{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:42.527Z","total":5,"returned":5,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"FBI warns Silent Ransom Group is callback-phishing US law firms","date":"2025-05","date_precision":"month","victim_org":"US law firms and legal services organisations (campaign)","sector":"Legal","country":"United States","primary_vector":"Callback Phishing (TOAD)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the FBI advisory.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the group extorts victims after data theft without deploying encryption.","records_affected":null,"threat_actor":"Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, UNC3753)","summary":"The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.","how_it_worked":"The primary lure is a telephone-oriented attack delivery email: a message claims a small subscription has been renewed and will be charged unless the recipient calls a number to cancel. There is no link or attachment, so the mail passes gateway filtering. When the victim calls, the operator, posing as support, directs them to a website and has them install a legitimate remote access utility such as Zoho Assist, Syncro, AnyDesk, SuperOps or Atera. The group has also skipped the email entirely and simply telephoned employees claiming to be the firm's own IT department with an after-hours maintenance request. Once connected, the operators escalate where possible, use tools such as WinSCP or Rclone to exfiltrate documents, then extort the firm by threatening publication on a leak site.","lessons":"Application control that blocks unapproved remote access tools is the decisive check here, since the email carries no malicious payload for a gateway to catch; staff also need a verified internal number for IT so an unexpected support call can be refused.","confidence":"Confirmed","sources":[{"title":"FBI warns of Luna Moth extortion attacks targeting law firms","url":"https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/","publisher":"BleepingComputer"},{"title":"Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign","url":"https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html","publisher":"The Hacker News"},{"title":"FBI warns of cybercriminals impersonating IT staff to breach law firms","url":"https://www.floridabar.org/the-florida-bar-news/fbi-warns-of-cybercriminals-impersonating-it-staff-to-breach-law-firms/","publisher":"The Florida Bar"}],"entry_type":"campaign","slug":"2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms"},{"title":"Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta","date":"2024-05-15","date_precision":"day","victim_org":"Multiple organisations (campaign)","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Tech Support Scam","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"Microsoft reported live human callers, not synthetic voice.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published for the campaign.","records_affected":null,"threat_actor":"Storm-1811, deploying Black Basta ransomware","summary":"Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.","how_it_worked":"The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.","lessons":"Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.","confidence":"Confirmed","sources":[{"title":"Threat actors misusing Quick Assist in social engineering attacks leading to ransomware","url":"https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/","publisher":"Microsoft Security Blog"},{"title":"Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing","url":"https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing","publisher":"Sophos"},{"title":"Windows Quick Assist Anchors Black Basta Ransomware Gambit","url":"https://www.darkreading.com/threat-intelligence/windows-quick-assist-anchors-black-basta-ransomware","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"},{"title":"FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings","date":"2023-09-29","date_precision":"day","victim_org":"US senior citizens (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"The advisory does not describe AI-generated voice or content in this campaign.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":542000000,"loss_note":"IC3 received 19,000 tech support scam complaints between January and June 2023 with estimated victim losses over $542 million; nearly half of victims were over 60 and accounted for 66 percent of losses.","records_affected":19000,"threat_actor":null,"summary":"On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.","how_it_worked":"Phase one is a supposed technology company representative reaching the victim by call, text, email or pop-up, who obtains remote access, shows fabricated virus scan results and reviews the victim's financial accounts to find the largest balance, then warns that the institution's fraud department will be in touch. Phase two is a caller posing as that bank or brokerage saying a foreign hacker has accessed the accounts and the money must be moved to a safe government account by wire, cash or cryptocurrency, with instructions to keep it confidential. Phase three is a purported Federal Reserve or government employee, sometimes sending official-looking letterhead, who confirms the story and presses the victim to complete the transfer.","lessons":"The confidentiality instruction is the diagnostic tell; bank staff trained to treat customer secrecy plus urgent large outbound transfers as a scam indicator, and mandatory cooling-off holds, break the chain.","confidence":"Confirmed","sources":[{"title":"'Phantom Hacker' Scams Target Senior Citizens and Result in Victims Losing their Life Savings","url":"https://www.ic3.gov/PSA/2023/PSA230929","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"campaign","slug":"2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings"},{"title":"FTC: business and government impersonation scams hit $1.1 billion in 2023","date":"2023","date_precision":"year","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Callback Phishing (TOAD)"],"ai_involvement":"Unknown","ai_notes":"The 2024 data spotlight does not break out AI-enabled impersonation.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft","Identity Theft"],"loss_usd":1100000000,"loss_note":"$1.1 billion in combined reported losses to business and government impersonation scams in 2023, more than triple the $310 million reported in 2020. Over 330,000 business impersonation reports and nearly 160,000 government impersonation reports, together about 48 percent of fraud reports made directly to the FTC.","records_affected":490000,"threat_actor":null,"summary":"An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.","how_it_worked":"The dominant openers are bogus account security alerts purporting to come from a company such as Amazon or from a bank, claiming unauthorised activity and steering the victim toward transferring funds or feeding cash into a Bitcoin ATM to protect their money. A second pattern is the fake subscription renewal notice, often impersonating Geek Squad, which offers a refund and then coerces the victim into buying gift cards and reading out the numbers. The most damaging innovation is the multi-agency handoff: scammers who begin as a business then transfer the victim to a fake bank representative, FBI agent or even a purported FTC employee, so that each successive persona corroborates the last.","lessons":"No government agency or legitimate business asks anyone to move money to protect it or to pay in gift cards or Bitcoin ATM deposits; retailer and ATM operator interdiction prompts at the point of payment are the strongest late-stage control.","confidence":"Confirmed","sources":[{"title":"Impersonation scams: not what they used to be","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2024/04/impersonation-scams-not-what-they-used-be","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023"},{"title":"Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups","date":"2017-05-12","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Callback Phishing (TOAD)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the era predates generative tooling in this scam type.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The FTC stated consumers paid millions of dollars but published no single campaign total. Individual matters included a $27 million default judgment and $1.3 million in forfeited assets.","records_affected":null,"threat_actor":"Repair All PC LLC, Troth Solutions, Vylah Tec, Universal Network Solutions, Click4Support, BigDog Solutions, First Choice Tech Support and others","summary":"On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.","how_it_worked":"Consumers browsing the web were served pop-up advertisements built to mimic genuine security alerts from Microsoft, Apple and other technology companies, warning that the machine was infected or being hacked and instructing the user to call a toll-free number. Telemarketers answering those calls claimed to represent the impersonated vendor, talked the victim into installing remote access software, and ran theatrical fake diagnostic tests that displayed ordinary system logs as evidence of infection. Having manufactured alarm and demonstrated apparent expertise, they sold hundreds of dollars of unnecessary repairs, software and multi-year service plans.","lessons":"Browser and OS vendors blocking full-screen dialog abuse, plus the simple consumer rule that no legitimate vendor puts a support phone number in a security warning, removes the entry point.","confidence":"Confirmed","sources":[{"title":"FTC and Federal, State and International Partners Announce Major Crackdown on Tech Support Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2017/05/ftc-federal-state-international-partners-announce-major-crackdown-tech-support-scams","publisher":"Federal Trade Commission"}],"entry_type":"campaign","slug":"2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support"}]}