{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:27:58.896Z","total":13,"returned":13,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware","date":"2026-02","date_precision":"month","victim_org":"An unnamed cryptocurrency company executive","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Deepfake Video Call","secondary_vectors":["Tech Support Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.","records_affected":null,"threat_actor":"UNC1069 (DPRK), tracked by Mandiant since 2018","summary":"Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.","how_it_worked":"Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.","lessons":"No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.","confidence":"Confirmed","sources":[{"title":"North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam","url":"https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix","publisher":"The Record (Recorded Future News)"},{"title":"North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms","url":"https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"},{"title":"BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware","date":"2025-06","date_precision":"month","victim_org":"Employee of a cryptocurrency foundation (Web3 sector)","sector":"Cryptocurrency","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.","outcomes":["Cryptocurrency Theft","Credential Theft","Espionage"],"loss_usd":null,"loss_note":"Amount stolen not disclosed","records_affected":null,"threat_actor":"BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)","summary":"In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.","how_it_worked":"The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.","lessons":"Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.","confidence":"Confirmed","sources":[{"title":"North Korean hackers deepfake execs in Zoom call to spread Mac malware","url":"https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/","publisher":"BleepingComputer"},{"title":"BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware","url":"https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"},{"title":"North Korean operatives adopt real-time deepfakes to pass remote job interviews","date":"2025-04","date_precision":"month","victim_org":"Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Deepfake Video Call","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.","how_it_worked":"The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.","lessons":"Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.","confidence":"Confirmed","sources":[{"title":"False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation","url":"https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/","publisher":"Palo Alto Networks Unit 42"},{"title":"North Korean Operatives Use Deepfakes in IT Job Interviews","url":"https://www.darkreading.com/remote-workforce/north-korean-operatives-deepfakes-it-job-interviews","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int"},{"title":"Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO","date":"2025-03","date_precision":"month","victim_org":"Unnamed multinational firm, Singapore office","sector":"Other","country":"Singapore","primary_vector":"Deepfake Video Call","secondary_vectors":["Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Singapore Police said deepfake technology was used to render the company's chief financial officer, chief executive and other officials during a Zoom video conference.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":499000,"loss_note":"Over US$499,000 transferred; funds recovered by Singapore and Hong Kong police within days","records_affected":null,"threat_actor":null,"summary":"On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.","how_it_worked":"The approach opened on WhatsApp, a channel where an executive contact request feels informal but not alarming, and offered a business rationale, a confidential regional restructuring, that justified both secrecy and an unusual payment. The video conference supplied the decisive trust signal by putting the target in a room with the two most senior people in his reporting line plus other familiar faces. An outside lawyer and an NDA added procedural theatre that made the transaction look governed rather than improvised, while also formalising the instruction not to tell colleagues. Compliance was easy because the finance director was doing precisely his job, executing a payment approved by the CFO.","lessons":"Payments authorised on a video call should still require callback verification to a directory-listed number and dual approval; the fast bank and police escalation here is what made recovery possible.","confidence":"Confirmed","sources":[{"title":"Singapore firm nearly lost $500,000 after deepfake video scam: police","url":"https://www.hcamag.com/asia/specialisation/hr-technology/singapore-firm-nearly-lost-500000-after-deepfake-video-scam-police/531450","publisher":"Human Resources Director Asia"}],"entry_type":"incident","slug":"2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w"},{"title":"Hong Kong arrests 31 in second deepfake romance fraud ring targeting Southeast Asia","date":"2025-01","date_precision":"month","victim_org":"Victims in Taiwan, Singapore and Malaysia","sector":"Consumer","country":"Hong Kong","primary_vector":"Romance / Investment Scam","secondary_vectors":["Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The syndicate combined photographs of attractive people scraped online with deepfake technology to create and sustain fictitious personas on dating apps.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":4370000,"loss_note":"Over HK$34 million, approx US$4.37 million","records_affected":null,"threat_actor":"Hong Kong-based fraud syndicate operating from Kowloon Bay","summary":"Hong Kong police arrested 31 people on 2 and 3 January 2025 over a deepfake-enabled romance and investment fraud syndicate that operated from two premises in Kowloon Bay and took more than HK$34 million (about US$4.37 million) from victims in Taiwan, Singapore and Malaysia. Members were trained to approach targets on dating apps using online photographs of attractive people combined with deepfake technology. It was the second major deepfake fraud bust by Hong Kong authorities in three months.","how_it_worked":"Recruits worked from scripts and training materials, opening on dating apps with fabricated female personas assembled from scraped photographs and rendered live with face-swapping software when a target asked for video proof. The romance was cultivated over weeks so that the eventual investment pitch arrived from someone the victim believed they knew personally rather than from a stranger. Targets in neighbouring jurisdictions were chosen partly because cross-border reporting and recovery are slower. Funds were routed into cryptocurrency, which made reversal difficult once the persona went dark.","lessons":"Cross-border anti-fraud coordination and dating-platform detection of face-swap artefacts on live video are the two controls that materially shrink this model.","confidence":"Confirmed","sources":[{"title":"Hong Kong police arrest 31 over deepfakes used to scam victims in Singapore, Malaysia","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3293476/hong-kong-police-arrest-31-who-used-deepfakes-scam-victims-singapore-malaysia","publisher":"South China Morning Post"}],"entry_type":"campaign","slug":"2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou"},{"title":"FBI warns criminals are using generative AI to scale voice-clone and identity fraud","date":"2024-12-03","date_precision":"day","victim_org":"US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Deepfake Video Call","Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The entire advisory concerns criminal use of generative AI: AI text for phishing and fake profiles, AI images for fake IDs and personas, voice cloning to impersonate relatives and account holders, and real-time video synthesis to impersonate executives and authorities.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Extortion","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"The advisory does not publish an aggregate loss figure for AI-enabled fraud.","records_affected":null,"threat_actor":null,"summary":"On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.","how_it_worked":"Voice cloning is the pivotal technique for consumer harm. A short sample of a person's speech, readily available from social media video, is enough to synthesise a distressed relative calling to say they have been in an accident or arrested and need money immediately. The lever is the recognisable voice of a loved one under duress, which suppresses verification instincts far more effectively than any script. The same technology is used to satisfy bank voice authentication as an account holder, and real-time video synthesis extends it to live calls impersonating executives or providing proof of legitimacy to a romance or investment target. AI translation also strips the grammatical errors that once exposed foreign operators.","lessons":"The FBI's own recommendation is the practical control: agree a family or organisational verification code word in advance, and independently call back on a known number before acting on any urgent request.","confidence":"Confirmed","sources":[{"title":"Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud","url":"https://www.ic3.gov/PSA/2024/PSA241203","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide"},{"title":"Deepfake Elon Musk videos drive crypto investment scams against US consumers","date":"2024-11","date_precision":"month","victim_org":"Multiple US consumers","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Romance / Investment Scam","Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Scammers generated AI video and voice of Elon Musk pitching cryptocurrency investment schemes and distributed them as ads and posts on Facebook and TikTok.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Individual victim Heidi Swan lost over US$10,000; Deloitte estimated generative AI contributed to more than US$12 billion in US fraud losses in 2023, projected to reach US$40 billion by 2027","records_affected":null,"threat_actor":null,"summary":"By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.","how_it_worked":"The lure ran on the credibility of a single very famous investor whose views on cryptocurrency are widely known, so a video of him endorsing a platform confirmed what many targets already half-believed. Distribution through paid social advertising delivered the content inside trusted feeds and let operators target older users with disposable savings. The synthetic Musk described a limited-time opportunity with outsized returns, and the follow-through moved victims onto a bogus exchange with a support representative who coached them through funding the account. Fabricated balance growth and, in some cases, small permitted withdrawals sustained belief and encouraged larger deposits until withdrawals were blocked.","lessons":"Celebrity endorsement is never a basis for investing; platforms must verify advertiser identity and screen for synthetic likeness of public figures before ads run.","confidence":"Reported","sources":[{"title":"Deepfakes of Elon Musk are contributing to billions of dollars in fraud losses in the U.S.","url":"https://www.cbsnews.com/texas/news/deepfakes-ai-fraud-elon-musk/","publisher":"CBS News"},{"title":"Deepfake Elon Musk Videos Have Reportedly Contributed to Billions in Fraud","url":"https://incidentdatabase.ai/cite/795/","publisher":"AI Incident Database"}],"entry_type":"campaign","slug":"2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu"},{"title":"Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring","date":"2024-10","date_precision":"month","victim_org":"Men across Asia targeted through dating apps","sector":"Consumer","country":"Hong Kong","primary_vector":"Romance / Investment Scam","secondary_vectors":["Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Syndicate members used AI face-swapping to replace their own faces with those of attractive women during video calls with victims, sustaining the fiction of a relationship.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":46000000,"loss_note":"HK$360 million, approx US$46 million","records_affected":null,"threat_actor":"Hong Kong-based syndicate with reported triad links","summary":"Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.","how_it_worked":"Operators opened on dating apps with AI-generated or face-swapped profiles of attractive women and invested weeks in ordinary conversation, building an emotional bond before money was ever mentioned. Video calls were the decisive trust signal, because a target who has seen and spoken with the person on camera discounts warnings about catfishing. Once the relationship felt real, the persona introduced a cryptocurrency trading platform run by the syndicate, showing fabricated gains and letting small withdrawals succeed so the returns appeared genuine. Pressure came from a mixture of intimacy and fear of missing out, and the training documents seized by police show the manipulation was scripted, not improvised.","lessons":"Reverse-image and liveness checks on dating profiles help, but the durable control is treating any investment platform introduced by an online romantic contact as fraudulent by default.","confidence":"Confirmed","sources":[{"title":"Hong Kong fraudsters use deepfake tech to swindle love-struck men out of HK$360 million","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3282345/hong-kong-fraudsters-use-deepfake-tech-swindle-love-struck-men-out-hk360-million","publisher":"South China Morning Post"},{"title":"Police arrest 27 for deepfake love scams totaling $360m, seizes scam-training documents","url":"https://www.thestandard.com.hk/news/article/221507/Police-arrest-27-for-deepfake-love-scams-totaling-360m-seizes-scam-training-documents","publisher":"The Standard (Hong Kong)"}],"entry_type":"campaign","slug":"2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen","year":2024,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen"},{"title":"US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM","date":"2024-09","date_precision":"month","victim_org":"Office of US Senator Ben Cardin, Senate Foreign Relations Committee","sector":"Government","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Senate security officials described the video call participant as an apparent deepfake of former Ukrainian foreign minister Dmytro Kuleba that matched his appearance and voice from prior encounters.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.","how_it_worked":"The pretext exploited a routine of the job: a foreign official Cardin had genuinely met requesting a follow-up video call on a live policy question. Because the identity was plausible and the scheduling followed normal staff channels, the meeting went ahead without independent verification through the State Department. On camera the deepfake supplied the visual and vocal confirmation staff expected. The impersonator then pushed for on-the-record statements that could be clipped and weaponised, applying pressure by demanding immediate answers. The tell was behavioural rather than technical: the real Kuleba would not badger a committee chair for soundbites, and the mismatch in conduct ended the call.","lessons":"Legislative offices should route requests for meetings with foreign officials through the State Department or the relevant embassy for confirmation before a call is scheduled.","confidence":"Reported","sources":[{"title":"Ben Cardin targeted in apparent deepfake call with someone posing as Dmytro Kuleba","url":"https://www.nbcnews.com/politics/congress/ben-cardin-targeted-apparent-deep-fake-call-dmytro-kuleba-rcna172776","publisher":"NBC News"},{"title":"Elaborate Deepfake Operation Takes a Meeting With US Senator","url":"https://www.darkreading.com/cyberattacks-data-breaches/elaborate-deepfake-operation-meeting-us-senator","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s"},{"title":"WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read","date":"2024-05","date_precision":"month","victim_org":"WPP","sector":"Media & Entertainment","country":"United Kingdom","primary_vector":"Deepfake Video Call","secondary_vectors":["Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers set up a WhatsApp account using a publicly available image of chief executive Mark Read, then ran a Microsoft Teams meeting using YouTube footage of him alongside an AI voice clone.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.","how_it_worked":"The pretext was a new business opportunity that a chief executive might plausibly want to explore quietly with one trusted agency leader, which explained both the confidentiality and the unusual approach. The attackers assembled several weak trust signals into a convincing whole: a WhatsApp profile with Read's real photo, a Teams invite from an apparently senior source, video that showed his face and a synthetic voice on the line, and chat messages written in his persona. The technical staging papered over the gaps, with camera and audio problems used to explain why the video looked like recorded footage. The target was asked to move on money and personal information without touching normal corporate process.","lessons":"Verifying meeting invitations through the corporate directory rather than a messaging-app contact, and refusing to progress financial arrangements outside standard process, are what stopped this.","confidence":"Confirmed","sources":[{"title":"CEO of world's biggest ad firm targeted by deepfake scam","url":"https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam","publisher":"The Guardian"},{"title":"Scammers Reportedly Used AI Voice Clone and YouTube Footage to Impersonate WPP CEO","url":"https://incidentdatabase.ai/cite/983/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark"},{"title":"Arup Hong Kong office loses about $25 million in deepfake video call scam","date":"2024-02","date_precision":"month","victim_org":"Arup Group (Hong Kong office)","sector":"Professional Services","country":"Hong Kong","primary_vector":"Deepfake Video Call","secondary_vectors":["Business Email Compromise","Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":25000000,"loss_note":"HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.","records_affected":null,"threat_actor":null,"summary":"In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.","how_it_worked":"The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.","lessons":"High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.","confidence":"Confirmed","sources":[{"title":"Deepfaked video conference call makes employee send $25 million to scammers","url":"https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/","publisher":"Help Net Security"},{"title":"Arup Group (fraud incident section)","url":"https://en.wikipedia.org/wiki/Arup_Group","publisher":"Wikipedia"},{"title":"Business Email Compromise: Virtual Meeting Platforms","url":"https://www.ic3.gov/PSA/2022/PSA220216","publisher":"FBI IC3"},{"title":"Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee","url":"https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk","publisher":"CNN"},{"title":"'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage","publisher":"South China Morning Post"}],"entry_type":"incident","slug":"2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"},{"title":"Deepfake of Binance communications chief used to scam crypto projects on video calls","date":"2022-08","date_precision":"month","victim_org":"Multiple cryptocurrency projects seeking Binance listings","sector":"Cryptocurrency","country":"Multiple countries","primary_vector":"Deepfake Video Call","secondary_vectors":["Romance / Investment Scam"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Binance chief communications officer Patrick Hillmann said attackers built an AI video 'hologram' of him from his past news interviews and TV appearances and used it live on Zoom calls.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Losses to individual projects were not disclosed","records_affected":null,"threat_actor":null,"summary":"In August 2022 Binance disclosed that a 'sophisticated hacking team' had produced a deepfake video likeness of chief communications officer Patrick Hillmann and used it on Zoom calls with representatives of cryptocurrency projects. The impersonator offered help getting tokens listed on Binance and solicited payments and information. Hillmann said several project managers were convinced before the fraud was discovered, and that the clone was built from his publicly available interview footage.","how_it_worked":"The pretext was the single thing small crypto projects want most, a listing on the largest exchange, and the caller occupied a role that plausibly controls access to it. Contact was made over social channels and then escalated to a Zoom call, where the deepfake of a face the targets had seen in Binance media coverage supplied the trust signal that a mere email could not. Because listing discussions are routinely confidential and involve fees, requests for money and business documents did not look out of place. Victims were pushed to move fast on the implied scarcity of a listing slot, and only later checked with Binance through official channels.","lessons":"Exchange listing and partnership discussions should be confirmed through the company's published contact channels, and no vendor should treat a video likeness as proof of employment.","confidence":"Reported","sources":[{"title":"Binance exec says scammers made a deepfake hologram of him","url":"https://www.theregister.com/2022/08/23/binance_deepfake_scam/","publisher":"The Register"},{"title":"Deepfake hologram targets Binance and crypto community","url":"https://www.malwarebytes.com/blog/news/2022/08/deepfake-hologram-targets-binance-and-crypto-community","publisher":"Malwarebytes Labs"}],"entry_type":"campaign","slug":"2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on"},{"title":"European mayors duped by deepfake video calls posing as Kyiv mayor Klitschko","date":"2022-06","date_precision":"month","victim_org":"City governments of Berlin, Madrid and Vienna","sector":"Government","country":"Germany","primary_vector":"Deepfake Video Call","secondary_vectors":[],"ai_involvement":"Suspected AI-enabled","ai_notes":"Berlin's mayoral office concluded after the call that deepfake technology had been used to render Vitali Klitschko's face and voice in a live video conference; other analysts suggested edited genuine footage may have been used instead.","outcomes":["Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In June 2022 the mayors of Berlin (Franziska Giffey), Madrid (Jose Luis Martinez-Almeida) and Vienna (Michael Ludwig) each held video calls with someone presenting as Kyiv mayor Vitali Klitschko. Giffey's office said the call was cut short when the topics and framing became implausible, and concluded a deepfake had been used. Klitschko linked the calls to Russian efforts to drive a wedge between Ukraine and its European partners. Attribution was never publicly established.","how_it_worked":"The approach exploited an entirely normal wartime diplomatic pattern: European capitals were actively arranging solidarity calls with Ukrainian city leaders, so an inbound request for a video meeting with Klitschko fit expectations and passed through official scheduling channels. On camera the impersonator looked and sounded like a figure the mayors had seen in constant media coverage, which supplied the trust signal. The caller then steered the conversation toward politically loaded subjects, apparently to elicit quotable statements about Ukrainian refugees and support for Ukraine. Berlin's staff aborted only when the substance of the conversation, rather than the imagery, stopped making sense.","lessons":"Video identity is not authentication; inbound requests for calls with senior officials should be confirmed through the counterpart's own foreign ministry or embassy channel before the meeting is booked.","confidence":"Reported","sources":[{"title":"European mayors duped into calls with fake Kyiv mayor","url":"https://www.clickorlando.com/news/world/2022/06/25/european-mayors-duped-into-calls-with-fake-kyiv-mayor/","publisher":"Associated Press"},{"title":"European mayors duped into calls with fake Kyiv mayor","url":"https://www.cnbc.com/2022/06/25/european-mayors-duped-into-calls-with-fake-kyiv-mayor.html","publisher":"CNBC"}],"entry_type":"incident","slug":"2022-european-mayors-duped-by-deepfake-video-calls-posing-as-kyiv-mayor-klits","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-european-mayors-duped-by-deepfake-video-calls-posing-as-kyiv-mayor-klits"}]}