wires-29-million-on-fraudulent-management-instru","title":"Nikkei America employee wires $29 million on fraudulent management instructions","date":"2019-09","date_precision":"month","year":2019,"victim_org":"Nikkei Inc. (Nikkei America)","sector":"Media & Entertainment","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":29000000,"loss_kind":"direct_loss","loss_note":"About US$29 million (approximately 3.2 billion yen) transferred to a bank account controlled by the fraudsters; Nikkei said it was pursuing recovery.","records_affected":null,"threat_actor":null,"summary":"Japanese media group Nikkei disclosed in October 2019 that an employee at its US subsidiary, Nikkei America, had transferred about $29 million to a bank account controlled by fraudsters the previous month. The employee acted on instructions from someone impersonating a Nikkei management executive. Nikkei reported the matter to authorities in the United States and Hong Kong and said it was working to recover the funds.","how_it_worked":"Someone posing as a Nikkei management executive instructed an employee in the American subsidiary's finance function to make a large transfer, and the employee did so believing the request was a legitimate internal payment. The structure is the recurring one for cross-border subsidiary fraud: the target sits in an overseas office where head-office instructions arrive by email as a matter of course, where time-zone gaps make immediate verbal confirmation awkward, and where the seniority gradient discourages challenge. No independent check on the beneficiary account was performed before the money left, and the fraud surfaced afterwards during internal review.","lessons":"A hard rule that no single employee can release a transfer of this size without a second approver and a verified callback would have stopped it.","confidence":"Confirmed","sources":[{"title":"Media Giant Nikkei Loses $29 Million to BEC Scammers","url":"https://www.bleepingcomputer.com/news/security/media-giant-nikkei-loses-29-million-to-bec-scammers/","publisher":"BleepingComputer"},{"title":"Japanese media giant Nikkei says $29 million lost in BEC scam","url":"https://cyberscoop.com/nikkei-email-scam-bec-29-million/","publisher":"CyberScoop"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-nikkei-america-employee-wires-29-million-on-fraudulent-management-instru"},{"title":"Toyota Boshoku European unit loses $37 million to payment-instruction BEC","date":"2019-08-14","date_precision":"day","victim_org":"Toyota Boshoku Corporation (European subsidiary)","sector":"Manufacturing","country":"Japan","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":37000000,"loss_note":"Approximately ¥4 billion, reported as about $37 million; the company said it was pursuing recovery of the funds.","records_affected":null,"threat_actor":null,"summary":"Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.","how_it_worked":"Attackers sent messages that impersonated a trading partner or an internal authority and instructed the subsidiary's finance function to redirect a large trade payment to a different bank account. Because the amount and the counterparty were consistent with the subsidiary's normal automotive supply-chain payments, the request did not stand out, and the transfer was executed on the strength of the emailed instruction alone. The loss was discovered after the fact, and Toyota Boshoku disclosed it to the market alongside a downward revision of expected results while pursuing legal recovery.","lessons":"Any instruction that changes payee bank details, even mid-transaction with a known partner, should require independent verification through an established contact and a second approver outside the requesting chain.","confidence":"Confirmed","sources":[{"title":"Over $37 Million Lost by Toyota Boshoku Subsidiary in BEC Scam","url":"https://www.bleepingcomputer.com/news/security/over-37-million-lost-by-toyota-boshoku-subsidiary-in-bec-scam/","publisher":"BleepingComputer"},{"title":"Toyota Parts Supplier Loses $37 Million in Email Scam","url":"https://www.tripwire.com/state-of-security/toyota-parts-supplier-loses-37-million-email-scam","publisher":"Tripwire State of Security"},{"title":"Toyota Boshoku Corporation lost over $37 Million following BEC attack","url":"https://securityaffairs.com/90955/cyber-crime/toyota-boshoku-corporation-bec.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec","year":2019,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec"},{"title":"UK energy firm CEO tricked by AI voice clone of German parent-company boss","date":"2019-03","date_precision":"month","victim_org":"Unnamed UK-based energy company (subsidiary of a German parent)","sector":"Energy & Utilities","country":"United Kingdom","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Business Email Compromise"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Fraud investigators at insurer Euler Hermes attributed the call to commercial voice-synthesis software that reproduced the German executive's accent and speech melody. The AI attribution rests on the insurer's assessment, not on forensic recovery of the tool.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":243000,"loss_note":"EUR 220,000, approx US$243,000","records_affected":null,"threat_actor":null,"summary":"In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.","how_it_worked":"The attacker phoned the UK CEO directly and presented as the group chief executive, a person the target reported to and whose voice he knew. The cloned audio carried the familiar German accent and cadence, which served as the trust signal that displaced any need for written confirmation. The pretext was an urgent payment to a Hungarian supplier that had to clear within the hour, and the caller promised the subsidiary would be reimbursed immediately. After the first transfer succeeded the fraudster called back twice more, once claiming reimbursement had been sent and once asking for a further payment. The CEO only balked when the promised refund failed to appear and a later call arrived from an Austrian number.","lessons":"Out-of-band callback to a known-good number and a dual-authorisation rule for first-time beneficiary payments would have broken the single-channel voice trust the attack depended on.","confidence":"Reported","sources":[{"title":"A Voice Deepfake Was Used To Scam A CEO Out Of $243,000","url":"https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/","publisher":"Forbes"},{"title":"Scammers deepfake CEO's voice to talk underling into $243,000 transfer","url":"https://www.sophos.com/en-us/blog/scammers-deepfake-ceos-voice-to-talk-underling-into-243000-transfer","publisher":"Sophos Naked Security"}],"entry_type":"incident","slug":"2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo","year":2019,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo"},{"title":"Tecnimont India loses $18.6 million to fake CEO conference calls","date":"2018-12","date_precision":"month","victim_org":"Tecnimont SpA (Indian subsidiary, Maire Tecnimont group)","sector":"Professional Services","country":"India","primary_vector":"Business Email Compromise","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"Impersonation on the conference calls was performed by live human actors; no synthetic voice was reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":18600000,"loss_note":"About 1.3 billion rupees, reported as roughly $18.5-18.6 million, sent in three installments to banks in Hong Kong.","records_affected":null,"threat_actor":"Group reported by the company to be operating from China","summary":"The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.","how_it_worked":"This scheme layered voice over email to defeat skepticism. Messages arrived from a domain closely resembling the group CEO's, describing a secret acquisition in China that had to be funded from India because regulatory constraints supposedly blocked transfers from Italy. To answer the obvious objection, the fraudsters convened conference calls in which multiple actors played the CEO, group executives and an external Swiss attorney, giving the transaction the texture of a real deal team. Secrecy was justified as regulatory sensitivity, which kept the India head from calling headquarters. Three tranches were wired to Hong Kong before the parent company discovered the deception.","lessons":"Verification must go through a channel the attacker does not control: a callback to headquarters' known switchboard would have collapsed the entire fake deal team.","confidence":"Reported","sources":[{"title":"Chinese group swindles $18.5 million from Indian arm of Italian company","url":"https://in.marketscreener.com/quote/stock/MAIRE-S-P-A-13369769/news/Maire-Tecnimont-Chinese-group-swindles-18-5-million-from-Indian-arm-of-Italian-company-Economic-27846733/","publisher":"The Economic Times via MarketScreener"},{"title":"BEC Scam Leads to Theft of $18.6 Million","url":"https://www.bankinfosecurity.com/bec-scam-leads-to-theft-186-million-fraud-a-11930","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls"},{"title":"Cabarrus County, NC diverts $2.5 million school payment to BEC actors","date":"2018-11","date_precision":"month","victim_org":"Cabarrus County, North Carolina","sector":"Government","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2504601,"loss_note":"$2,504,601 paid to fraudsters; $776,518.40 recovered, leaving about $1.7 million unrecovered.","records_affected":null,"threat_actor":null,"summary":"Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.","how_it_worked":"The attackers targeted the vendor master-data process rather than a single invoice. Posing as the school construction contractor, they submitted a bank-account change request accompanied by forms and signatures that matched what the county's finance staff expected to see for a legitimate update. Once the fraudulent account details were accepted into the vendor record, the next scheduled construction draw, more than $2.5 million, flowed to the criminals automatically through the county's normal payment run, with no anomaly to catch. The money was then layered through multiple downstream accounts, and only a fraction was traced and clawed back after the county recognized the diversion weeks later.","lessons":"Vendor bank-detail changes should be treated as a privileged change: verified by outbound call to a number from the original contract, confirmed by a second staffer, and followed by a small test payment before the next large draw.","confidence":"Confirmed","sources":[{"title":"Scammers Grab $2.5 Million From North Carolina County in BEC Scam","url":"https://www.securityweek.com/scammers-grab-25-million-north-carolina-county-bec-scam/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors"},{"title":"City of Ottawa treasurer wires about US$98,000 to fake city manager","date":"2018-07","date_precision":"month","victim_org":"City of Ottawa","sector":"Government","country":"Canada","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":98000,"loss_note":"Approximately US$98,000 wired (reported locally as roughly C$128,000). A second request for US$150,000 was blocked. The U.S. Secret Service monitored a receiving account and an individual connected to the scheme was arrested.","records_affected":null,"threat_actor":null,"summary":"In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.","how_it_worked":"The attacker impersonated the city manager, the one person whose instruction the treasurer would be least likely to challenge, and framed the payment as a confidential acquisition requiring a quick wire. The exchange ran over several emails, letting the fraudster answer questions and build rapport in the city manager's voice, which reinforced authenticity. Because the amount was modest by municipal standards and the requester was the treasurer's superior, the transfer cleared normal handling. The scheme unraveled only by coincidence when the treasurer was physically next to the real city manager during a follow-up request, illustrating that the control that caught it was luck rather than process.","lessons":"Executive-initiated wire requests should require verbal confirmation on a known number before release, and municipalities should bar email as an authorization channel for funds transfers entirely.","confidence":"Confirmed","sources":[{"title":"City of Ottawa treasurer fell victim to US$100K phishing scam: auditor general","url":"https://obj.ca/city-of-ottawa-treasurer-fell-victim-to-us100k-phishing-scam-auditor-general/","publisher":"Ottawa Business Journal"}],"entry_type":"incident","slug":"2018-city-of-ottawa-treasurer-wires-about-us-98-000-to-fake-city-manager","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-city-of-ottawa-treasurer-wires-about-us-98-000-to-fake-city-manager"},{"title":"Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud","date":"2018-04","date_precision":"month","victim_org":"Unatrac Holding Limited (Caterpillar export sales affiliate)","sector":"Manufacturing","country":"United Kingdom","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":11000000,"loss_note":"Approximately $11 million in fraudulent transfer requests sent from the compromised CFO account in April 2018; DOJ cited about $11 million in known losses across the wider scheme.","records_affected":null,"threat_actor":"Obinwanne Okeke ('Invictus Obi') and co-conspirators, Nigeria","summary":"Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.","how_it_worked":"The crew sent a credential-phishing email to Unatrac's chief financial officer that harvested his Microsoft Office 365 login. With mailbox access, they read pending payment correspondence, then sent roughly fifteen fraudulent transfer requests and payment approvals over eight days in April 2018 that appeared to come directly from the CFO. Fake invoices and altered supplier banking details supported the requests, and finance staff processed them as ordinary executive-approved payments because they arrived from the genuine internal account. Funds were routed to overseas accounts. The company recognized the fraud only after the CFO's mailbox behavior and the missing payments were reconciled in June 2018.","lessons":"Multifactor authentication on executive mailboxes plus monitoring for anomalous mailbox rules and sign-ins would have blocked the takeover that made every downstream approval look authentic.","confidence":"Confirmed","sources":[{"title":"Nigerian National Sentenced to Prison for $11 Million Global Fraud Scheme","url":"https://www.justice.gov/usao-edva/pr/nigerian-national-sentenced-prison-11-million-global-fraud-scheme","publisher":"U.S. Department of Justice, E.D. Va."}],"entry_type":"incident","slug":"2018-obinwanne-okeke-sentenced-to-10-years-over-11-million-unatrac-bec-fraud","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-obinwanne-okeke-sentenced-to-10-years-over-11-million-unatrac-bec-fraud"},{"title":"Pathé Dutch branch wires €19 million in fake CEO acquisition scam","date":"2018-03","date_precision":"month","victim_org":"Pathé (Netherlands branch)","sector":"Media & Entertainment","country":"Netherlands","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":21500000,"loss_note":"More than €19 million (about $21.5 million) paid in multiple transfers, including from the Pathé group cash pool in France. Recovery not publicly confirmed.","records_affected":null,"threat_actor":null,"summary":"In March 2018 fraudsters impersonating the chief executive of French film company Pathé's parent persuaded the Dutch branch's leadership to make a series of payments totaling more than €19 million for a purported acquisition of a Dubai-based company. Branch director Dertje Meijer and CFO Edwin Slutter were both dismissed after the loss surfaced. An external investigation cleared them of involvement, and Slutter later won partial relief in a wrongful-termination suit.","how_it_worked":"The attackers opened with a low-key question about a KPMG contact to establish a plausible thread, then escalated to a confidential acquisition of a Dubai entity, insisting that all communication run through a spoofed personal address 'as a security measure' for sensitive transactions. When the CFO asked for verification, the fraudsters produced a forged authorization email from the Pathé France manager complete with copied signatures and an invoice from the supposed Dubai target. The CFO checked the signatures, which matched, and payments proceeded from several sources including the group cash pool. Small inconsistencies in the correspondence were noticed but not escalated until headquarters queried the withdrawals.","lessons":"Document-based verification is not verification when the attacker supplies the documents; approval for cross-border deal payments must be confirmed by voice with named group officers on known numbers.","confidence":"Confirmed","sources":[{"title":"BEC scammers stole €19m from film company Pathé","url":"https://www.helpnetsecurity.com/2018/11/14/pathe-bec-scam/","publisher":"Help Net Security"}],"entry_type":"incident","slug":"2018-pathe-dutch-branch-wires-19-million-in-fake-ceo-acquisition-scam","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-pathe-dutch-branch-wires-19-million-in-fake-ceo-acquisition-scam"},{"slug":"2018-cinema-group-pathe-loses-eur-19-2-million-to-ceo-fraud-dutch-executives","title":"Cinema group Pathe loses EUR 19.2 million to CEO fraud; Dutch executives dismissed","date":"2018-03","date_precision":"month","year":2018,"victim_org":"Pathe (Pathe Nederland)","sector":"Media & Entertainment","country":"Netherlands","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":21500000,"loss_kind":"direct_loss","loss_note":"EUR 19.2 million (about US$21.5 million at the time). A Dutch court later upheld the dismissal of the executives involved.","records_affected":null,"threat_actor":null,"summary":"Between March and May 2018 the Dutch arm of the French cinema chain Pathe transferred about EUR 19.2 million in a series of payments to accounts in Dubai, acting on emails purporting to come from Pathe's French head office. The company dismissed the managing director and financial director of Pathe Nederland; a Dutch court ruling later published details of the case and upheld the dismissals.","how_it_worked":"Emails presented as coming from Pathe's headquarters in France told the Dutch leadership that the group was making a confidential acquisition in Dubai and needed funds released quickly, with strict instructions not to discuss it internally because of regulatory sensitivity. The correspondence adopted the tone and structure of genuine group communications and continued over weeks, with follow-up messages managing the executives' doubts as the sums grew. The confidentiality clause was the key mechanism: it explained away every anomaly and stopped the one action, a phone call to Paris, that would have ended the fraud immediately.","lessons":"Any instruction whose own terms forbid verification should be treated as fraudulent by default; secrecy is the tell, not the credential.","confidence":"Confirmed","sources":[{"title":"Details of Pathe Nederland's EUR 19.2M Loss to CEO-fraud Revealed","url":"https://celluloidjunkie.com/2018/11/12/details-of-pathe-nederlands-e19-2m-loss-to-ceo-fraud-revealed/","publisher":"Celluloid Junkie"},{"title":"Dutch Film Boss Sacked After EUR 19m BEC Loss","url":"https://www.infosecurity-magazine.com/news/dutch-film-boss-sacked-after-19m/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-cinema-group-pathe-loses-eur-19-2-million-to-ceo-fraud-dutch-executives"},{"slug":"2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli","title":"UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients","date":"2018-03","date_precision":"month","year":2018,"victim_org":"UnityPoint Health","sector":"Healthcare","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":2800000,"loss_kind":"business_impact","loss_note":"US$2.8 million class-action settlement to resolve litigation over the breach.","records_affected":1400000,"threat_actor":null,"summary":"UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.","how_it_worked":"The phishing emails were crafted to appear to come from an executive inside UnityPoint Health, which gave them the internal legitimacy that gets messages read and links clicked. Staff who followed the links and entered their credentials handed over access to their mailboxes, and the attackers used those accounts for about three weeks. The financial motive shows in what they did next: they hunted for vendor invoices and payroll processes to redirect. The patient data exposure, which included medical, insurance, Social Security and in some cases payment card details, was collateral, simply whatever happened to be sitting in the compromised inboxes.","lessons":"Multi-factor authentication on clinical staff email, and a policy against storing patient identifiers in mailboxes, would have limited both the access and the exposure.","confidence":"Confirmed","sources":[{"title":"1.4 million patient records breached in UnityPoint Health phishing attack","url":"https://www.healthcareitnews.com/news/14-million-patient-records-breached-unitypoint-health-phishing-attack","publisher":"Healthcare IT News"},{"title":"1.4 Million Patients Warned About UnityPoint Health Phishing Attack","url":"https://www.hipaajournal.com/unitypoint-health-phishing-attack-1-4-million-patients/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli"},{"title":"Save the Children Federation loses nearly $1 million in charity BEC fraud","date":"2017-05","date_precision":"month","victim_org":"Save the Children Federation, Inc.","sector":"Nonprofit","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":1000000,"loss_note":"Approximately $1 million diverted; insurance covered most of it, leaving the charity with a net loss of about $112,000.","records_affected":null,"threat_actor":null,"summary":"In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.","how_it_worked":"The attacker first phished credentials and gained control of a legitimate internal mailbox, which removed the usual lookalike-domain tell from the fraud. Operating from inside the organization's own email, they generated invoices and supporting documentation for a plausible program expense, solar equipment for Pakistani health facilities, that matched the charity's real field activities. Approvals then flowed through normal internal channels because every message came from a trusted colleague's real address. Payment was directed to a bank account in Japan, a jurisdiction inconsistent with the stated project, and the funds were gone before the discrepancy was noticed during later reconciliation.","lessons":"Account takeover defeats sender-based trust, so payment approvals for program expenses need out-of-band confirmation plus a geography sanity check between the vendor, the project and the receiving bank.","confidence":"Confirmed","sources":[{"title":"Save the Children Charity Org Scammed for Almost $1 Million","url":"https://www.bleepingcomputer.com/news/security/save-the-children-charity-org-scammed-for-almost-1-million/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2017-save-the-children-federation-loses-nearly-1-million-in-charity-bec-fraud","year":2017,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-save-the-children-federation-loses-nearly-1-million-in-charity-bec-fraud"},{"title":"IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits","date":"2017-02-02","date_precision":"day","victim_org":"US school districts, tribal organizations, nonprofits and employers (multi-victim campaign)","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in the IRS alert.","outcomes":["Data Breach","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The IRS did not publish an aggregate dollar figure; it stated some organisations lost both employee W-2s and thousands of dollars in wire transfers.","records_affected":null,"threat_actor":null,"summary":"In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.","how_it_worked":"Criminals spoofed an organisation's executive and emailed payroll or human resources staff asking for a list of all employees and their Forms W-2. School districts and small nonprofits were attractive because payroll is often handled by one or two people with no formal verification procedure and no security team. After the W-2 file was sent, the same spoofed executive followed up with a request to the payroll or comptroller staff to wire funds to a specified account, exploiting the compliance momentum created by the first successful request. Some organisations lost both the employee data and the money.","lessons":"Small public-sector and nonprofit payroll functions need a written, mandatory callback rule for executive requests, since they lack the compensating controls larger firms rely on.","confidence":"Confirmed","sources":[{"title":"IR-2017-20: Dangerous W-2 Phishing Scam Evolving; Targeting Schools, Restaurants, Hospitals, Tribal Groups and Others","url":"https://www.irs.gov/pub/irs-news/ir-17-020.pdf","publisher":"Internal Revenue Service"}],"entry_type":"campaign","slug":"2017-irs-warns-of-w-2-phishing-epidemic-spreading-to-school-districts-and-non","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-irs-warns-of-w-2-phishing-epidemic-spreading-to-school-districts-and-non"},{"title":"Dublin Zoo defrauded of about €500,000 in invoice redirection scam","date":"2017","date_precision":"year","victim_org":"Dublin Zoo","sector":"Other","country":"Ireland","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Approximately €500,000 was diverted; Gardaí recovered most of the funds, with reporting indicating roughly €130,000 outstanding. No official USD figure was published.","records_affected":null,"threat_actor":null,"summary":"Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.","how_it_worked":"The scheme substituted the destination account on invoices the zoo already expected to pay, so nothing about the amount, the supplier name or the timing looked unusual. Criminals obtained or replicated genuine invoices and presented altered bank details as a routine change of the supplier's account, communicated by email or phone. Finance staff updated the payment details and released the payments in the ordinary run. Gardaí publicly warned after the case that no business should change a supplier's bank account number on the basis of a call or email without verifying the change with a known contact at the supplier, which is precisely the control gap the fraud exploited.","lessons":"Treat supplier bank-detail changes as a security event requiring verification with a known contact using previously held numbers, and reconcile with suppliers promptly so a diversion is caught while funds are still recoverable.","confidence":"Reported","sources":[{"title":"Dublin Zoo lost €500k after falling victim to cyber scam","url":"https://www.irishexaminer.com/ireland/dublin-zoo-lost-500k-after-falling-victim-to-cyber-scam-464818.html","publisher":"Irish Examiner"}],"entry_type":"incident","slug":"2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam"},{"title":"Leoni AG Romanian subsidiary wires €40 million to fraudsters","date":"2016-08","date_precision":"month","victim_org":"Leoni AG (Bistrița, Romania subsidiary)","sector":"Manufacturing","country":"Romania","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":44000000,"loss_note":"About €40 million (roughly $44 million) transferred to an account in the Czech Republic. Recovery not confirmed.","records_affected":null,"threat_actor":null,"summary":"German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.","how_it_worked":"The attackers researched Leoni's internal payment culture before striking, and reporting indicated they knew that German group executives had previously requested transfers by email. They created lookalike sender identities for those executives and directed instructions to the Romanian subsidiary's finance director, who was accustomed to acting on such requests. The messages mimicked the format, tone and approval language of genuine intra-group transfers and were supported by falsified documents. Because the request pattern matched prior legitimate behavior, the finance director executed the wire to a Czech account without a callback to Germany, and the funds were dispersed before the group detected the loss.","lessons":"Intra-group cash movements need a codified verification protocol, ideally a signed treasury workflow rather than email, so that familiarity with past email requests cannot be weaponized.","confidence":"Confirmed","sources":[{"title":"Hackers steal EUR 40 mln from German group Leoni's subsidiary in Romania","url":"https://www.romania-insider.com/hackers-steal-eur-40-mln-german-group-leoni-subsidiary-romania","publisher":"Romania Insider"},{"title":"German wire supplier Leoni loses EUR 40m in email impersonation scam","url":"https://www.bitdefender.com/en-us/blog/businessinsights/leoni-fraud-email-impersonation-scam","publisher":"Bitdefender Business Insights"}],"entry_type":"incident","slug":"2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters"},{"slug":"2016-milwaukee-bucks-employee-sends-players-and-staff-w-2s-to-an-impersonator","title":"Milwaukee Bucks employee sends players' and staff W-2s to an impersonator","date":"2016-04-26","date_precision":"day","year":2016,"victim_org":"Milwaukee Bucks (NBA)","sector":"Media & Entertainment","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"The NBA's Milwaukee Bucks disclosed in May 2016 that an employee had emailed 2015 W-2 tax documents for players and staff to an unknown party in response to a message impersonating the team's president. The documents included names, addresses, Social Security numbers and compensation figures. The team offered three years of credit monitoring to those affected.","how_it_worked":"On 26 April 2016 an email arrived that appeared to be from the Bucks' president requesting the organisation's W-2 forms. A staff member sent them. The pretext was the standard W-2 season request, and the impersonated identity was the single most senior person in the organisation, which suppresses the instinct to verify. A professional sports team is an unusually attractive target for this scheme because the compensation figures in the files are large and publicly interesting, and because players' Social Security numbers carry high resale value. Discovery came only after the request was later questioned internally.","lessons":"A named-executive request for the entire workforce's tax records should trigger a mandatory verification call, and payroll data should be exchanged only through controlled systems.","confidence":"Confirmed","sources":[{"title":"Milwaukee Bucks' tax information released by employee who fell for email scam","url":"https://www.washingtonpost.com/news/early-lead/wp/2016/05/19/milwaukee-bucks-tax-information-released-by-employee-who-fell-for-email-scam/","publisher":"The Washington Post"},{"title":"Bucks leak tax info of players, employees as result of email scam","url":"https://www.espn.com/nba/story/_/id/15615363/milwaukee-bucks-leak-tax-information-players-employees-result-email-scam","publisher":"ESPN"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-milwaukee-bucks-employee-sends-players-and-staff-w-2s-to-an-impersonator"},{"title":"Seagate CEO-impersonation phish exposes every US employee's W-2","date":"2016-03-01","date_precision":"day","victim_org":"Seagate Technology","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No direct wire loss; downstream harm was tax refund fraud exposure for employees.","records_affected":null,"threat_actor":null,"summary":"On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.","how_it_worked":"The attacker spoofed the display name and writing style of a senior executive and emailed payroll or HR staff during tax season with a short, direct request for the complete W-2 file. Two levers combined: the authority of a named chief executive and the seasonal normality of the request, since W-2 handling is exactly what payroll does in early March. The employee attached the full file and replied. Because W-2s pair Social Security numbers with income and address data, the single reply produced everything needed to file fraudulent tax refunds in each employee's name.","lessons":"Bulk employee tax or PII files should never be releasable by email reply; a workflow requiring release through an authenticated HR system with a second approver would have blocked it.","confidence":"Confirmed","sources":[{"title":"Seagate Phish Exposes All Employee W-2's","url":"https://krebsonsecurity.com/2016/03/seagate-phish-exposes-all-employee-w-2s/","publisher":"Krebs on Security"},{"title":"Snapchat and Seagate fall prey to new W-2 scam","url":"https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/","publisher":"CBS News"}],"entry_type":"incident","slug":"2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2"},{"slug":"2016-sprouts-farmers-market-payroll-employee-emails-21-000-staff-w-2s-to-a-sc","title":"Sprouts Farmers Market payroll employee emails 21,000 staff W-2s to a scammer","date":"2016-03","date_precision":"month","year":2016,"victim_org":"Sprouts Farmers Market","sector":"Retail","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":21000,"threat_actor":null,"summary":"In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.","how_it_worked":"The attacker sent a short, plain email to a payroll staff member that appeared to come from a Sprouts executive and asked for all employee W-2 forms. The pretext matched the calendar: late March is the height of US tax season, when internal requests for wage data are entirely routine, so the ask raised no category alarm. The message used seniority as the trust signal and gave no reason for the request, which in a large organisation reads as normal executive brevity rather than suspicious. The employee replied with the file, handing over a complete identity-theft package for the workforce.","lessons":"Bulk employee tax or payroll data should only leave through a ticketed request in an HR system, never as an email attachment, regardless of who appears to be asking.","confidence":"Confirmed","sources":[{"title":"Employers Beware of Phishing Scams","url":"https://www.natlawreview.com/article/employers-beware-phishing-scams","publisher":"The National Law Review"},{"title":"Sprouts Farmers Market Class Actions Target W-2 Phishing Scam","url":"https://topclassactions.com/lawsuit-settlements/lawsuit-news/sprouts-farmers-market-class-actions-target-w-2-phishing-scam/","publisher":"Top Class Actions"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-sprouts-farmers-market-payroll-employee-emails-21-000-staff-w-2s-to-a-sc"},{"title":"Snapchat payroll staff phished by fake CEO request for employee W-2s","date":"2016-02-28","date_precision":"day","victim_org":"Snapchat, Inc.","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No wire loss reported; exposure was employee payroll and identity data.","records_affected":null,"threat_actor":null,"summary":"On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.","how_it_worked":"The message was a classic CEO-fraud W-2 lure: a spoofed executive sender, minimal detail, an implied deadline, and a request that fell squarely inside the recipient's normal duties during US tax season. The lever was hierarchical authority combined with the reluctance of a junior payroll employee to question a terse instruction that appears to come from the founder. The extracted action was a single email attachment containing employees' names, addresses, Social Security numbers and wage data, which criminals use to file fraudulent federal tax returns and claim refunds before the real employee files.","lessons":"Enforce a standing rule that no bulk tax or identity data leaves the organisation by email, backed by outbound DLP inspection for W-2 patterns and mandatory verbal verification of executive data requests.","confidence":"Confirmed","sources":[{"title":"Snapchat and Seagate fall prey to new W-2 scam","url":"https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/","publisher":"CBS News"}],"entry_type":"incident","slug":"2016-snapchat-payroll-staff-phished-by-fake-ceo-request-for-employee-w-2s","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-snapchat-payroll-staff-phished-by-fake-ceo-request-for-employee-w-2s"},{"title":"Austrian aerospace supplier FACC loses about €50 million to CEO fraud","date":"2016-01","date_precision":"month","victim_org":"FACC AG","sector":"Manufacturing","country":"Austria","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the impersonation was email-based, not a voice clone.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":54000000,"loss_note":"FACC reported damage of approximately €50 million (roughly US$54 million at the time); USD figures in press reports range from about $47 million to $56 million depending on exchange rate and date.","records_affected":null,"threat_actor":null,"summary":"FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.","how_it_worked":"Fraudsters sent email instructions that appeared to come from FACC's chief executive, framed around a confidential acquisition and directing finance staff to wire funds to foreign accounts. The framing discouraged the recipients from consulting colleagues, and the payments were released without independent confirmation. Part of the money was frozen in transit; the remainder was dispersed abroad. Austrian police later arrested an alleged accomplice tied to receiving accounts in Hong Kong. No malware or network intrusion was involved, which is why FACC described it as damage from a criminal act rather than a technical breach.","lessons":"A mandatory callback to a directory-listed number for any payment framed as confidential or urgent, plus dual sign-off on international transfers, defeats CEO fraud outright.","confidence":"Confirmed","sources":[{"title":"Austrian Firm Fires CEO After $56-million Cyber Scam","url":"https://www.securityweek.com/austrian-firm-fires-ceo-after-56-million-cyber-scam/","publisher":"SecurityWeek"},{"title":"Aerospace firm loses $47 million in cyber fraud, fires CEO","url":"https://www.bitdefender.com/en-us/blog/businessinsights/cyber-fraud-ceo-fired","publisher":"Bitdefender Business Insights"},{"title":"Cops nab accomplice in Austrian €50m caper","url":"https://www.thelocal.at/20160828/cops-nab-accomplice-in-austrian-50m-caper-facc-hong-kong/","publisher":"The Local Austria"}],"entry_type":"incident","slug":"2016-austrian-aerospace-supplier-facc-loses-about-50-million-to-ceo-fraud","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-austrian-aerospace-supplier-facc-loses-about-50-million-to-ceo-fraud"},{"title":"Belgian bank Crelan loses €70 million to CEO-fraud payment orders","date":"2016-01","date_precision":"month","victim_org":"Crelan NV/SA","sector":"Financial Services","country":"Belgium","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":75800000,"loss_note":"€70 million (about $75.8 million). The bank said reserves absorbed the loss and customers were not affected.","records_affected":null,"threat_actor":null,"summary":"Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.","how_it_worked":"The scheme attacked a bank's own treasury payment process rather than customer accounts. Fraudsters used a compromised or spoofed executive mailbox to issue payment instructions to finance staff, relying on the authority of the sender and on urgency and confidentiality to suppress questions. Because the orders came through the expected internal channel and carried apparently legitimate executive approval, they were processed without out-of-band confirmation. The diversion went undetected until routine internal audit work flagged irregularities, at which point the funds had already left the institution. Crelan reported the matter to prosecutors and reviewed its internal control framework.","lessons":"Internal payment instructions deserve the same scrutiny as external ones: even executive-originated transfers should require verification through a separate channel and a segregation-of-duties check before release.","confidence":"Confirmed","sources":[{"title":"Belgian bank Crelan loses €70 million to BEC scammers","url":"https://www.helpnetsecurity.com/2016/01/26/belgian-bank-crelan-loses-e70-million-to-bec-scammers/","publisher":"Help Net Security"}],"entry_type":"incident","slug":"2016-belgian-bank-crelan-loses-70-million-to-ceo-fraud-payment-orders","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-belgian-bank-crelan-loses-70-million-to-ceo-fraud-payment-orders"},{"title":"Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise","date":"2015-06-05","date_precision":"day","victim_org":"Ubiquiti Networks","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; impersonation was text-based email spoofing.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":46700000,"loss_note":"Ubiquiti disclosed $46.7 million transferred; $8.1 million was recovered at the time of disclosure and the company said additional sums were subject to legal injunction and expected to be recovered.","records_affected":null,"threat_actor":null,"summary":"In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.","how_it_worked":"Fraudsters used spoofed email addresses and forged requests that appeared to come from senior Ubiquiti executives and from an external business counterparty, instructing the finance team of the company's Hong Kong subsidiary to make a series of international transfers. There was no malware or network compromise; the deception rode entirely on the apparent authority of the sender and on a payments process that accepted email as sufficient authorisation. The fraud was discovered only after the transfers had been made, and Ubiquiti moved to recover funds through legal injunctions in the receiving jurisdictions.","lessons":"Out-of-band verification by known phone number for any payment instruction above a threshold, and dual authorisation for changes to beneficiary details, would have caught the fraudulent requests before the wires left.","confidence":"Confirmed","sources":[{"title":"Tech Firm Ubiquiti Suffers $46M Cyberheist","url":"https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/","publisher":"Krebs on Security"},{"title":"Networking Manufacturer Ubiquiti Lost $46.7M after Falling for Elaborate Impersonation Scam","url":"https://www.nextgov.com/cybersecurity/2015/08/breach/143746/","publisher":"Nextgov/FCW"},{"title":"Ubiquiti Networks says it was victim of $47 million cyber scam","url":"https://www.nbcnews.com/tech/security/ubiquiti-networks-says-it-was-victim-47-million-cyber-scam-n406201","publisher":"NBC News"},{"title":"Ubiquiti Networks Form 8-K, August 2015","url":"https://www.sec.gov/Archives/edgar/data/1511737/000157104915006288/t1501817_8k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email"},{"title":"Mattel wires $3 million to Chinese account in CEO impersonation scam, recovers it","date":"2015-04-30","date_precision":"day","victim_org":"Mattel, Inc.","sector":"Consumer","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":3000000,"loss_note":"$3 million transferred and subsequently recovered in full after Chinese authorities froze the receiving account.","records_affected":null,"threat_actor":null,"summary":"On April 30, 2015 a Mattel finance executive wired $3 million to a bank in Wenzhou, China after receiving an email purporting to come from newly appointed chief executive Christopher Sinclair. The fraud was recognized the same day. Because May 1 was a banking holiday in China, Mattel was able to work with U.S. and Chinese law enforcement and the receiving bank to freeze the account, and the funds were returned within days.","how_it_worked":"The attackers studied Mattel's payment approval rule, which required sign-off from two senior managers, and timed their approach to a leadership transition when a new CEO's email habits were unfamiliar. They sent a spoofed request from the incoming chief executive asking for a vendor payment to a new supplier in China, framed as routine business expansion. The finance executive believed the request satisfied the two-approver rule because the CEO himself appeared to be one of the approvers. Only afterward, when she mentioned it to Sinclair, was the fraud exposed. A Chinese public holiday delayed onward movement of the money long enough for law enforcement to freeze it.","lessons":"Approval rules must count only independently verified approvers; a request that supplies its own authorization by email is not dual control, and new-vendor payments deserve a mandatory verification step.","confidence":"Confirmed","sources":[{"title":"Chinese scammers take Mattel to the bank, phishing them for $3 million","url":"https://www.csoonline.com/article/555513/chinese-scammers-take-mattel-to-the-bank-phishing-them-for-3-million.html","publisher":"CSO Online"}],"entry_type":"incident","slug":"2015-mattel-wires-3-million-to-chinese-account-in-ceo-impersonation-scam-reco","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-mattel-wires-3-million-to-chinese-account-in-ceo-impersonation-scam-reco"},{"title":"Ryanair loses nearly $5 million from fuel account via fraudulent transfer","date":"2015-04","date_precision":"month","victim_org":"Ryanair Holdings plc","sector":"Transportation & Logistics","country":"Ireland","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":5000000,"loss_note":"About €4.6 million (just under $5 million) transferred out of an aircraft fuel account via a Chinese bank; Ryanair said the funds were frozen and it expected repayment.","records_affected":null,"threat_actor":null,"summary":"In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.","how_it_worked":"The fraud targeted a single-purpose corporate account used for high-value, recurring commodity purchases, where large outbound payments are normal and unlikely to stand out. An unauthorized electronic transfer instruction moved nearly €4.6 million out of the fuel account and into the banking system via a Chinese institution, a common laundering corridor for payment-diversion fraud in that period. Ryanair identified the loss quickly enough for Irish authorities and their Asian counterparts to reach the receiving bank and freeze the balance. The airline declined to describe the precise attack vector, citing legal proceedings, and said corrective measures had been put in place.","lessons":"High-value commodity payment accounts need transaction-level anomaly alerting and a dedicated approval path, so that a single unexpected instruction cannot drain them before anyone reviews it.","confidence":"Reported","sources":[{"title":"Ryanair Loses $5m in Bank Hack","url":"https://www.infosecurity-magazine.com/news/ryanair-loses-5-million-in-bank/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer"},{"title":"Xoom Corporation loses $30.8 million to employee impersonation fraud","date":"2014-12-30","date_precision":"day","victim_org":"Xoom Corporation","sector":"Financial Services","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":30800000,"loss_note":"$30.8 million of corporate cash transferred to overseas accounts. The company said no customer data or customer funds were involved.","records_affected":null,"threat_actor":null,"summary":"Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.","how_it_worked":"The attackers directed impersonated internal requests at Xoom's finance department, the function authorized to move corporate treasury cash. Posing as company personnel, they issued transfer instructions that fit the company's own internal request format, so the payments were processed as legitimate corporate disbursements rather than customer transactions. The money went to accounts abroad and was not recovered. Xoom emphasized that its systems were not breached and no customer funds or data were touched, underscoring that the failure was in the human approval chain for corporate wires. The board's response included an independent investigation, a review of internal controls, and the immediate departure of the CFO.","lessons":"Corporate treasury disbursement requests should be authenticated in a workflow system with enforced separation of duties, never accepted as an emailed instruction that appears to come from a colleague.","confidence":"Confirmed","sources":[{"title":"Xoom Corporation Form 8-K (filed January 5, 2015)","url":"https://www.sec.gov/Archives/edgar/data/1315657/000110465915000360/a15-1144_18k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud","year":2014,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud"},{"title":"Scoular Company wires $17.2 million after fake CEO and auditor emails","date":"2014-06","date_precision":"month","victim_org":"The Scoular Company","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":17200000,"loss_note":"$17.2 million sent in three transfers of about $780,000, $7 million and $9.4 million to a bank in China.","records_affected":null,"threat_actor":null,"summary":"In June 2014 the corporate controller of Omaha-based commodities trading firm The Scoular Company wired $17.2 million to a Chinese bank in three installments after receiving emails impersonating chief executive Chuck Elsea and the company's outside auditor at KPMG. The messages described a confidential international acquisition and demanded secrecy. The emails were sent from accounts associated with Germany, France and Israel using servers in Moscow.","how_it_worked":"The fraudsters built a two-sided pretext so that the controller's natural verification instinct was satisfied inside the scam itself. Emails from the apparent CEO announced a blockbuster confidential acquisition in China and instructed him to coordinate with a named KPMG contact; emails from that fake auditor then corroborated the deal and supplied wiring details. Secrecy was explicitly demanded because of supposed securities sensitivity, which discouraged any check with colleagues. The story was plausible because Scoular genuinely had expansion discussions involving China. Three escalating transfers cleared over several days before the deception surfaced, by which point the funds were beyond reach.","lessons":"External confirmation must originate from the victim, not the requester: calling KPMG's published main number or the CEO's office, rather than the contact details supplied in the email, would have ended the scheme immediately.","confidence":"Confirmed","sources":[{"title":"55th Largest Private Company In America Sent Millions To China Because An Email Told Them To","url":"https://www.techdirt.com/2015/02/06/55th-largest-private-company-america-sent-millions-to-china-because-email-told-them-to/","publisher":"Techdirt"}],"entry_type":"incident","slug":"2014-scoular-company-wires-17-2-million-after-fake-ceo-and-auditor-emails","year":2014,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-scoular-company-wires-17-2-million-after-fake-ceo-and-auditor-emails"},{"title":"Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million","date":"2013","date_precision":"year","victim_org":"Google LLC and Facebook, Inc.","sector":"Technology","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media was reported; the scheme relied on forged paper documents and lookalike corporate identity.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":120000000,"loss_note":"DOJ states the scheme caused more than $120 million in losses to the two victim companies. Rimasauskas was ordered to forfeit $49,738,559.41 and pay $26,479,079.24 in restitution.","records_affected":null,"threat_actor":"Evaldas Rimasauskas (Lithuanian national) and co-conspirators","summary":"From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.","how_it_worked":"The fraud abused the accounts payable relationship between two technology giants and a legitimate Taiwanese hardware manufacturer. Rimasauskas incorporated a shell company bearing the supplier's name in Latvia, opened bank accounts in its name, and sent phishing and invoice emails from addresses designed to look like the supplier's. He supported the requests with forged invoices, contracts and letters carrying counterfeit corporate stamps and executive signatures, which satisfied the victims' vendor verification paperwork. Because the amounts matched real ongoing supplier business, finance staff processed the wires as routine vendor payments, and the funds were quickly moved across Latvian, Cypriot and other accounts.","lessons":"Bank-detail changes for existing suppliers must be verified by callback to a phone number already on file, and payment files should be reconciled against master vendor records rather than against details supplied in the invoice email.","confidence":"Confirmed","sources":[{"title":"Lithuanian Man Sentenced To 5 Years In Prison For Theft Of Over $120 Million In Fraudulent Business Email Compromise Scheme","url":"https://www.justice.gov/usao-sdny/pr/lithuanian-man-sentenced-5-years-prison-theft-over-120-million-fraudulent-business","publisher":"U.S. Department of Justice, S.D.N.Y."},{"title":"Ringleader of Business Email Compromise Scheme Sentenced","url":"https://www.fbi.gov/news/stories/ringleader-of-business-email-compromise-scheme-sentenced-012820","publisher":"Federal Bureau of Investigation"},{"title":"Lithuanian Man Arrested For Theft Of Over $100 Million In Fraudulent Email Compromise Scheme","url":"https://www.justice.gov/usao-sdny/pr/lithuanian-man-arrested-theft-over-100-million-fraudulent-email-compromise-scheme","publisher":"U.S. Department of Justice"},{"title":"Lithuanian Man Sentenced to Prison Over BEC Scheme Targeting Facebook, Google","url":"https://www.securityweek.com/lithuanian-man-sentenced-prison-over-bec-scheme-targeting-facebook-google/","publisher":"SecurityWeek"},{"title":"How this scammer used phishing emails to steal over $100 million from Google and Facebook","url":"https://www.cnbc.com/2019/03/27/phishing-email-scam-stole-100-million-from-facebook-and-google.html","publisher":"CNBC"},{"title":"Lithuanian scammer gets 5 years for defrauding Google, Facebook of $120 million","url":"https://cyberscoop.com/facebook-google-scam-man-sentenced/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2013-rimasauskas-bec-scheme-defrauds-google-and-facebook-of-over-120-million","year":2013,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2013-rimasauskas-bec-scheme-defrauds-google-and-facebook-of-over-120-million"}]}