{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:35.343Z","total":17,"returned":17,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag","title":"FBI identifies North Korean remote IT worker employed by a US federal agency","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Unnamed US federal agency","sector":"Government","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Insider Access","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker programme","summary":"FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.","how_it_worked":"The DPRK remote IT worker programme wins access by being hired rather than by breaking in. Operatives apply for remote technical roles using stolen or fabricated identities, often with US-based facilitators who host company laptops, sit for identity checks, or lend a domestic address and bank account so that pay and equipment appear to land with a real person in the United States. Video interviews and onboarding checks are handled by the operative or the facilitator. Once employed the worker holds legitimate credentials and normal access, which is why detection typically comes from behavioural or payroll anomalies rather than security tooling.","lessons":"Live identity proofing at hire and again at equipment issue, plus checks that payroll destinations and laptop network locations match the claimed residence, are what surface these placements.","confidence":"Confirmed","sources":[{"title":"FBI investigating North Korean remote IT staffer working for US agency","url":"https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/","publisher":"Federal News Network"},{"title":"FBI finds North Korean IT worker inside federal agency","url":"https://www.thestreet.com/employment/fbi-north-korean-remote-worker-insider-threat-2026","publisher":"TheStreet"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag"},{"slug":"2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day","title":"Lazarus pairs fake recruiter approaches with a Windows zero-day","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Defence and aerospace organisations in Western Europe, India and South America","sector":"Defense","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Lazarus Group (North Korea)","summary":"Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.","how_it_worked":"Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.","lessons":"Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.","confidence":"Confirmed","sources":[{"title":"Lazarus hackers pair fake job offers with Windows zero-day exploit","url":"https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/","publisher":"Help Net Security"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"},{"title":"Six-month DPRK social engineering operation preceded $285M Drift Protocol theft","date":"2026-04-01","date_precision":"day","victim_org":"Drift Protocol","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Physical Pretexting","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.","outcomes":["Cryptocurrency Theft"],"loss_usd":285000000,"loss_note":"USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.","records_affected":null,"threat_actor":"UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence","summary":"Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.","how_it_worked":"This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.","lessons":"Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.","confidence":"Reported","sources":[{"title":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","publisher":"The Hacker News"},{"title":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks","publisher":"TRM Labs"}],"entry_type":"incident","slug":"2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol","year":2026,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"},{"slug":"2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors","title":"Contagious Interview: fake developer job interviews deliver backdoors","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Software developers at enterprise solution, media and communications firms","sector":"Technology","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Cryptocurrency Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.","how_it_worked":"The pretext is a career opportunity, and the trust signal is the ordinary shape of a developer hiring process: a recruiter approach, a screening call, then a take-home coding exercise. The malicious step is disguised as the exercise itself, because cloning a repository and running it locally is exactly what a candidate is expected to do. Payloads fire automatically from task configuration files when the repository is opened in Visual Studio Code, so no obviously suspicious action is needed. The malware then harvests API tokens, cloud credentials, cryptocurrency wallets, password manager databases, private keys, source code and clipboard contents.","lessons":"Candidate exercises and any unvetted repository should be run only in a disposable sandbox with no access to corporate credentials, wallets or password vaults.","confidence":"Confirmed","sources":[{"title":"Contagious Interview: Malware delivered through fake developer job interviews","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"},{"title":"Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware","date":"2026-02","date_precision":"month","victim_org":"An unnamed cryptocurrency company executive","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Deepfake Video Call","secondary_vectors":["Tech Support Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.","records_affected":null,"threat_actor":"UNC1069 (DPRK), tracked by Mandiant since 2018","summary":"Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.","how_it_worked":"Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.","lessons":"No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.","confidence":"Confirmed","sources":[{"title":"North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam","url":"https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix","publisher":"The Record (Recorded Future News)"},{"title":"North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms","url":"https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"},{"title":"Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds","date":"2025-10-14","date_precision":"day","victim_org":"Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign)","sector":"Consumer","country":"Cambodia","primary_vector":"Romance / Investment Scam","secondary_vectors":["Fake Job Offer / Recruitment Lure","Smishing (SMS)"],"ai_involvement":"Unknown","ai_notes":"The indictment does not attribute the schemes to AI tooling, though contemporaneous reporting on the sector describes AI-assisted personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss"],"loss_usd":15000000000,"loss_note":"Approximately 127,271 bitcoin, worth roughly $15 billion at the time, were seized in what DOJ called its largest forfeiture action ever. This is the seizure value, not a per-victim loss total.","records_affected":null,"threat_actor":"Chen Zhi and the Prince Holding Group (indicted)","summary":"On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.","how_it_worked":"Workers inside the compounds contacted strangers through messaging apps and social media using fabricated personas, opening with an apparent wrong number or a friendly cold approach. Over weeks or months they built a personal relationship, often romantic, before introducing a cryptocurrency investment opportunity backed by a fake trading platform that displayed rising balances and permitted small early withdrawals to prove legitimacy. Victims were then pressed to deposit progressively larger sums, and any attempt to withdraw triggered demands for taxes or fees. The compound operators tracked which schemes ran from which rooms and logged the profits.","lessons":"Banks and exchanges need behavioural interdiction for customers making escalating transfers to newly seen crypto addresses after prolonged online-only relationships, since the victim will defend the transaction when asked directly.","confidence":"Reported","sources":[{"title":"Chairman of Prince Group Indicted for Operating Cambodian Forced Labor Scam Compounds","url":"https://www.justice.gov/opa/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged","publisher":"U.S. Department of Justice"},{"title":"U.S. and U.K. Take Largest Action Ever Targeting Cybercriminal Networks in Southeast Asia","url":"https://home.treasury.gov/news/press-releases/sb0278","publisher":"U.S. Department of the Treasury"}],"entry_type":"campaign","slug":"2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri","year":2025,"loss_kind":"seizure","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri"},{"title":"US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud","date":"2025-09-08","date_precision":"day","victim_org":"US, European and Chinese scam victims (multi-victim campaign)","sector":"Consumer","country":"Myanmar and Cambodia","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Romance / Investment Scam","Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"The sanctions announcement does not characterise AI use in the compounds' scam operations.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":10000000000,"loss_note":"Over $10 billion in losses to Americans was cited in connection with the announcement; this is a sector-wide aggregate, not a single-incident figure.","records_affected":null,"threat_actor":"Shwe Kokko / Yatai International Holdings Group network and Cambodian casino operators","summary":"On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.","how_it_worked":"The compounds are staffed by recruitment fraud. Thousands of people are lured with fake job offers, typically advertised as customer service, translation or IT work at attractive salaries in Thailand or Cambodia, then transported across borders, held against their will and forced to run scams targeting people in the United States, Europe and China. Inside, workers follow scripted romance and investment playbooks against assigned target lists, with quotas enforced by violence. The compound model industrialises social engineering: the recruitment lure supplies the labour, and the labour supplies the volume of romance and investment approaches.","lessons":"Because the front-line operators are themselves trafficking victims, effective controls sit upstream in sanctions, telecom and payment infrastructure rather than in prosecuting individual callers.","confidence":"Confirmed","sources":[{"title":"US sanctions companies behind cyber scam centers in Cambodia, Myanmar","url":"https://therecord.media/us-sanctions-companies-southeast-asia-scam-compounds","publisher":"The Record (Recorded Future News)"},{"title":"Myanmar Military Arrests Hundreds in Raid on Thai-Border Scam Center","url":"https://www.occrp.org/en/news/myanmar-military-arrests-hundreds-in-raid-on-thai-border-scam-center","publisher":"OCCRP"}],"entry_type":"campaign","slug":"2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la"},{"title":"North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs","date":"2025-08","date_precision":"month","victim_org":"US Fortune 500 technology companies employing fraudulent remote workers","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.","outcomes":["Insider Access","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Salaries paid to fraudulent workers fund DPRK weapons programmes; amounts not quantified in this report","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.","how_it_worked":"The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.","lessons":"Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"},{"title":"North Korean operatives adopt real-time deepfakes to pass remote job interviews","date":"2025-04","date_precision":"month","victim_org":"Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Deepfake Video Call","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.","how_it_worked":"The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.","lessons":"Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.","confidence":"Confirmed","sources":[{"title":"False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation","url":"https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/","publisher":"Palo Alto Networks Unit 42"},{"title":"North Korean Operatives Use Deepfakes in IT Job Interviews","url":"https://www.darkreading.com/remote-workforce/north-korean-operatives-deepfakes-it-job-interviews","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int"},{"title":"KnowBe4 hired a North Korean fake IT worker who loaded malware on day one","date":"2024-07-15","date_precision":"day","victim_org":"KnowBe4","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The candidate's profile photo was a stock image manipulated with AI to match a stolen US identity, and KnowBe4 described the persona as an AI deepfake that held up across four video interviews.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"No loss occurred. KnowBe4 stated no data was accessed and no systems were compromised.","records_affected":null,"threat_actor":"DPRK state-sponsored fake IT worker, confirmed with Mandiant and the FBI","summary":"Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.","how_it_worked":"The persona was assembled rather than invented: a real US person's identity supplied the details that background and reference checks validated, and a stock photograph enhanced with AI supplied a face consistent enough to survive four video calls. The shipping address was not a home but an IT mule laptop farm, so the corporate workstation arrived at a location that would keep it online in the US while the operative connected in by VPN from North Korea or nearby, working nights to match US hours. Within minutes of receipt the operative used a Raspberry Pi to download malware onto the workstation and began manipulating session history files. Challenged by the SOC, they claimed router troubleshooting, then went silent.","lessons":"Live identity verification against the government ID during interviews, plus device shipment to a verified address and endpoint monitoring that treats day-one activity as high-risk, are what turned this into a contained incident rather than a breach.","confidence":"Confirmed","sources":[{"title":"How a North Korean Fake IT Worker Tried to Infiltrate Us","url":"https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us","publisher":"KnowBe4"},{"title":"KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware","url":"https://www.securityweek.com/knowbe4-hires-fake-north-korean-it-worker-catches-new-employee-planting-malware/","publisher":"SecurityWeek"},{"title":"Cyber firm KnowBe4 hired a fake IT worker from North Korea","url":"https://cyberscoop.com/cyber-firm-knowbe4-hired-a-fake-it-worker-from-north-korea/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on"},{"title":"LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft","date":"2024-05","date_precision":"month","victim_org":"DMM Bitcoin, via wallet software vendor Ginco","sector":"Cryptocurrency","country":"Japan","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in the joint FBI, DC3 and NPA advisory.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":308000000,"loss_note":"4,502.9 BTC, valued at approximately $308 million in the joint FBI/DC3/NPA advisory; Japanese reporting at the time cited roughly $305 million. DMM Bitcoin subsequently wound down, transferring assets to SBI VC Trade.","records_affected":null,"threat_actor":"TraderTraitor (DPRK), per FBI, DC3 and Japan's National Police Agency","summary":"Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.","how_it_worked":"The recruiter pretext delivered a malicious Python script hosted on GitHub, framed as a pre-employment coding assessment. The Ginco employee copied the script into their own GitHub account to work on it, which handed the attacker access to session cookie data. Using those session cookies the attacker impersonated the employee and compromised Ginco's unencrypted internal communications system. From there they waited: in late May a DMM Bitcoin employee submitted a legitimate transaction request through Ginco's system, and the attacker altered it in flight so that the withdrawal, which carried valid authorisation from DMM's side, sent 4,502.9 BTC to attacker-controlled addresses.","lessons":"Take-home coding tasks must be isolated from corporate identity and never touched by an account with production session access, and transaction requests should be verified against an independent channel between exchange and custody vendor before signing.","confidence":"Confirmed","sources":[{"title":"FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com","url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom","publisher":"Federal Bureau of Investigation"},{"title":"FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin","url":"https://cryptoslate.com/fbi-reveals-north-korea-used-linkedin-to-steal-305-million-from-japans-dmm-bitcoin/","publisher":"CryptoSlate"}],"entry_type":"incident","slug":"2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t"},{"title":"Fake recruiter's coding test cost payment processor CoinsPaid $37M","date":"2023-07-22","date_precision":"day","victim_org":"CoinsPaid","sector":"Cryptocurrency","country":"Estonia","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":37000000,"loss_note":"CoinsPaid reported losses of over $37 million; company funds rather than customer funds bore the loss. Most of the proceeds were moved through SwftSwap.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), suspected by CoinsPaid","summary":"Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.","how_it_worked":"After direct infrastructure attacks failed, the operators changed target from the network to a person. Fake recruiters approached a CoinsPaid engineer over messaging and professional platforms with an offer well above market rate, then moved the conversation to an interview process. The 'technical task' the candidate was asked to run as part of that process was the payload. Running it on their working machine gave the attackers a foothold with the employee's credentials and access, from which they reached the infrastructure that authorised outbound transfers and drained more than $37 million. CoinsPaid noted the transaction patterns closely mirrored other Lazarus operations from the same period.","lessons":"Job-application code and take-home assessments must only ever run in a disposable, network-isolated VM, and recruiters approaching engineers with outsized offers should be treated as an active threat indicator, not an HR event.","confidence":"Reported","sources":[{"title":"CoinsPaid claims North Korean hacking group used fake job interview to steal $37M","url":"https://cointelegraph.com/news/coinspaid-claims-north-korean-hacking-group-fake-job-interview-theft","publisher":"Cointelegraph"},{"title":"The CoinsPaid Hack Explained","url":"https://coinspaid.com/company-updates/the-coinspaid-hack-explained/","publisher":"CoinsPaid"}],"entry_type":"incident","slug":"2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m"},{"slug":"2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d","title":"Dragos intrusion began with the hijacked personal email of an employee due to start work","date":"2023-05-08","date_precision":"day","year":2023,"victim_org":"Dragos","sector":"Technology","country":"United States","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"No ransom paid; Dragos refused to engage with the extortion attempt.","records_affected":null,"threat_actor":null,"summary":"Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.","how_it_worked":"The attacker targeted the gap that exists before a new hire's first day, when the person has an accepted offer but no corporate identity yet. Having taken over the recruit's personal email, the criminal completed the onboarding steps in their name, receiving credentials and access as the company believed it was equipping its own new starter. That produced legitimate access to onboarding-tier resources including SharePoint and a contract system. When ransomware deployment failed, the group escalated to personal pressure, contacting executives' private accounts and naming relatives to force negotiation. Dragos's SIEM alerts surfaced the activity and the account was blocked.","lessons":"Onboarding must verify identity through a channel independent of the address on the offer letter, and new-hire accounts should start with minimal access under heightened monitoring.","confidence":"Confirmed","sources":[{"title":"Deconstructing a Cybersecurity Event","url":"https://www.dragos.com/blog/deconstructing-a-cybersecurity-event","publisher":"Dragos"},{"title":"Cybersecurity firm Dragos discloses cybersecurity incident, extortion attempt","url":"https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d"},{"title":"Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF","date":"2022-03-23","date_precision":"day","victim_org":"Sky Mavis (Ronin Network / Axie Infinity)","sector":"Cryptocurrency","country":"Vietnam","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona and interview process were run by humans.","outcomes":["Cryptocurrency Theft"],"loss_usd":620000000,"loss_note":"173,600 ETH and 25.5 million USDC were drained; the value is commonly reported as roughly $540 million at the time of the hack and about $620-625 million at the time of disclosure, depending on the valuation date.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); sanctioned by the US Treasury in April 2022","summary":"On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.","how_it_worked":"Attackers posing as a non-existent company recruited a senior engineer over LinkedIn with an unusually generous compensation package, running a plausible multi-round interview process to build credibility. The final offer arrived as a PDF; downloading and opening it on a company machine executed spyware that gave the attackers a foothold in Sky Mavis systems. From there they obtained the private keys for four of the nine Ronin validator nodes, and used a still-active allowlist permission previously granted by Sky Mavis to the Axie DAO to obtain a fifth signature, reaching the five-of-nine threshold needed to authorise withdrawals from the bridge.","lessons":"Validator key material should live in hardware security modules on isolated machines that never render untrusted documents, and delegated signing permissions must expire automatically rather than persist after a temporary need ends.","confidence":"Confirmed","sources":[{"title":"How a fake job offer took down the world's most popular crypto game","url":"https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","publisher":"The Block"},{"title":"Hackers Used Fake Job Offer to Hack and Steal $540 Million from Axie Infinity","url":"https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","publisher":"The Hacker News"},{"title":"Spear Phishing Fake Job Offer Likely Behind Axie Infinity's Lazarus $600m Hack","url":"https://www.infosecurity-magazine.com/news/fake-job-offer-behind-axie/","publisher":"Infosecurity Magazine"},{"title":"Hackers stole $620 million from Axie Infinity via fake job interviews","url":"https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake-job-interviews/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf"},{"title":"Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge","date":"2022","date_precision":"year","victim_org":"Unnamed aerospace company in Spain","sector":"Defense","country":"Spain","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona was operated manually over LinkedIn Messaging.","outcomes":["Espionage","Data Breach"],"loss_usd":null,"loss_note":"No financial loss reported; the objective was espionage.","records_affected":null,"threat_actor":"Lazarus Group (North Korea), Operation Dream Job","summary":"ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.","how_it_worked":"A fake recruiter contacted employees through LinkedIn Messaging claiming to be running a Meta hiring process. The candidate was sent two supposed C++ programming tests, Quiz1.exe and Quiz2.exe, packaged inside ISO images hosted on cloud storage; one printed 'Hello, World!' and the other computed Fibonacci numbers, so the tasks appeared genuine. Running them side-loaded a malicious DLL that installed the NickelLoader downloader, which fetched miniBlindingCan and LightlessCan. LightlessCan supports up to 68 commands and reimplements many Windows utilities internally rather than spawning visible processes, reducing the telemetry available to endpoint monitoring during the espionage phase.","lessons":"Recruitment materials should never be executed on corporate endpoints; disposable virtual machines for candidate exercises plus application allow-listing eliminate this entire vector.","confidence":"Confirmed","sources":[{"title":"Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company","url":"https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/","publisher":"ESET WeLiveSecurity"},{"title":"North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain","url":"https://www.eset.com/us/about/newsroom/press-releases/north-korea-linked-lazarus-impersonates-meta-on-linkedin-to-attack-an-aerospace-company-in-spain/","publisher":"ESET"},{"title":"Lazarus hackers breach aerospace firm with new LightlessCan malware","url":"https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding"},{"title":"FTC data: $147.8M in gift card fraud driven by government and business impersonators","date":"2021-12-08","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam","Romance / Investment Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement described.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":147800000,"loss_note":"$147.8 million reported lost across 39,263 gift card fraud reports in the first nine months of 2021. Government impersonation accounted for 7,844 reports and $39.6 million; business impersonation for 12,239 reports and $35.5 million.","records_affected":39263,"threat_actor":null,"summary":"An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.","how_it_worked":"A caller impersonating the Social Security Administration, another government agency, or a business such as Amazon or Apple tells the victim that money is owed or that an account has been compromised, and instructs them to resolve it immediately by buying gift cards at a nearby retailer. The victim is kept on the phone throughout the drive and the purchase, which prevents consultation with anyone and lets the scammer coach them past cashier questions with a cover story about buying gifts. At the register the victim reads the card numbers and PINs aloud over the phone, and the value is drained within minutes. Gift cards are attractive because they are irreversible and untraceable.","lessons":"Retail checkout interdiction, where staff are trained and empowered to stop high-value gift card purchases by customers on the phone, is the single highest-yield control at the point of loss.","confidence":"Confirmed","sources":[{"title":"Scammers prefer gift cards, but not just any card will do","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2021/12/scammers-prefer-gift-cards-not-just-any-card-will-do","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp","year":2021,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp"},{"title":"Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails","date":"2016-02","date_precision":"month","victim_org":"Bangladesh Bank (central bank of Bangladesh)","sector":"Financial Services","country":"Bangladesh","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss","Service Disruption"],"loss_usd":81000000,"loss_note":"$101 million in fraudulent SWIFT transfers were executed, of which $81 million reached accounts in the Philippines and about $20 million sent to Sri Lanka was blocked; a portion of the Philippine funds was later recovered, leaving roughly $65 million outstanding.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); US DOJ charged Park Jin Hyok in 2018","summary":"In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.","how_it_worked":"Emails from a fabricated job-seeker persona were sent to Bangladesh Bank employees with a link to a résumé hosted externally; retrieving it delivered malware that established remote access. The attackers dwelled for about a year, mapping the bank's network and the workstation used for SWIFT Alliance Access. They then deployed custom malware that manipulated the SWIFT client's database and print output so fraudulent messages would not appear on the confirmation printer, issued transfer instructions to the New York Fed over a weekend, and routed proceeds through Philippine bank accounts and casino junkets to launder them.","lessons":"Isolating the SWIFT terminal on its own segment with application allow-listing, and independent reconciliation of outbound payment messages, would have caught both the intrusion path and the tampered confirmations.","confidence":"Reported","sources":[{"title":"Hackers took years before stealing $81m from Bangladesh Bank: FBI","url":"https://www.newagebd.net/print/article/141463","publisher":"New Age Bangladesh"},{"title":"When North Korean hackers almost pulled off a billion-dollar heist from Bangladesh Bank","url":"https://www.thedailystar.net/tech-startup/news/when-north-korean-hackers-almost-pulled-billion-dollar-heist-bangladesh-bank-2115317","publisher":"The Daily Star"},{"title":"Lessons Learned From the Bangladesh Bank Heist","url":"https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/lessons-learned-from-the-bangladesh-bank-heist","publisher":"ISACA Journal"}],"entry_type":"incident","slug":"2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin"}]}