{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:34:18.658Z","total":98,"returned":50,"limit":50,"offset":0,"next":"https://global-social-engineering-impact-da.vercel.app/api/incidents?vector=Credential+Phishing+Portal&offset=50&limit=50","note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ReliaQuest blocks ShinyHunters vishing attack with device-trust controls","date":"2026-08-24","date_precision":"day","victim_org":"ReliaQuest","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"ReliaQuest did not state whether synthetic voice was used on the calls.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; no customer data was accessed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.","how_it_worked":"The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.","lessons":"Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.","confidence":"Confirmed","sources":[{"title":"ReliaQuest confirms failed data-theft attack after ShinyHunters breach","url":"https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"},{"slug":"2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ","title":"Levi Strauss files 8-K after social engineering compromises three employee computers","date":"2026-08-07","date_precision":"day","year":2026,"victim_org":"Levi Strauss & Co.","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.","how_it_worked":"Levi Strauss disclosed only that the vector was social engineering against employees, without naming the technique. The linkage Reuters drew to a crew running a five-week, 200-company spree matches the voice-phishing-plus-lookalike-portal pattern dominant through 2026, in which callers impersonating IT support harvest credentials and session tokens from individual staff. Access reached three endpoints and corporate data was taken before the company contained it. Levi Strauss activated incident response and engaged third-party specialists; consumer systems were reported unaffected.","lessons":"Phishing-resistant MFA plus rapid session revocation limits a three-endpoint compromise to exactly that; the 8-K filing over three laptops shows how cheaply this vector reaches material-disclosure territory.","confidence":"Confirmed","sources":[{"title":"Levi Strauss discloses data breach after social engineering attack on employees","url":"https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/","publisher":"CyberInsider"},{"title":"Levi Strauss describes contained cyber incident, LEVI 8-K filing","url":"https://www.stocktitan.net/sec-filings/LEVI/8-k-levi-strauss-co-reports-material-event-0f6321560e78.html","publisher":"StockTitan (SEC filing)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ"},{"title":"Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks","date":"2026-08-06","date_precision":"day","victim_org":"Point72, Millennium Management, Two Sigma, Citadel and private-equity firms","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.","outcomes":["Attempt Blocked","Extortion","Credential Theft"],"loss_usd":10600000,"loss_note":"Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.","records_affected":null,"threat_actor":"UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon","summary":"BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.","how_it_worked":"Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.","lessons":"Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.","confidence":"Confirmed","sources":[{"title":"Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group","url":"https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at","year":2026,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"},{"slug":"2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee","title":"Brinks Home breached after Microsoft Entra vishing call to an employee","date":"2026-07-13","date_precision":"day","year":2026,"victim_org":"Brinks Home","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.","how_it_worked":"The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.","lessons":"Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.","confidence":"Confirmed","sources":[{"title":"ShinyHunters claims Brinks Home breach, threatens to leak stolen data","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/","publisher":"BleepingComputer"},{"title":"Salesforce Hacks 2026: Everything We Know So Far","url":"https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"},{"slug":"2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai","title":"RingCentral data on 1.6M accounts leaked after social engineering campaign","date":"2026-07","date_precision":"month","year":2026,"victim_org":"RingCentral","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1600000,"threat_actor":"ShinyHunters","summary":"Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.","how_it_worked":"RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.","lessons":"Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.","confidence":"Confirmed","sources":[{"title":"RingCentral data breach exposed info of 1.6 million accounts","url":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","publisher":"BleepingComputer"},{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","url":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai"},{"slug":"2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365","title":"Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Corporate Microsoft 365 users across a dozen countries","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Actors tracked as codemado, mail-argenta and saroula01","summary":"French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.","how_it_worked":"Two of the three crews ran reverse-proxy phishing: the victim received a link to a page that forwarded every keystroke to the real Microsoft login and returned the genuine responses, so the sign-in looked and behaved correctly while the operator captured the password and the resulting session cookie. The mail-argenta fork pre-filled the victim's email address and rewrote URLs to evade detection. The quietest and most successful operator instead abused Microsoft's legitimate device code flow, persuading targets to enter a short code on the real Microsoft site, which authorises the attacker's device without any fake page at all and defeats MFA including passkeys.","lessons":"Device code flow should be disabled by conditional access policy where it is not needed, and long-lived session cookies should be cut short and rebound to device compliance.","confidence":"Confirmed","sources":[{"title":"Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365","url":"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365"},{"slug":"2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe","title":"Abbott investigates ShinyHunters claim after mid-June vishing on employees","date":"2026-06","date_precision":"month","year":2026,"victim_org":"Abbott Laboratories (legacy Exact Sciences systems)","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.","how_it_worked":"Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.","lessons":"Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.","confidence":"Reported","sources":[{"title":"Abbott Investigating Cyberattack Claims From Two Threat Actors","url":"https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/","publisher":"HIPAA Journal"},{"title":"Abbott investigates after ShinyHunters claims massive data theft","url":"https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"},{"slug":"2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft","title":"Cushman & Wakefield confirms vishing-triggered Salesforce data theft","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Cushman & Wakefield","sector":"Professional Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters; Qilin also claimed the victim","summary":"Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.","how_it_worked":"The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.","lessons":"Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.","confidence":"Confirmed","sources":[{"title":"Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim","url":"https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/","publisher":"Cybernews"},{"title":"Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped","url":"https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/","publisher":"Breached.Company"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"},{"slug":"2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat","title":"UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services","sector":"Other","country":"Global","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":10600000,"loss_kind":"criminal_proceeds","loss_note":"USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.","records_affected":null,"threat_actor":"UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)","summary":"Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.","how_it_worked":"Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.","lessons":"Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.","confidence":"Confirmed","sources":[{"title":"Vishing Extortion Group UNC6671 Rebrands After Making Millions","url":"https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/","publisher":"SecurityWeek"},{"title":"UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data","url":"https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"},{"title":"ADT confirms breach after vishing attack on employee's Okta SSO account","date":"2026-04-20","date_precision":"day","victim_org":"ADT","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using AI voice agents in its vishing operations; AI use in the ADT call was not separately confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"ShinyHunters set an April 27, 2026 ransom deadline; no payment or loss figure was disclosed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.","how_it_worked":"An operator called an ADT employee posing as internal support and used a plausible authentication pretext to route them to a company-branded fake sign-in page. The page relayed the credentials and one-time code to the real Okta login in real time, giving the attacker a live SSO session. Because Salesforce sat behind that same single sign-on, the session opened the CRM directly, and the attackers exported customer and prospect records in bulk before ADT terminated the intrusion. Extortion followed, with a leak deadline set three days after public confirmation.","lessons":"Phishing-resistant passkeys bound to managed devices, plus export-volume alerting on the CRM, would have blocked both the credential relay and the bulk extraction.","confidence":"Confirmed","sources":[{"title":"ADT confirms data breach after ShinyHunters leak threat","url":"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/","publisher":"BleepingComputer"},{"title":"ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack","url":"https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack","publisher":"Rescana"}],"entry_type":"incident","slug":"2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account"},{"slug":"2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi","title":"Carnival confirms social engineering of an employee account exposed 6 million customers","date":"2026-04-14","date_precision":"day","year":2026,"victim_org":"Carnival Corporation","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5995277,"threat_actor":"ShinyHunters","summary":"Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.","how_it_worked":"Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.","lessons":"Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.","confidence":"Reported","sources":[{"title":"Carnival Cruise confirms data breach affecting nearly 6 million people","url":"https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/","publisher":"BleepingComputer"},{"title":"Carnival Data Breach Exposed 6 Million People","url":"https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/","publisher":"SecurityWeek"},{"title":"Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach","url":"https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach","publisher":"Office of the Texas Attorney General"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"},{"slug":"2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi","title":"Charter Communications breach of 4.9M accounts began with an Entra vishing call","date":"2026-04-01","date_precision":"day","year":2026,"victim_org":"Charter Communications (Spectrum)","sector":"Telecom","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4900000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.","how_it_worked":"The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.","lessons":"Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.","confidence":"Confirmed","sources":[{"title":"Charter Communications data breach affects 4.9 million accounts","url":"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/","publisher":"BleepingComputer"},{"title":"Charter confirms Spectrum data breach after ShinyHunters claims hack","url":"https://www.foxnews.com/tech/charter-breach-warning-customers-know","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi"},{"slug":"2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account","title":"Crunchyroll support tickets stolen via compromised BPO agent SSO account","date":"2026-03-12","date_precision":"day","year":2026,"victim_org":"Crunchyroll","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.","how_it_worked":"The weak point was not Crunchyroll's own workforce but a third-party contact centre agent with standing access to the streaming service's ticketing system. The attacker said malware on the agent's machine captured their credentials, then used the resulting Okta session to authenticate into Zendesk as a legitimate support operator. Because helpdesk agents routinely open and read large numbers of tickets, bulk retrieval did not stand out immediately, and roughly 24 hours passed before access was cut. Some payment card details were exposed only where customers had typed them into tickets.","lessons":"Outsourced agent identities need the same phishing-resistant MFA and device-health enforcement as employees, plus per-agent ticket access rate limits so no single account can enumerate the whole queue.","confidence":"Reported","sources":[{"title":"Crunchyroll probes breach after hacker claims to steal 6.8M users' data","url":"https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/amp/","publisher":"BleepingComputer"},{"title":"1.2 million Crunchyroll users confirmed impacted by data breach","url":"https://cyberinsider.com/1-2-million-crunchyroll-users-confirmed-impacted-by-data-breach/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"},{"slug":"2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a","title":"Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Organisations across education, healthcare, finance, nonprofit and government","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","QR Code Phishing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Tycoon2FA phishing-as-a-service operators","summary":"Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.","how_it_worked":"Tycoon2FA industrialised adversary-in-the-middle credential theft for buyers with no technical skill. A subscriber picked a template and sent lures; when a recipient entered their password on the fake sign-in page, the platform relayed it live to the real Microsoft or Google service and captured the returned session cookie along with whatever MFA the user completed. That defeated SMS codes, one-time passcodes and push approvals alike, because the victim genuinely authenticated, just into the attacker's session. Domains were rotated every 24 to 72 hours on cheap generic TLDs using readable subdomains such as cloud, desktop and sharepoint.","lessons":"Only origin-bound credentials such as FIDO2 passkeys break the relay; conditional access requiring a compliant managed device makes a stolen cookie useless from attacker infrastructure.","confidence":"Confirmed","sources":[{"title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale","url":"https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/","publisher":"Microsoft Security Blog"},{"title":"Europol, Microsoft, TrendAI and Collaborators Halt Tycoon 2FA Operations","url":"https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html","publisher":"Trend Micro"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a"},{"slug":"2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo","title":"Figure Technology loses ~967,000 customer records after employee falls for SSO vishing","date":"2026-02-19","date_precision":"day","year":2026,"victim_org":"Figure Technology Solutions","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":967000,"threat_actor":"ShinyHunters","summary":"Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.","how_it_worked":"The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.","lessons":"Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.","confidence":"Reported","sources":[{"title":"Nearly 1 Million User Records Compromised in Figure Data Breach","url":"https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/","publisher":"SecurityWeek"},{"title":"Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters","url":"https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/","publisher":"Cybernews"},{"title":"Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People","url":"https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"},{"slug":"2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod","title":"CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes","date":"2026-02-13","date_precision":"day","year":2026,"victim_org":"CarGurus","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.","how_it_worked":"Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.","lessons":"One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.","confidence":"Reported","sources":[{"title":"CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach","url":"https://news.dealershipguy.com/p/cargurus-probes-cyberattack-shinyhunters-theft-1-7-million-records-data-breach-2026-02-23","publisher":"Dealership Guy News"},{"title":"CarGurus Reported Data Breach","url":"https://complyauto.com/cargurus-reported-data-breach/","publisher":"ComplyAuto"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod"},{"title":"Optimizely confirms data breach after vishing attack on employees","date":"2026-02-11","date_precision":"day","victim_org":"Optimizely","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"Optimizely did not state whether synthetic voice was used on the calls.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed; the company said there was no disruption to business operations.","records_affected":null,"threat_actor":"Likely ShinyHunters-affiliated","summary":"Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.","how_it_worked":"Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.","lessons":"Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.","confidence":"Confirmed","sources":[{"title":"Ad tech firm Optimizely confirms data breach after vishing attack","url":"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees"},{"slug":"2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts","title":"Hims & Hers support tickets stolen through compromised Okta SSO accounts","date":"2026-02-04","date_precision":"day","year":2026,"victim_org":"Hims & Hers Health","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.","how_it_worked":"Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.","lessons":"Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.","confidence":"Confirmed","sources":[{"title":"Hims & Hers warns of data breach after Zendesk support ticket breach","url":"https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/","publisher":"BleepingComputer"},{"title":"Telehealth Giant Hims & Hers Announces Data Breach","url":"https://www.hipaajournal.com/him-hers-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts"},{"title":"BlackFile extortion gang runs vishing campaign against retail and hospitality","date":"2026-02","date_precision":"month","victim_org":"Multiple retail and hospitality organisations (unnamed)","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.","records_affected":null,"threat_actor":"BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)","summary":"BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.","how_it_worked":"Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.","lessons":"Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.","confidence":"Confirmed","sources":[{"title":"New BlackFile extortion gang targets retail and hospitality orgs","url":"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"},{"slug":"2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill","title":"Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records","date":"2026-01-29","date_precision":"day","year":2026,"victim_org":"Match Group (Match, Hinge, OkCupid)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":10000000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.","how_it_worked":"The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.","lessons":"Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.","confidence":"Reported","sources":[{"title":"Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match","url":"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/","publisher":"BleepingComputer"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill"},{"slug":"2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages","title":"Starbucks employee data stolen via cloned Partner Central login pages","date":"2026-01-19","date_precision":"day","year":2026,"victim_org":"Starbucks","sector":"Hospitality","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":900,"threat_actor":null,"summary":"Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.","how_it_worked":"Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.","lessons":"Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.","confidence":"Confirmed","sources":[{"title":"Starbucks Data Breach Impacts Employees","url":"https://www.securityweek.com/starbucks-data-breach-impacts-employees/","publisher":"SecurityWeek"},{"title":"Starbucks suffers data breach via employee portal clone sites","url":"https://cyberinsider.com/starbucks-suffers-data-breach-via-employee-portal-clone-sites/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"},{"title":"Betterment named among victims of the January 2026 real-time vishing wave","date":"2026-01-09","date_precision":"day","victim_org":"Betterment","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"No synthetic voice was reported for this campaign; the calls were described as live operators.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.","how_it_worked":"The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.","lessons":"Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav"},{"slug":"2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov","title":"FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government","date":"2026-01-08","date_precision":"day","year":2026,"victim_org":"Think tanks, academic institutions and government entities","sector":"Government","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Spear Phishing (Email)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Kimsuky (APT43)","summary":"The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.","how_it_worked":"Kimsuky wrote emails in the voice of a diplomat or embassy employee inviting a policy expert to an event or a document review, and placed the link inside a QR code rather than as clickable text. Scanning moved the victim off the monitored corporate desktop onto a personal phone, where enterprise mail filtering and endpoint detection do not reach, and onto a spoofed Google or document-portal sign-in. The FBI noted these operations frequently end in session token theft and replay, which defeats multi-factor authentication because the attacker never faces the login challenge.","lessons":"Treat QR codes in inbound mail as untrusted links and render them for inspection at the gateway; bind sessions to device posture so a stolen token cannot be replayed from unmanaged hardware.","confidence":"Confirmed","sources":[{"title":"FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing","url":"https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html","publisher":"The Hacker News"},{"title":"FBI FLASH AC-000001-MW, 08 January 2026","url":"https://www.ic3.gov/CSA/2026/260108.pdf","publisher":"FBI / IC3"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov"},{"title":"SoundCloud hit as real-time vishing kits drive browsers through SSO logins","date":"2026-01","date_precision":"month","victim_org":"SoundCloud","sector":"Media & Entertainment","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":36000000,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.","how_it_worked":"The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.","lessons":"Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"},{"title":"Okta SSO accounts targeted in vishing campaign against financial firms","date":"2026-01","date_precision":"month","victim_org":"Multiple fintech, wealth management and advisory firms (unnamed)","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_note":"Ransom demands were made by email; no aggregate figure was published for this wave.","records_affected":null,"threat_actor":"ShinyHunters (signed some extortion demands)","summary":"BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.","how_it_worked":"Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.","lessons":"Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.","confidence":"Confirmed","sources":[{"title":"Okta SSO accounts targeted in vishing-based data theft attacks","url":"https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"},{"slug":"2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec","title":"Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Crunchbase","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":2000000,"threat_actor":"ShinyHunters","summary":"Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.","how_it_worked":"The attackers called Crunchbase staff and posed as internal IT support, using a pretext about an account or access issue that required the employee to sign in while the caller stayed on the line. The employee entered Okta single sign-on credentials and read back the one-time code, which the caller replayed against the live Okta login within its validity window, producing an authenticated session under a legitimate staff identity. The trust signals abused were the routine familiarity of an IT support call and the employee's own genuine Okta prompt; the pressure was urgency framed as fixing a problem already affecting the employee's access.","lessons":"Phishing-resistant, origin-bound authenticators remove the readable one-time code these calls depend on, and a standing rule that IT never requests codes by phone gives staff a clean refusal script.","confidence":"Reported","sources":[{"title":"Crunchbase Confirms Data Breach After Hacking Claims","url":"https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/","publisher":"SecurityWeek"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"},{"title":"ShinyHunters claims 2 Million Crunchbase records; company confirms breach","url":"https://securityaffairs.com/187340/data-breach/shinyhunters-claims-2-million-crunchbase-records-company-confirms-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing","title":"ShinyHunters claim 14M Panera Bread records after Entra SSO vishing","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Panera Bread","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.","how_it_worked":"The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.","lessons":"Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.","confidence":"Alleged","sources":[{"title":"ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach","url":"https://www.techrepublic.com/article/news-panera-bread-data-breach/","publisher":"TechRepublic"},{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing"},{"slug":"2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text","title":"Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Consumers and card issuers worldwide (Google plaintiff)","sector":"Consumer","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"Court filings and researchers cited estimates of many millions of compromised cards; no single verified loss figure was published.","records_affected":null,"threat_actor":"Smishing Triad / 'Lighthouse' phishing-as-a-service","summary":"In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.","how_it_worked":"Victims received a text claiming an unpaid road toll, a stuck parcel or a suspended account, with a short deadline and a link to a convincing replica of the relevant agency or brand. Toll authorities and postal services were chosen because almost everyone plausibly has an outstanding interaction with one, and because the sums demanded were small enough not to warrant scrutiny. The site collected card details and then, critically, the one-time passcode sent by the bank, which let the operators load the stolen card into a mobile wallet on their own phone. The kit also spoofed sender identities and rotated domains to evade filtering.","lessons":"Banks should refuse to provision cards into wallets on the strength of an SMS passcode alone, and consumers should reach toll and postal accounts only through an app or a typed-in official domain.","confidence":"Confirmed","sources":[{"title":"Google Sues to Disrupt Chinese SMS Phishing Triad","url":"https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/","publisher":"Krebs on Security"},{"title":"Google sues to dismantle Chinese phishing platform behind US toll scams","url":"https://www.bleepingcomputer.com/news/security/google-sues-to-dismantle-chinese-phishing-platform-behind-us-toll-scams/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text"},{"slug":"2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering","title":"University of Pennsylvania donor systems breached via social engineering","date":"2025-10-31","date_precision":"day","year":2025,"victim_org":"University of Pennsylvania","sector":"Education","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.","how_it_worked":"Penn said the intrusion began with social engineering that tricked an individual into giving up login credentials, and reporting noted that some senior staff held exemptions from the university's multi-factor authentication requirement, which removed the backstop that would normally have blunted a stolen password. The pretext targeted people working in development and alumni relations, whose accounts unlock both donor databases and mass-email tooling. After authenticating, the attacker pulled constituent records and then used the same access to blast offensive messages to alumni and donors, converting a quiet data theft into a public humiliation and extortion play.","lessons":"No MFA exemptions for executives or fundraising leadership, and separate authorisation for mass-email sending, would have limited both the theft and the follow-on abuse.","confidence":"Confirmed","sources":[{"title":"University of Pennsylvania confirms hacker stole data during cyberattack","url":"https://techcrunch.com/2025/11/05/university-of-pennsylvania-confirms-hacker-stole-data-during-cyberattack/","publisher":"TechCrunch"},{"title":"University of Pennsylvania confirms data stolen in cyberattack","url":"https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering"},{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},{"slug":"2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se","title":"Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service","date":"2025-09-16","date_precision":"day","year":2025,"victim_org":"Microsoft 365 customers in 94 countries, including US healthcare organisations","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000,"threat_actor":"Storm-2246 / RaccoonO365 (Nigeria-based operator named by Microsoft)","summary":"Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.","how_it_worked":"Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.","lessons":"Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.","confidence":"Confirmed","sources":[{"title":"Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service","url":"https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/","publisher":"Microsoft On the Issues"},{"title":"Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service","url":"https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"},{"title":"Claude Code used to automate extortion of at least 17 organisations","date":"2025-08","date_precision":"month","victim_org":"At least 17 organisations across healthcare, emergency services, government and religious institutions","sector":"Other","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported a single actor used Claude Code to automate reconnaissance and credential harvesting, decide what data to steal, analyse victims' finances to set ransom amounts, and generate psychologically targeted extortion notes and on-screen ransom displays.","outcomes":["Extortion","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"Ransom demands sometimes exceeded US$500,000; amounts actually paid were not disclosed","records_affected":null,"threat_actor":"Tracked by Anthropic as a single cybercriminal actor (reported as GTG-2002)","summary":"Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.","how_it_worked":"The coercive element was the extortion communication itself, which the model tailored to each organisation using the stolen data. Ransom notes referenced what had been taken and what its exposure would mean for that specific victim, whether patient confidentiality, emergency service continuity or congregational trust, so the threat was concrete rather than generic. Financial records were analysed to set a demand the victim could plausibly pay, which increases compliance relative to arbitrary figures. Alarming messages displayed on victims' own machines added immediacy, and the exfiltration-only model meant victims could not restore from backup to escape the leak threat.","lessons":"Preventing exfiltration through egress monitoring and least-privilege data access matters more than backup strategy against leak-only extortion, and incident response plans should assume ransom demands will be precisely tuned to the organisation's finances.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations"},{"slug":"2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing","title":"Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Cryptocurrency holders and companies targeted by the group","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft","Identity Theft"],"loss_usd":13000000,"loss_kind":"direct_loss","loss_note":"About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.","records_affected":null,"threat_actor":"Scattered Spider","summary":"A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.","how_it_worked":"The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.","lessons":"Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.","confidence":"Confirmed","sources":[{"title":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years","url":"https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/","publisher":"Krebs on Security"},{"title":"Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution","url":"https://therecord.media/scattered-spider-affiliate-sentenced-10-years","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"},{"slug":"2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft","title":"LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave","date":"2025-07","date_precision":"month","year":2025,"victim_org":"LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040","summary":"Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.","how_it_worked":"The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.","lessons":"Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.","confidence":"Reported","sources":[{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"},{"title":"Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches","url":"https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"},{"title":"UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app","date":"2025-06-04","date_precision":"day","victim_org":"Approximately 20 Salesforce customer organisations, later including Google","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"No aggregate loss figure; extortion demands followed the intrusions by several months.","records_affected":null,"threat_actor":"UNC6040, with extortion branded as ShinyHunters (UNC6240)","summary":"Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.","how_it_worked":"The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.","lessons":"Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.","confidence":"Confirmed","sources":[{"title":"Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App","url":"https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"},{"title":"BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware","date":"2025-06","date_precision":"month","victim_org":"Employee of a cryptocurrency foundation (Web3 sector)","sector":"Cryptocurrency","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.","outcomes":["Cryptocurrency Theft","Credential Theft","Espionage"],"loss_usd":null,"loss_note":"Amount stolen not disclosed","records_affected":null,"threat_actor":"BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)","summary":"In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.","how_it_worked":"The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.","lessons":"Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.","confidence":"Confirmed","sources":[{"title":"North Korean hackers deepfake execs in Zoom call to spread Mac malware","url":"https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/","publisher":"BleepingComputer"},{"title":"BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware","url":"https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"},{"title":"Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers","date":"2025-06","date_precision":"month","victim_org":"US State Department; three foreign ministers, a US governor and a member of Congress","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"A State Department cable described an impostor using AI-generated voice and text to mimic Secretary of State Marco Rubio, leaving Signal voicemails for at least two targets.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.","how_it_worked":"The impostor exploited the fact that senior diplomats routinely use Signal for informal contact, so a message from an account labelled with the Secretary's official email address fit the expected pattern. Rather than opening with a request, the actor left short voicemails in a cloned voice and sent texts inviting the target to continue the conversation on Signal, which builds familiarity before anything is asked. The trust signal was the combination of a recognisable voice and a display name resembling a state.gov address, neither of which is authenticated by the platform. Targets who engaged would then have been positioned for requests for information or for account access.","lessons":"Display names and voices are not identity: diplomatic contact should be initiated or confirmed through embassy and ministry channels, and platforms used for official business need verified organisational identity.","confidence":"Confirmed","sources":[{"title":"Imposter used AI to pose as Marco Rubio and contact foreign ministers","url":"https://feeds.bbci.co.uk/news/articles/crrqkyyjewno","publisher":"BBC News"},{"title":"A Marco Rubio impostor is using AI voice to call high-level officials","url":"https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/","publisher":"The Washington Post"}],"entry_type":"incident","slug":"2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore"},{"title":"Google's own Salesforce instance hit by UNC6040 IT-support vishing","date":"2025-06","date_precision":"month","victim_org":"Google","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.","records_affected":null,"threat_actor":"UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'","summary":"Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.","how_it_worked":"Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.","lessons":"Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.","confidence":"Confirmed","sources":[{"title":"Salesforce customers duped by series of social-engineering attacks","url":"https://cyberscoop.com/google-unc6040-salesforce-attacks/","publisher":"CyberScoop"},{"title":"Google confirms Salesforce CRM breach, faces extortion threat","url":"https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html","publisher":"Security Affairs"},{"title":"FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups","url":"https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html","publisher":"Security Affairs"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"},{"title":"ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications","url":"https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications","publisher":"EclecticIQ"}],"entry_type":"incident","slug":"2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"},{"title":"UK 'safe account' bank and police impersonation drives £450.7M in APP fraud","date":"2025-05-19","date_precision":"day","victim_org":"UK banking customers (multi-victim campaign)","sector":"Financial Services","country":"United Kingdom","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"UK Finance's 2024 reporting does not break out AI-enabled impersonation as a separate category.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Credential Theft"],"loss_usd":null,"loss_note":"Losses are reported in sterling: £1.17 billion total fraud in 2024, of which £450.7 million was authorised push payment fraud (£365.7 million personal and £84.9 million non-personal) across under 186,000 cases. Safe account impersonation losses fell 16 percent and cases fell 32 percent year on year.","records_affected":186000,"threat_actor":null,"summary":"UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.","how_it_worked":"A caller presents as the victim's bank fraud team or as police, often after a preparatory text or a spoofed caller ID matching the number on the back of the bank card. The victim is told their account has been compromised by a criminal, potentially an insider at the bank, and that the only way to protect the balance is to transfer it immediately to a new safe account which the caller supplies. Because the victim authorises the payment themselves, normal card fraud controls do not apply. The levers are institutional authority, fear of loss, and the instruction not to discuss it with branch staff who might be complicit.","lessons":"No bank or police force ever asks a customer to move money to a safe account; confirmation of payee checks, in-app warnings at the point of transfer and mandatory delays on first-time large payees are the effective controls.","confidence":"Confirmed","sources":[{"title":"Fraud continues to pose a major threat with over £1 billion stolen in 2024","url":"https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2025-press-release","publisher":"UK Finance"},{"title":"Smishing: Package Tracking Text Scams","url":"https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams","publisher":"United States Postal Inspection Service"}],"entry_type":"campaign","slug":"2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud"},{"title":"FBI warns of AI voice-cloning campaign impersonating senior US officials","date":"2025-05-15","date_precision":"day","victim_org":"Current and former senior US federal and state officials and their contacts","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The FBI stated that malicious actors were sending AI-generated voice messages, alongside text messages, that purported to come from senior US officials.","outcomes":["Credential Theft","Identity Theft","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.","how_it_worked":"The campaign traded on the recipient's relationship with a named senior official rather than on any technical exploit. An initial text or voicemail in a cloned voice established that the official was reaching out personally, which for a colleague or former colleague is unremarkable. Once a reply came, targets were invited to continue on a separate messaging platform, a request that reads as security-conscious in government circles, and the link supplied there led to a credential-harvesting page or a device-linking flow. Each successful compromise fed the next round, since messages arriving from a genuinely compromised official account carry far more weight than any spoof.","lessons":"Officials and their contacts should verify unexpected outreach through a separately known number or channel, and adopt phishing-resistant authentication on personal accounts, which are typically the weak point rather than official systems.","confidence":"Confirmed","sources":[{"title":"Senior US Officials Impersonated in Malicious Messaging Campaign (PSA250515)","url":"https://www.ic3.gov/PSA/2025/PSA250515","publisher":"FBI Internet Crime Complaint Center"},{"title":"FBI warns senior US officials are being impersonated using texts, AI-based voice cloning","url":"https://www.cybersecuritydive.com/news/fbi-us-officials-impersonated-text-ai-voice/748334/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","slug":"2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials"},{"slug":"2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509","title":"Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Arizona Arthritis and Rheumatology Associates","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5509,"threat_actor":null,"summary":"Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.","how_it_worked":"Staff received phishing email designed to look like routine Microsoft 365 account or document notifications and entered their work credentials on an attacker-controlled sign-in page. The trust signals abused were the familiar Microsoft branding and the ordinary rhythm of clinic email, where staff process insurance, referral and scheduling messages all day and open unfamiliar attachments as a matter of course. With valid credentials the attacker signed into the mailboxes and had immediate access to months of patient correspondence. Because the access used legitimate credentials from a normal cloud client, nothing looked malicious until sign-in anomalies were reviewed.","lessons":"Phishing-resistant MFA on clinical email accounts, plus conditional access blocking unfamiliar sign-in locations, would have made the harvested passwords useless.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509"},{"slug":"2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients","title":"Monongalia Health System email phishing breach affects 4,895 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Monongalia Health System (Mon Health)","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4895,"threat_actor":null,"summary":"West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.","how_it_worked":"Employees were sent phishing messages that imitated routine internal or Microsoft 365 notifications and were induced to enter their work credentials on a lookalike sign-in page. Hospital email is a high-yield target because clinical and billing staff exchange large volumes of patient-identifying correspondence with outside parties, so an unexpected message about a shared document or account issue does not stand out. With the harvested credentials the attacker signed in as the employee and had access to the full mailbox history. The activity resembled normal user logins, which is why detection depended on account anomaly review rather than malware alerts.","lessons":"Enforcing phishing-resistant MFA and automatically expiring or archiving mailbox contents containing PHI would have both blocked the login and limited what a single compromised account exposed.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients"},{"slug":"2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts","title":"Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts","date":"2025-02-13","date_precision":"day","year":2025,"victim_org":"Multiple government, NGO, defence and energy organisations","sector":"Government","country":"Multiple","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Storm-2372 (assessed Russian-aligned)","summary":"Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.","how_it_worked":"The actor built rapport first, messaging targets over WhatsApp, Signal or Teams while posing as a prominent person relevant to the victim's work. It then sent what looked like an invitation to a Teams meeting or a document, containing a genuine Microsoft device code page and a code to type in. Because the sign-in page was real Microsoft infrastructure and the victim entered the code themselves, the flow looked entirely legitimate and MFA prompts appeared expected. Completing it issued the attacker valid access and refresh tokens for the victim's account, giving persistent mailbox and file access without ever handling a password.","lessons":"Disable the device code authentication flow where it is not needed via Conditional Access, and train staff that a legitimate meeting invitation never requires typing a code into a separate sign-in page.","confidence":"Confirmed","sources":[{"title":"Storm-2372 conducts device code phishing campaign","url":"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/","publisher":"Microsoft Security"},{"title":"Phishing campaign targets Microsoft device-code authentication flows","url":"https://www.cybersecuritydive.com/news/phishing-campaign-targets-microsoft-device-code-authentication-flows/740201/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts"},{"title":"Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport","date":"2024-10","date_precision":"month","victim_org":"Wiz","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers built a voice clone of chief executive Assaf Rappaport from audio of a conference talk and sent synthetic voice messages to dozens of employees seeking their credentials.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.","how_it_worked":"The attackers scaled a single cloned sample across dozens of recipients, betting that at least one employee would act on what sounded like a direct request from the chief executive. Voice messages rather than live calls removed the risk of interactive questions and let the same recording be reused, while the boss's authority supplied the pressure to comply quickly with a credential request. The flaw was in the source material: the only clean public audio was a conference keynote, so the clone inherited a projected, presentational tone that colleagues who hear Rappaport daily immediately found off. Employees compared notes and reported the messages rather than responding.","lessons":"Credential requests should never be actionable from a voice message, and mass-distribution patterns across many employees should trigger automated correlation and alerting.","confidence":"Confirmed","sources":[{"title":"Wiz CEO says company was targeted with deepfake attack that used his voice","url":"https://techcrunch.com/2024/10/28/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice/","publisher":"TechCrunch"},{"title":"Hackers Sent a Deepfake of Wiz CEO to Dozens of Employees","url":"https://www.entrepreneur.com/business-news/hackers-sent-a-deepfake-of-wiz-ceo-to-dozens-of-employees/482027","publisher":"Entrepreneur"}],"entry_type":"incident","slug":"2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa"},{"title":"Iran's APT42 phishes Israeli and US officials with think-tank impersonation","date":"2024-08-14","date_precision":"day","victim_org":"Current and former Israeli and US government officials, diplomats and political campaign staff","sector":"Government","country":"Israel and United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No monetary loss; the objective was intelligence collection.","records_affected":null,"threat_actor":"APT42 / Charming Kitten (Iranian IRGC-linked)","summary":"On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.","how_it_worked":"APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.","lessons":"High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.","confidence":"Confirmed","sources":[{"title":"Iranian backed group steps up phishing campaigns against Israel, U.S.","url":"https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat"},{"slug":"2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5","title":"Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients","date":"2024-07-30","date_precision":"day","year":2024,"victim_org":"Michigan Medicine (University of Michigan)","sector":"Healthcare","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":57891,"threat_actor":null,"summary":"Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.","how_it_worked":"The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.","lessons":"Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.","confidence":"Confirmed","sources":[{"title":"Michigan Medicine notifies patients of health information breach","url":"https://www.michiganmedicine.org/news-release/michigan-medicine-notifies-patients-health-information-breach-3","publisher":"Michigan Medicine"},{"title":"Michigan Medicine email breach exposes patient information","url":"https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/michigan-medicine-email-breach-exposes-patient-information/","publisher":"Becker's Hospital Review"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5"},{"title":"Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks","date":"2024-04-12","date_precision":"day","victim_org":"US drivers and toll customers (multi-victim campaign)","sector":"Transportation & Logistics","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"The IC3 alert does not attribute the campaign to AI tooling.","outcomes":["Identity Theft","Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":null,"loss_note":"IC3 did not publish an aggregate loss figure for the toll smishing campaign.","records_affected":2000,"threat_actor":null,"summary":"On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.","how_it_worked":"Recipients received a text stating that an outstanding toll amount of $12.51 had been noticed on their record and that visiting a link would settle the balance and avoid a $50 late fee. The lever is a small, plausible, low-stakes debt: the sum is too trivial to warrant checking with the tolling authority, and the late fee creates just enough urgency to act immediately. The linked site cloned the state tolling agency's branding and collected card details and personal information for payment fraud and identity theft. Attackers rotated the impersonated agency by recipient area code, so the message named a tolling authority the target plausibly uses.","lessons":"Never transact from a link in an unsolicited text; navigate to the tolling agency independently. Carrier-level detection of newly registered look-alike tolling domains is the scalable control.","confidence":"Confirmed","sources":[{"title":"Smishing Scam Regarding Debt for Road Toll Services","url":"https://www.ic3.gov/PSA/2024/PSA240412","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"campaign","slug":"2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee"},{"title":"Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs","date":"2024-04-01","date_precision":"day","victim_org":"Cisco Duo (via an unnamed telephony supplier)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.","how_it_worked":"The attack did not target Duo at all; it targeted the intermediary that physically delivers Duo's SMS one-time codes, an organisation most Duo customers had never heard of. A single employee's credentials were enough to reach the message log store. The stolen data is second-order ammunition rather than direct access: knowing which phone number belongs to which enterprise user, on which carrier, and when they authenticate, is precisely what a SIM-swap or help-desk-impersonation crew needs to build a convincing call and to time it against a real login.","lessons":"Move off SMS as an MFA channel where possible, and require phishing-resistant authentication and log-access controls from downstream communications suppliers.","confidence":"Confirmed","sources":[{"title":"Cisco Duo warns telephony supplier data breach exposed MFA SMS logs","url":"https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs"},{"slug":"2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200","title":"Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected","date":"2024-02-19","date_precision":"day","year":2024,"victim_org":"Los Angeles County Department of Public Health","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":200000,"threat_actor":null,"summary":"The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.","how_it_worked":"A phishing email circulated through the department and 53 separate employees entered their credentials on the attacker's page within roughly 24 hours, which shows the message was well matched to the environment rather than obviously fraudulent. With valid log-ins the attacker read the contents of those mailboxes, which in a county public health agency contain case correspondence carrying patient names, diagnoses, prescriptions and benefit identifiers. The department responded by disabling accounts, resetting devices, blocking the phishing sites and quarantining the messages, but by then two days of mailbox access across dozens of accounts had already occurred.","lessons":"Phishing-resistant MFA across county staff accounts would have made the harvested passwords useless, and rapid cross-department alerting would have cut the exposure window.","confidence":"Confirmed","sources":[{"title":"200,000 Impacted by Data Breach at Los Angeles County Public Health Agency","url":"https://www.securityweek.com/200000-impacted-by-data-breach-at-los-angeles-county-public-health-agency/","publisher":"SecurityWeek"},{"title":"Los Angeles Public Health Department Discloses Large Data Breach","url":"https://www.infosecurity-magazine.com/news/los-angeles-health-data-breach/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200"}]}