{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:30.821Z","total":44,"returned":44,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks","date":"2026-08-06","date_precision":"day","victim_org":"Point72, Millennium Management, Two Sigma, Citadel and private-equity firms","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.","outcomes":["Attempt Blocked","Extortion","Credential Theft"],"loss_usd":10600000,"loss_note":"Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.","records_affected":null,"threat_actor":"UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon","summary":"BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.","how_it_worked":"Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.","lessons":"Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.","confidence":"Confirmed","sources":[{"title":"Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group","url":"https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at","year":2026,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"},{"title":"Apollo Global Management breached by BlackFile callers posing as IT support","date":"2026-07-06","date_precision":"day","victim_org":"Apollo Global Management","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Researchers described a large pool of human callers recruited for small fees rather than synthetic voice.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"Apollo did not disclose a figure; researchers said BlackFile typically opens around $3 million and settles under $1 million.","records_affected":null,"threat_actor":"BlackFile (tracked by Google as UNC6671), part of The Com, operating the Redact, Pink, Helix and Falcon extortion brands","summary":"Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.","how_it_worked":"BlackFile industrialised the phone call. Researchers describe hundreds of callers, often low-level people recruited for a small fee or for standing within the group, dialling employees while impersonating internal IT support until one target complies. Volume replaces finesse: the crew averages about 1.5 new victims a day and has hit private equity firms, law firms, ratings agencies and medical technology companies. Once an identity is obtained the operators move into cloud platforms and collect data for extortion, escalating with threatening messages and swatting when victims resist.","lessons":"Phishing-resistant MFA plus a strict no-credentials-over-the-phone policy blunts high-volume calling, and cloud data stores need export alerting because these crews steal rather than encrypt.","confidence":"Confirmed","sources":[{"title":"Apollo discloses data breach from ongoing wave of attacks hitting financial sector","url":"https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/","publisher":"CyberScoop"},{"title":"Details emerge on BlackFile's recent attacks on financial companies","url":"https://cyberscoop.com/blackfile-cyberattacks-financial-sector/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"},{"slug":"2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials","title":"MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices","date":"2026-05-06","date_precision":"day","year":2026,"victim_org":"Multiple organisations in the United States and MENA (unnamed)","sector":"Manufacturing","country":"United States and Middle East / North Africa","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"MuddyWater (Seedworm), assessed as linked to Iran's Ministry of Intelligence and Security, operating behind Chaos ransomware branding","summary":"Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.","how_it_worked":"The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.","lessons":"Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.","confidence":"Reported","sources":[{"title":"Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware","url":"https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/","publisher":"Rapid7 Labs"},{"title":"MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack","url":"https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"},{"slug":"2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat","title":"UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services","sector":"Other","country":"Global","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":10600000,"loss_kind":"criminal_proceeds","loss_note":"USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.","records_affected":null,"threat_actor":"UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)","summary":"Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.","how_it_worked":"Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.","lessons":"Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.","confidence":"Confirmed","sources":[{"title":"Vishing Extortion Group UNC6671 Rebrands After Making Millions","url":"https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/","publisher":"SecurityWeek"},{"title":"UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data","url":"https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},{"title":"Workday discloses CRM breach after social engineering of employees","date":"2025-08-06","date_precision":"day","victim_org":"Workday","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign","summary":"Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.","how_it_worked":"Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.","lessons":"Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.","confidence":"Confirmed","sources":[{"title":"Workday hit by social engineering data breach targeting its CRM platform","url":"https://therecord.media/workday-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Human resources firm Workday disclosed a data breach","url":"https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-workday-discloses-crm-breach-after-social-engineering-of-employees","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"title":"Qantas contact centre platform breached after help desk tricked into adding MFA","date":"2025-07-01","date_precision":"day","victim_org":"Qantas Airways","sector":"Transportation & Logistics","country":"Australia","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.","records_affected":5700000,"threat_actor":"Scattered Spider / Muddled Libra (reported)","summary":"Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.","how_it_worked":"The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.","lessons":"Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.","confidence":"Confirmed","sources":[{"title":"Qantas data breach impacted 5.7 million individuals","url":"https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html","publisher":"Security Affairs"},{"title":"Qantas confirms customer data breach amid Scattered Spider attacks","url":"https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html","publisher":"Security Affairs"},{"title":"Update on Qantas cyber incident: Wednesday 9 July 2025","url":"https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025","publisher":"Qantas Newsroom"},{"title":"Tech support scam caused massive data breach at Australian airline Qantas","url":"https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267","publisher":"The Register"}],"entry_type":"incident","slug":"2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"},{"slug":"2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d","title":"Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware","date":"2025-07","date_precision":"month","year":2025,"victim_org":"US retail, airline, transportation and insurance organisations","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC3944 / Scattered Spider","summary":"Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.","how_it_worked":"Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.","lessons":"Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.","confidence":"Confirmed","sources":[{"title":"Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure","url":"https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html","publisher":"The Hacker News"},{"title":"Scattered Spider targets VMware ESXi using social engineering","url":"https://securityaffairs.com/180466/cyber-crime/scattered-spider-targets-vmware-esxi-in-using-social-engineering/","publisher":"Security Affairs"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d"},{"title":"Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector","date":"2025-06-26","date_precision":"day","victim_org":"Hawaiian Airlines","sector":"Transportation & Logistics","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported in this intrusion.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944 / Muddled Libra)","summary":"Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.","how_it_worked":"Scattered Spider's standard aviation playbook is to impersonate an employee or contractor in a call to the IT help desk and persuade the agent to reset credentials or enrol a new authenticator. The group also registers unauthorised devices against compromised accounts as a way of defeating multi-factor authentication, so that later logins look legitimate. Because airlines run large outsourced service desks covering shift workers and contractors around the clock, a caller claiming to be locked out mid-shift is a routine and hard-to-challenge request.","lessons":"Strict, scripted caller-verification for account recovery and alerting on new device registrations against existing accounts are the controls that surface this pattern early.","confidence":"Reported","sources":[{"title":"Scattered Spider appears to pivot toward aviation sector","url":"https://www.cybersecuritydive.com/news/scattered-spider-appears-to-pivot-toward-aviation-sector/751917/","publisher":"Cybersecurity Dive"}],"entry_type":"incident","slug":"2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector"},{"slug":"2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password","title":"WestJet breach of 1.2 million passengers began with a help desk password reset","date":"2025-06-13","date_precision":"day","year":2025,"victim_org":"WestJet","sector":"Transportation & Logistics","country":"Canada","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1200000,"threat_actor":null,"summary":"Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.","how_it_worked":"The attackers used social engineering to have an employee's password reset, then signed in to the corporate network through Citrix. The pretext was that of a legitimate employee locked out of their account, and the identity impersonated was a staff member whose details had been researched beforehand. The trust signal abused was the help desk's willingness to restore access on the strength of knowledge-based answers, and the pressure applied was a worker unable to do their job. From that foothold the intruders moved into the Windows domain and Microsoft cloud tenant and exfiltrated passenger records over several days before detection.","lessons":"Identity-proofing at the service desk, using video verification or a manager-approved out-of-band challenge before any password or MFA reset, is the single control that would have stopped this.","confidence":"Confirmed","sources":[{"title":"WestJet data breach exposes travel details of 1.2 million customers","url":"https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/","publisher":"BleepingComputer"},{"title":"Data breach at Canadian airline WestJet affects 1.2M passengers","url":"https://techcrunch.com/2025/10/01/data-breach-at-canadian-airline-westjet-affects-1-2m-passengers/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password"},{"title":"Aflac breached in insurance-sector social engineering campaign; 22.6M affected","date":"2025-06-12","date_precision":"day","victim_org":"Aflac","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No public reporting attributes AI-generated voice to the Aflac intrusion.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed; Aflac offered 24 months of credit monitoring, identity theft and medical fraud protection.","records_affected":22650000,"threat_actor":"Not confirmed by Aflac; reporting points to Scattered Spider's 2025 insurance-sector campaign","summary":"Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.","how_it_worked":"Aflac has not published the intrusion mechanics beyond describing a sophisticated cybercrime group and an industry-wide campaign, so the vector here is characterised from the campaign rather than from Aflac's own disclosure. Google Threat Intelligence, warning insurers during the same weeks, told the sector to pay particular attention to social engineering attempts against help desks and call centres, the route the same crews had used against retail and hospitality: a phone call impersonating staff to obtain credential or MFA resets, then rapid data collection with no malware deployed.","lessons":"Identity verification standards for help desks and call centres, applied to both employee and customer channels, is the control the sector was explicitly warned to strengthen.","confidence":"Confirmed","sources":[{"title":"Aflac discloses breach amidst Scattered Spider insurance attacks","url":"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/","publisher":"BleepingComputer"},{"title":"22M Affected by Aflac Data Breach","url":"https://www.securityweek.com/22-million-affected-by-aflac-data-breach/","publisher":"SecurityWeek"},{"title":"Aflac confirms June data breach affecting over 22 million customers","url":"https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html","publisher":"Security Affairs"},{"title":"Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised","url":"https://www.hipaajournal.com/aflac-data-breach/","publisher":"The HIPAA Journal"},{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff"},{"title":"UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app","date":"2025-06-04","date_precision":"day","victim_org":"Approximately 20 Salesforce customer organisations, later including Google","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"No aggregate loss figure; extortion demands followed the intrusions by several months.","records_affected":null,"threat_actor":"UNC6040, with extortion branded as ShinyHunters (UNC6240)","summary":"Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.","how_it_worked":"The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.","lessons":"Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.","confidence":"Confirmed","sources":[{"title":"Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App","url":"https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"},{"title":"Google's own Salesforce instance hit by UNC6040 IT-support vishing","date":"2025-06","date_precision":"month","victim_org":"Google","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.","records_affected":null,"threat_actor":"UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'","summary":"Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.","how_it_worked":"Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.","lessons":"Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.","confidence":"Confirmed","sources":[{"title":"Salesforce customers duped by series of social-engineering attacks","url":"https://cyberscoop.com/google-unc6040-salesforce-attacks/","publisher":"CyberScoop"},{"title":"Google confirms Salesforce CRM breach, faces extortion threat","url":"https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html","publisher":"Security Affairs"},{"title":"FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups","url":"https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html","publisher":"Security Affairs"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"},{"title":"ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications","url":"https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications","publisher":"EclecticIQ"}],"entry_type":"incident","slug":"2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"},{"title":"Erie Insurance hit in Scattered Spider help desk campaign against insurers","date":"2025-06","date_precision":"month","victim_org":"Erie Insurance","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.","how_it_worked":"The intrusion set relied on service-desk manipulation rather than exploitation. An operator called the help desk holding enough identifying information to impersonate a named employee, asked for an MFA enrolment link to be issued for a supposed new mobile device, and once that device was trusted, used self-service password reset to seize the account outright. Researchers noted the technique was effective across multiple insurers precisely because help desks follow an identical procedure no matter who calls, so a single credible pretext worked repeatedly.","lessons":"Identity proofing that a caller cannot supply from public or previously breached data, such as manager callback or a live video ID check, is the control that breaks this chain.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure"},{"title":"Philadelphia Insurance Companies disclosed breach in insurer-focused campaign","date":"2025-06","date_precision":"month","victim_org":"Philadelphia Insurance Companies","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.","how_it_worked":"Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.","lessons":"Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"},{"title":"Bribed overseas support agents leaked Coinbase data; $20M extortion refused","date":"2025-05-15","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in Coinbase's disclosure.","outcomes":["Data Breach","Extortion","Insider Access","Cryptocurrency Theft","Identity Theft"],"loss_usd":null,"loss_note":"Coinbase refused the $20 million demand and instead established a $20 million reward fund for information leading to arrests. Aggregate customer losses from the resulting social engineering were not quantified in the disclosure.","records_affected":69461,"threat_actor":"Unattributed extortion group","summary":"Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.","how_it_worked":"The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.","lessons":"Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.","confidence":"Confirmed","sources":[{"title":"Protecting Our Customers - Standing Up to Extortionists","url":"https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists","publisher":"Coinbase"},{"title":"Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails","url":"https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html","publisher":"The Hacker News"},{"title":"Coinbase confirms insiders handed over data of 70K users","url":"https://www.theregister.com/2025/05/21/coinbase_confirms_insider_breach_affects/","publisher":"The Register"}],"entry_type":"incident","slug":"2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse"},{"title":"Harrods restricts internet access after intrusion attempts in UK retail wave","date":"2025-05-01","date_precision":"day","victim_org":"Harrods","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"Harrods disclosed no technical detail, so no assessment of AI involvement is possible.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.","how_it_worked":"Harrods has never described the mechanics, so the entry attempt is characterised here only by the campaign it belonged to. The wave that hit UK retail in April and May 2025 was driven by English-speaking crews who phoned retailer service desks impersonating staff to obtain password and MFA resets, then escalated inside the identity provider. Harrods' response, cutting external internet access at sites while investigating, is consistent with defending against credential-based lateral movement rather than a software exploit, but the company has confirmed nothing further.","lessons":"Fast containment helped here, but the durable control against this campaign is out-of-band identity proofing before any help desk credential or MFA reset.","confidence":"Alleged","sources":[{"title":"Luxury department store Harrods suffered a cyberattack","url":"https://securityaffairs.com/177330/cyber-crime/luxury-department-store-harrods-suffered-a-cyberattack.html","publisher":"Security Affairs"},{"title":"Harrods alerts customers to new data breach linked to third-party provider","url":"https://securityaffairs.com/182752/data-breach/harrods-alerts-customers-to-new-data-breach-linked-to-third-party-provider.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail"},{"title":"FBI warns Silent Ransom Group is callback-phishing US law firms","date":"2025-05","date_precision":"month","victim_org":"US law firms and legal services organisations (campaign)","sector":"Legal","country":"United States","primary_vector":"Callback Phishing (TOAD)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the FBI advisory.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the group extorts victims after data theft without deploying encryption.","records_affected":null,"threat_actor":"Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, UNC3753)","summary":"The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.","how_it_worked":"The primary lure is a telephone-oriented attack delivery email: a message claims a small subscription has been renewed and will be charged unless the recipient calls a number to cancel. There is no link or attachment, so the mail passes gateway filtering. When the victim calls, the operator, posing as support, directs them to a website and has them install a legitimate remote access utility such as Zoho Assist, Syncro, AnyDesk, SuperOps or Atera. The group has also skipped the email entirely and simply telephoned employees claiming to be the firm's own IT department with an after-hours maintenance request. Once connected, the operators escalate where possible, use tools such as WinSCP or Rclone to exfiltrate documents, then extort the firm by threatening publication on a leak site.","lessons":"Application control that blocks unapproved remote access tools is the decisive check here, since the email carries no malicious payload for a gateway to catch; staff also need a verified internal number for IT so an unexpected support call can be refused.","confidence":"Confirmed","sources":[{"title":"FBI warns of Luna Moth extortion attacks targeting law firms","url":"https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/","publisher":"BleepingComputer"},{"title":"Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign","url":"https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html","publisher":"The Hacker News"},{"title":"FBI warns of cybercriminals impersonating IT staff to breach law firms","url":"https://www.floridabar.org/the-florida-bar-news/fbi-warns-of-cybercriminals-impersonating-it-staff-to-breach-law-firms/","publisher":"The Florida Bar"}],"entry_type":"campaign","slug":"2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms"},{"title":"Marks & Spencer attack tied to social engineering of outsourced service desk","date":"2025-04-22","date_precision":"day","victim_org":"Marks & Spencer Group plc","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vendor / Supply Chain Impersonation","Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":null,"loss_note":"M&S publicly guided to a hit of around £300 million to operating profit before mitigation; no USD figure is asserted here.","records_affected":null,"threat_actor":"Scattered Spider, deploying DragonForce ransomware","summary":"Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.","how_it_worked":"Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.","lessons":"Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.","confidence":"Confirmed","sources":[{"title":"M&S hackers gained access through third-party Tata Consulting Services, sources say","url":"https://cybernews.com/news/marks-spencer-hackers-used-employee-login-tsc-tata-consulting-scattered-spider/","publisher":"Cybernews"},{"title":"M&S confirms month-long breach result of third-party vendor phishing attack","url":"https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/","publisher":"Cybernews"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Marks and Spencer confirms data breach after April cyber attack","url":"https://securityaffairs.com/177784/data-breach/marks-and-spencer-confirms-data-breach-after-april-cyber-attack.html","publisher":"Security Affairs"},{"title":"Marks & Spencer breach linked to Scattered Spider ransomware attack","url":"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de"},{"title":"Co-op loses £206m of revenue and 6.5 million members' data to DragonForce","date":"2025-04","date_precision":"month","victim_org":"Co-operative Group","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Service Disruption","Extortion"],"loss_usd":275000000,"loss_note":"Co-op reported a £206 million revenue loss, roughly $275 million, driven by weeks of food supply disruption.","records_affected":6500000,"threat_actor":"DragonForce, with Scattered Spider-aligned English-speaking affiliates; four people aged 17 to 20 were arrested by the UK NCA in July 2025","summary":"The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.","how_it_worked":"Co-op's account of the intrusion, given publicly by its leadership, is that the attackers impersonated an employee convincingly enough to have that employee's password reset, then used the re-issued credentials to enter the network. The Teams messages and follow-up phone calls to security staff show the same crew comfortable operating in the victim's own collaboration tools, negotiating and pressuring in real time. Co-op's decision to pull systems down aggressively contained the intrusion before encryption, which is why the damage landed as lost revenue and stolen data rather than ransomware.","lessons":"Caller verification at the service desk, and separate approval paths for resets on high-privilege accounts, would have removed the single conversation that granted access.","confidence":"Confirmed","sources":[{"title":"Cyberattack on Co-op leaves shelves empty, data stolen, and $275M in lost revenue","url":"https://securityaffairs.com/182713/security/cyberattack-on-co-op-leaves-shelves-empty-data-stolen-and-275m-in-lost-revenue.html","publisher":"Security Affairs"},{"title":"DragonForce group claims the theft of data after Co-op cyberattack","url":"https://securityaffairs.com/177376/cyber-crime/dragonforce-group-claims-the-theft-of-data-after-co-op-cyberattack.html","publisher":"Security Affairs"},{"title":"Data of all 6.5 million Co-op members stolen - CEO says she is 'incredibly sorry'","url":"https://www.techradar.com/pro/security/data-of-all-6-5-million-coop-members-stolen-ceo-is-incredibly-sorry","publisher":"TechRadar Pro"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce","year":2025,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce"},{"title":"Transport for London hit by Scattered Spider teens in a £29m intrusion","date":"2024-09-01","date_precision":"day","victim_org":"Transport for London","sector":"Transportation & Logistics","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Service Disruption","Data Breach","Credential Theft"],"loss_usd":39000000,"loss_note":"TfL put the cost at about £29 million (roughly $39 million); prosecutors said a complete shutdown could have caused up to £56 billion of economic damage.","records_affected":null,"threat_actor":"Scattered Spider; Thalha Jubair and Owen Flowers were each sentenced to five and a half years in July 2026","summary":"Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.","how_it_worked":"TfL has not published the entry vector, and the prosecution described Scattered Spider's general reliance on phone, email and SMS social engineering rather than a specific script for this intrusion. What the response reveals is the assumption TfL made about the attackers' capability: the organisation judged that remote password resets could themselves be abused, and required roughly 27,000 staff to attend in person with identity documents to re-establish credentials. That is the signature countermeasure to help-desk impersonation, adopted precisely because remote identity proofing could no longer be trusted.","lessons":"In-person or strongly verified credential re-issuance for staff, and phishing-resistant MFA for remote administrative access, are the controls TfL was forced to adopt reactively.","confidence":"Reported","sources":[{"title":"Transport for London (TfL) is dealing with an ongoing cyberattack","url":"https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html","publisher":"Security Affairs"},{"title":"Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack","url":"https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion","year":2024,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion"},{"title":"Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin","date":"2024-08-19","date_precision":"day","victim_org":"An individual Genesis creditor in Washington, D.C.","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning or synthetic media was reported; the callers used spoofed caller ID and live pretexting.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss"],"loss_usd":243000000,"loss_note":"4,064 BTC, worth approximately $243 million at the time. More than $9 million was subsequently frozen and about $500,000 returned to the victim.","records_affected":null,"threat_actor":"Malone Lam ('Greavys'), Jeandiel Serrano ('VersaceGod') and co-conspirators","summary":"On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.","how_it_worked":"The crew opened with a spoofed call presenting as Google support warning of unauthorised account access, which established urgency and a reason for the victim to accept further contact. A second set of callers then posed as Gemini support and walked the victim through resetting the two-factor authentication on the exchange account. Under the guise of remediation, they had the victim install AnyDesk and share their screen, at which point the attackers were able to see private keys held in the victim's Bitcoin Core wallet and to direct transfers to a wallet they controlled. Funds were then split across many wallets and pushed through more than fifteen exchanges. The crew's spending on cars, watches and designer goods exposed an address that let investigators freeze over $9 million.","lessons":"No legitimate provider initiates a call asking you to reset MFA or install remote-desktop software; hanging up and calling back on a number obtained independently is the single control that defeats this entire sequence.","confidence":"Reported","sources":[{"title":"Police Arrest Two People Related to $243M Crypto Heist Targeting Genesis Creditor","url":"https://www.coindesk.com/business/2024/09/19/police-arrests-two-people-related-to-243m-crypto-heist-targeting-genesis-creditor","publisher":"CoinDesk"},{"title":"Hackers Posed as Google Support to Steal $243 Million in Crypto","url":"https://hackread.com/hackers-posed-google-support-steal-243m-crypto/","publisher":"Hackread"}],"entry_type":"incident","slug":"2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit"},{"title":"Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta","date":"2024-05-15","date_precision":"day","victim_org":"Multiple organisations (campaign)","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Tech Support Scam","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"Microsoft reported live human callers, not synthetic voice.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published for the campaign.","records_affected":null,"threat_actor":"Storm-1811, deploying Black Basta ransomware","summary":"Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.","how_it_worked":"The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.","lessons":"Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.","confidence":"Confirmed","sources":[{"title":"Threat actors misusing Quick Assist in social engineering attacks leading to ransomware","url":"https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/","publisher":"Microsoft Security Blog"},{"title":"Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing","url":"https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing","publisher":"Sophos"},{"title":"Windows Quick Assist Anchors Black Basta Ransomware Gambit","url":"https://www.darkreading.com/threat-intelligence/windows-quick-assist-anchors-black-basta-ransomware","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"},{"title":"MGM Resorts shut down for ten days after a help desk social engineering call","date":"2023-09-11","date_precision":"day","victim_org":"MGM Resorts International","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI or voice cloning was reported; the reported method was a live human call using details gathered from public professional profiles.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":110000000,"loss_note":"MGM reported roughly $100 million of negative impact to Las Vegas and regional operations' adjusted property earnings plus under $10 million of one-time costs; a $45 million class settlement covering this and an earlier breach was approved later.","records_affected":null,"threat_actor":"Scattered Spider, an affiliate of ALPHV/BlackCat","summary":"MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.","how_it_worked":"MGM has never published the entry point, but the widely reported account, consistent with the CISA advisory and Okta's contemporaneous warning, is that the crew identified an MGM employee from a public professional profile, gathered enough personal and organisational detail to pass as them, and phoned the IT help desk to obtain a credential and MFA reset in a call reported to have lasted about ten minutes. With a legitimate identity re-issued to them, the actors escalated inside the identity provider and, after exfiltration, deployed ransomware against virtualisation infrastructure.","lessons":"High-privilege credential and MFA resets should never be grantable on a single inbound phone call; out-of-band verification with a known manager or video identity check would have cost the caller the whole operation.","confidence":"Reported","sources":[{"title":"Ransomware attack on MGM Resorts costs $110 Million","url":"https://securityaffairs.com/152077/cyber-crime/mgm-resorts-ransomware-attack.html","publisher":"Security Affairs"},{"title":"MGM Resorts confirms hackers stole customers' personal data during cyberattack","url":"https://techcrunch.com/2023/10/06/mgm-resorts-admits-hackers-stole-customers-personal-data-cyberattack/","publisher":"TechCrunch"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"},{"title":"A full timeline of the MGM Resorts cyber attack","url":"https://www.cshub.com/attacks/news/a-full-timeline-of-the-mgm-resorts-cyber-attack","publisher":"Cyber Security Hub"}],"entry_type":"incident","slug":"2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering"},{"title":"Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee","date":"2023-08-27","date_precision":"day","victim_org":"Retool","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Voice Clone / Audio Deepfake","Vishing (Voice Phishing)","Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Retool stated the caller used a deepfaked voice imitating a specific member of its IT team, whom the target employee knew. This is one of the earliest well-documented uses of voice cloning in a corporate intrusion.","outcomes":["Data Breach","Cryptocurrency Theft","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Retool reported no loss of its own; downstream, cryptocurrency customer Fortress Trust separately reported a theft of roughly $15 million tied to the compromise, a figure attributed to Fortress Trust rather than confirmed by Retool.","records_affected":27,"threat_actor":null,"summary":"Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.","how_it_worked":"The employee received a text claiming to be from Retool IT about a payroll and healthcare enrolment issue, with a link to a page cloning the company's internal identity portal. After the employee submitted credentials and an MFA code, the attacker phoned them; the voice was a deepfake of a specific IT team member the employee recognised, and the caller was familiar with office layout, colleagues and internal processes. During the call the employee provided an additional MFA code, which let the attacker add their own device to the employee's Okta account. From there they reached the employee's Google account, where Authenticator's cloud sync had backed up OTP seeds, and used those to pivot into internal admin systems and alter customer accounts.","lessons":"Voice is no longer an identity proof; hardware security keys plus a policy that MFA codes are never read aloud, and disabling authenticator cloud sync on enterprise accounts, close both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Retool blames breach on Google Authenticator MFA cloud sync feature","url":"https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/","publisher":"BleepingComputer"},{"title":"Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients","url":"https://thehackernews.com/2023/09/retool-falls-victim-to-sms-based.html","publisher":"The Hacker News"},{"title":"Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks","url":"https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/","publisher":"SecurityWeek"},{"title":"When MFA isn't actually MFA","url":"https://retool.com/blog/mfa-isnt-mfa","publisher":"Retool"}],"entry_type":"incident","slug":"2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp"},{"slug":"2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da","title":"SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data","date":"2023-08-19","date_precision":"day","year":2023,"victim_org":"Kroll","sector":"Professional Services","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.","how_it_worked":"The attacker convinced T-Mobile to port a Kroll employee's number to a SIM they controlled, a transfer carried out by a mobile carrier representative acting on a fraudulent request. Once the number was theirs, SMS-based authentication codes for the employee's accounts arrived on the attacker's device, letting them reset access and reach the claimant files Kroll held as bankruptcy administrator. The victims were bankrupt crypto platforms' creditors, a population whose names and contact details are immediately monetisable through targeted phishing about their claims, and several such phishing waves followed the breach.","lessons":"Remove SMS from the authentication path entirely for staff handling sensitive data, and place carrier-level port-out locks on corporate mobile numbers.","confidence":"Confirmed","sources":[{"title":"Kroll Employee SIM-Swapped for Crypto Investor Data","url":"https://krebsonsecurity.com/2023/08/kroll-employee-sim-swapped-for-crypto-investor-data/","publisher":"Krebs on Security"},{"title":"T-Mobile SIM-swapping attack on Kroll employee caused crypto platform data breach","url":"https://therecord.media/sim-swap-attack-caused-crypto-breach","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da"},{"title":"Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered","date":"2023-08-18","date_precision":"day","victim_org":"Caesars Entertainment","sector":"Gaming & Casino","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Help Desk Impersonation","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Wire Fraud / Financial Loss"],"loss_usd":15000000,"loss_note":"Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.","records_affected":null,"threat_actor":"Scattered Spider, reportedly working with ALPHV/BlackCat","summary":"Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.","how_it_worked":"Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.","lessons":"Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.","confidence":"Confirmed","sources":[{"title":"Caesars Entertainment says social-engineering attack behind August breach","url":"https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/","publisher":"Cybersecurity Dive"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"incident","slug":"2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially","year":2023,"loss_kind":"ransom_paid","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"},{"title":"Clorox attack traced to help desk agents resetting passwords without verification","date":"2023-08-11","date_precision":"day","victim_org":"The Clorox Company","sector":"Manufacturing","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the complaint describes live phone calls.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":380000000,"loss_note":"$380 million is the total damages Clorox sought in its 2025 lawsuit against Cognizant, including about $49 million in direct remediation costs; it is a litigation claim, not an adjudicated loss.","records_affected":null,"threat_actor":"Scattered Spider","summary":"Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.","how_it_worked":"According to the complaint, the attacker called the Cognizant-run service desk multiple times claiming to be a Clorox employee and asked for a password reset. The agent reset the credential and the multifactor enrolment without confirming the caller's identity, and transcripts quoted in the filing show no verification step took place. The attacker used the same technique against a Clorox IT security employee, which yielded privileged network access. From there the intrusion progressed to network-wide disruption; Clorox took systems offline, reverted to manual order processing, and saw sales and shipments fall for months afterwards.","lessons":"Outsourced service desks need contractually mandated, auditable identity proofing before any credential or MFA reset, with higher-assurance checks for accounts holding privileged access.","confidence":"Confirmed","sources":[{"title":"Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit","url":"https://www.bleepingcomputer.com/news/security/hackers-fooled-cognizant-help-desk-says-clorox-in-380m-cyberattack-lawsuit/","publisher":"BleepingComputer"},{"title":"Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack","url":"https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor","publisher":"The Record"},{"title":"Clorox files $380 million suit blaming Cognizant for 2023 cyberattack","url":"https://www.cybersecuritydive.com/news/clorox-380-million-suit-cognizant-cyberattack/753837/","publisher":"Cybersecurity Dive"},{"title":"$380M lawsuit: intruder got Clorox's passwords from Cognizant simply by asking","url":"https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/","publisher":"The Register"},{"title":"Clorox estimates the costs of the August cyberattack will exceed $49 Million","url":"https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver"},{"title":"Okta warns of a coordinated campaign against US customers' IT service desks","date":"2023-08","date_precision":"month","victim_org":"Multiple US-based Okta customer organizations","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in Okta's advisory.","outcomes":["Credential Theft","Data Breach","Insider Access"],"loss_usd":null,"loss_note":"Okta did not name victims or quantify losses in this advisory.","records_affected":null,"threat_actor":"Actor consistent with Scattered Spider / Muddled Libra (unnamed in the advisory)","summary":"Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.","how_it_worked":"The caller arrived already holding something: either the password to a privileged account or the ability to manipulate delegated authentication. That partial knowledge is what makes the help desk call succeed, because the agent hears a caller who knows their own username, manager and internal jargon, and treats an MFA reset as routine. Once the factors were reset the actor enrolled their own, signed in from anonymising proxies on unfamiliar devices, escalated to Super Administrator and stood up a second identity provider so they could impersonate arbitrary users through federation.","lessons":"Identity-proofing the caller out of band, such as manager attestation or video verification, plus admin-console policies that require phishing-resistant factors and known devices, breaks the reset-to-takeover chain.","confidence":"Confirmed","sources":[{"title":"Cross-Tenant Impersonation: Prevention and Detection","url":"https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/","publisher":"Okta Security"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"campaign","slug":"2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des"},{"slug":"2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d","title":"Dragos intrusion began with the hijacked personal email of an employee due to start work","date":"2023-05-08","date_precision":"day","year":2023,"victim_org":"Dragos","sector":"Technology","country":"United States","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"No ransom paid; Dragos refused to engage with the extortion attempt.","records_affected":null,"threat_actor":null,"summary":"Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.","how_it_worked":"The attacker targeted the gap that exists before a new hire's first day, when the person has an accepted offer but no corporate identity yet. Having taken over the recruit's personal email, the criminal completed the onboarding steps in their name, receiving credentials and access as the company believed it was equipping its own new starter. That produced legitimate access to onboarding-tier resources including SharePoint and a contract system. When ransomware deployment failed, the group escalated to personal pressure, contacting executives' private accounts and naming relatives to force negotiation. Dragos's SIEM alerts surfaced the activity and the account was blocked.","lessons":"Onboarding must verify identity through a channel independent of the address on the offer letter, and new-hire accounts should start with minimal access under heightened monitoring.","confidence":"Confirmed","sources":[{"title":"Deconstructing a Cybersecurity Event","url":"https://www.dragos.com/blog/deconstructing-a-cybersecurity-event","publisher":"Dragos"},{"title":"Cybersecurity firm Dragos discloses cybersecurity incident, extortion attempt","url":"https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d"},{"title":"Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked","date":"2023-05","date_precision":"month","victim_org":"Bart Stephens, co-founder of Blockchain Capital","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft","Attempt Blocked"],"loss_usd":6300000,"loss_note":"$6.3 million in bitcoin, ether and other tokens per the civil complaint. A further attempted theft of about $14 million from a cold storage wallet was stopped. Roughly half the stolen funds were routed through mixers.","records_affected":null,"threat_actor":"Unidentified attacker sued as 'Jane Doe'","summary":"Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.","how_it_worked":"The attacker assembled Stephens's personal details from public sources and dark web data, then used them to pass the identity checks at his mobile carrier, change the account password, order a new handset and port his private cell number to a SIM in that device. Holding the number, the attacker triggered password resets across Stephens's digital wallets and satisfied the SMS second factor on each one, then systematically moved assets out. The one transfer that failed was the cold storage withdrawal, which generated a notification seen by a colleague at the firm who acted before it settled.","lessons":"Removing SMS as a recovery or second factor for any wallet, and routing large withdrawals through a mandatory second-person approval with a time delay, are the two controls that separated the $6.3 million loss from the $14 million save.","confidence":"Reported","sources":[{"title":"Blockchain Capital's Bart Stephens Lost $6.3 Million In SIM-Swap Crypto Hack","url":"https://www.forbes.com/sites/iainmartin/2023/08/21/blockchain-capitals-bart-stephens-lost-63-million-in-sim-swap-crypto-hack/","publisher":"Forbes"}],"entry_type":"incident","slug":"2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked"},{"title":"Coinbase employee phished by SMS then talked through by a fake IT caller","date":"2023-02-05","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.","outcomes":["Data Breach","Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No customer funds or customer data were lost; exposure was limited to some employee contact details.","records_affected":null,"threat_actor":"Reported as the 0ktapus / Scattered Spider cluster","summary":"In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.","how_it_worked":"The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.","lessons":"Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.","confidence":"Confirmed","sources":[{"title":"Social Engineering - A Coinbase Case Study","url":"https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study","publisher":"Coinbase"},{"title":"Coinbase cyberattack targeted employees with fake SMS alert","url":"https://www.bleepingcomputer.com/news/security/coinbase-cyberattack-targeted-employees-with-fake-sms-alert/","publisher":"BleepingComputer"},{"title":"Coinbase breached by social engineers, employee data stolen","url":"https://news.sophos.com/en-us/2023/02/21/coinbase-breached-by-social-engineers-employee-data-stolen","publisher":"Sophos News"}],"entry_type":"incident","slug":"2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller"},{"title":"Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers","date":"2023-01-11","date_precision":"day","victim_org":"Mailchimp (Intuit)","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published; downstream Trezor customers were subsequently targeted by wallet-draining phishing.","records_affected":null,"threat_actor":null,"summary":"Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.","how_it_worked":"Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.","lessons":"Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.","confidence":"Confirmed","sources":[{"title":"Mailchimp suffers another data breach after social engineering attack on employees","url":"https://www.computing.co.uk/news/4063093/mailchimp-suffers-breach-social-engineering-attack-employees","publisher":"Computing"},{"title":"DigitalOcean says customer email addresses were exposed","url":"https://techcrunch.com/2022/08/16/digitalocean-emails-mailchimp-breach/","publisher":"TechCrunch"},{"title":"Impact to DigitalOcean customers resulting from Mailchimp security incident","url":"https://www.digitalocean.com/blog/digitalocean-response-to-mailchimp-security-incident","publisher":"DigitalOcean"},{"title":"Mailchimp suffers third breach in 12 months","url":"https://www.computerweekly.com/news/252529368/Mailchimp-suffers-third-breach-in-12-months","publisher":"Computer Weekly"},{"title":"IOTW: Mailchimp suffers another social engineering attack","url":"https://www.cshub.com/attacks/news/iotw-mailchimp-suffers-another-social-engineering-attack","publisher":"Cyber Security Hub"},{"title":"Mailchimp discloses a new security breach, the second one in 6 months","url":"https://securityaffairs.com/140997/data-breach/mailchimp-security-breach.html","publisher":"Security Affairs"},{"title":"Companies impacted by Mailchimp data breach warn their customers","url":"https://securityaffairs.com/141203/data-breach/companies-impacted-by-mailchimp-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor"},{"title":"Riot Games loses League of Legends source code to a social engineering attack","date":"2023-01","date_precision":"month","victim_org":"Riot Games","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Service Disruption"],"loss_usd":null,"loss_note":"Riot refused the $10 million ransom demand and did not publish remediation costs.","records_affected":null,"threat_actor":null,"summary":"Riot Games disclosed in January 2023 that attackers used social engineering to compromise its development environment and steal source code for League of Legends and Teamfight Tactics along with a legacy anti-cheat platform. The company received a ransom email demanding $10 million and publicly refused to pay. Riot said no player data or personal information was compromised, but the intrusion disrupted its build pipeline and delayed game patches.","how_it_worked":"Riot attributed the intrusion to social engineering rather than a software vulnerability and said an employee's access was the entry point, without publishing the script used. The attackers' goal shaped the tradecraft: rather than encrypting systems they moved quietly into the build and source environment, took the anti-cheat and game code that has resale value in the cheat-development market, and only surfaced afterwards with an emailed extortion demand. Riot's refusal to pay, and its public commitment to publish a post-incident report, limited the leverage the stolen code created.","lessons":"Source and build environments should require phishing-resistant MFA and device trust separately from general corporate SSO, so one socially engineered employee cannot reach them.","confidence":"Confirmed","sources":[{"title":"Riot Games receives 'ransom email' for stolen source code following social engineering attack","url":"https://therecord.media/riot-games-receives-ransom-email-for-stolen-source-code-following-social-engineering-attack","publisher":"The Record"},{"title":"Riot Games receives ransom demand from hackers, refuses to pay","url":"https://www.bleepingcomputer.com/news/security/riot-games-receives-ransom-demand-from-hackers-refuses-to-pay/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a"},{"title":"Rockstar Games internal Slack breached and GTA 6 footage leaked","date":"2022-09-18","date_precision":"day","victim_org":"Rockstar Games","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Rockstar and parent Take-Two did not quantify losses publicly.","records_affected":null,"threat_actor":"Arion Kurtaj, linked to Lapsus$ (same actor as the Uber intrusion)","summary":"An actor using the handle teapotuberhacker, the same persona behind the Uber intrusion days earlier, posted roughly 90 in-development Grand Theft Auto VI videos and claimed to hold GTA V and GTA VI source code, saying they had reached Rockstar's internal Slack and Confluence. Rockstar confirmed a network intrusion and unauthorised access to early development footage. A UK teenager, Arion Kurtaj, was later convicted and in December 2023 given an indefinite hospital order.","how_it_worked":"The actor did not publish a technical exploit chain, and Rockstar has never described the entry point, so the mechanics are attacker-claimed and inferred from the same operator's behaviour at Uber days earlier: harvesting employee credentials and then talking a human into approving access, followed by collection from collaboration platforms rather than code repositories. Once inside Slack and Confluence the value was not code execution but corporate memory, build videos, design documents and chat, which the actor packaged directly into an extortion attempt and a public leak.","lessons":"Collaboration platforms hold the crown jewels for a media company and deserve the same phishing-resistant MFA, device trust and data-egress monitoring as source control.","confidence":"Alleged","sources":[{"title":"Alleged Grand Theft Auto 6 (GTA6) gameplay videos and source code leaked online","url":"https://securityaffairs.com/135923/data-breach/gta6-gameplay-videos-source-code-leak.html","publisher":"Security Affairs"},{"title":"London Police arrested a teen suspected to be behind Uber, Rockstar Games breaches","url":"https://securityaffairs.com/136146/cyber-crime/uber-rockstar-games-hacker-arrest.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked"},{"title":"Uber breached after MFA push bombing and a WhatsApp message posing as IT","date":"2022-09-15","date_precision":"day","victim_org":"Uber Technologies","sector":"Transportation & Logistics","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Insider Access","Service Disruption"],"loss_usd":null,"loss_note":"No monetary loss disclosed; Uber said no public-facing systems or user accounts were accessed.","records_affected":null,"threat_actor":"Lapsus$ (an 18-year-old member was later convicted in the UK)","summary":"In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.","how_it_worked":"With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.","lessons":"Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.","confidence":"Confirmed","sources":[{"title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack","url":"https://www.darkreading.com/cyberattacks-data-breaches/uber-breach-external-contractor-mfa-bombing-attack","publisher":"Dark Reading"},{"title":"Lessons to learn from the Uber security breach","url":"https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/09/27-september-2022-lessons-to-learn-from-the-uber-security-breach.pdf.coredownload.inline.pdf","publisher":"KPMG"},{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Security Update","url":"https://www.uber.com/newsroom/security-update/","publisher":"Uber"},{"title":"Uber links breach to Lapsus$ group, blames contractor for hack","url":"https://www.bleepingcomputer.com/news/security/uber-links-breach-to-lapsus-group-blames-contractor-for-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it"},{"slug":"2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom","title":"Robinhood support employee socially engineered by phone; 7 million customers exposed","date":"2021-11-03","date_precision":"day","year":2021,"victim_org":"Robinhood Markets","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"An extortion demand was made; Robinhood said it reported the demand to law enforcement rather than paying.","records_affected":7000000,"threat_actor":null,"summary":"On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.","how_it_worked":"The attack was a phone call, not an email. The caller reached a customer support employee and, over the course of the conversation, obtained access to support tooling, most plausibly by presenting as internal IT or as an authorised colleague needing assistance. Support staff are the ideal target for this because their entire job is to be helpful under time pressure to people they cannot see, and their tooling is broad by design: a single support console can query millions of customer records. Robinhood confirmed no Social Security numbers, bank account numbers or debit card numbers were exposed, but the breadth of the customer list made the extortion attempt credible.","lessons":"Support consoles need per-record justification, rate limits and bulk-export alerting, and any inbound request for support access should be verified through an internal directory callback.","confidence":"Confirmed","sources":[{"title":"Robinhood data breach affects 7 million customers","url":"https://fortune.com/2021/11/08/robinhood-data-breach-7-million-customers","publisher":"Fortune"},{"title":"Robinhood Data Breach Leads Data Events in November","url":"https://www.idtheftcenter.org/post/robinhood-data-breach-leads-data-events-november-number-data-compromises-reaches-all-time-high/","publisher":"Identity Theft Resource Center"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom"},{"title":"Electronic Arts source code stolen via Slack cookie and IT help desk impersonation","date":"2021-06","date_precision":"month","victim_org":"Electronic Arts","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No confirmed payment or loss figure; the stolen data was advertised for sale on underground forums.","records_affected":null,"threat_actor":"Unnamed criminal group that spoke to Motherboard/Vice","summary":"In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.","how_it_worked":"The chain began with a cookie sold on a criminal marketplace that carried a live Slack session for an EA employee. Inside Slack the attackers had the informal context, names and internal jargon needed to sound like staff. They then approached IT support in chat, claiming a lost phone, and persuaded the agent to issue a replacement MFA token without independent identity proofing. With working corporate credentials and MFA they reached EA's internal developer compilation service, created a virtual machine to gain broader network visibility, and downloaded game source code and internal tooling. EA said no player data was accessed.","lessons":"Help desk MFA resets need identity proofing that does not depend on the requester's own chat account, such as manager verification or a video check against an HR photo record.","confidence":"Reported","sources":[{"title":"How Hackers Used Slack to Break into EA Games","url":"https://www.vice.com/en/article/how-ea-games-was-hacked-slack/","publisher":"Vice / Motherboard"},{"title":"Hackers reportedly used EA Games' Slack to breach network, access source code","url":"https://cyberscoop.com/ea-games-fifa-hack-hackers-slack/","publisher":"CyberScoop"},{"title":"Details Emerge on How Gaming Giant EA Was Hacked","url":"https://www.darkreading.com/cyberattacks-data-breaches/report-details-how-gaming-giant-ea-was-hacked","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp"},{"title":"Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash","date":"2020-11-13","date_precision":"day","victim_org":"GoDaddy (registrar); Liquid.com and NiceHash","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning was reported; the callers used conventional pretexting against registrar staff.","outcomes":["Data Breach","Credential Theft","Service Disruption"],"loss_usd":null,"loss_note":"No customer funds were reported lost. Liquid said customer funds remained secure; NiceHash said no emails, passwords or personal data were compromised.","records_affected":null,"threat_actor":"Unattributed","summary":"Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.","how_it_worked":"The attackers called GoDaddy employees and pretended to be authorised parties with a routine domain administration need, a pretext the registrar's own staff were positioned to fulfil. Once a rep made the change, the attackers held registrar-level control of the target's domain and could repoint DNS at will. For Liquid, control of the domain's MX and name server records let them take over internal email accounts, which in turn exposed customer names, addresses, encrypted passwords and identity verification documents. NiceHash saw the same DNS manipulation but reported no data compromise. The exchanges' own security was never touched; the failure was one level up, at the registrar.","lessons":"Registry lock on critical domains, which requires manual out-of-band verification before any DNS or nameserver change, defeats registrar-side social engineering outright.","confidence":"Confirmed","sources":[{"title":"GoDaddy Employees Tricked into Compromising Cryptocurrency Sites","url":"https://threatpost.com/godaddy-employees-tricked-compromise-cryptocurrency/161520/","publisher":"Threatpost"},{"title":"GoDaddy Employees Tricked Into Transferring Control of Crypto Firm Domains: Report","url":"https://www.coindesk.com/markets/2020/11/22/godaddy-employees-tricked-into-transferring-control-of-crypto-firm-domains-report","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic"},{"title":"Twitter's July 2020 account takeover started with phone spear phishing of employees","date":"2020-07-15","date_precision":"day","victim_org":"Twitter, Inc.","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"The callers used ordinary voice social engineering and pre-collected personal details; no synthetic voice was reported.","outcomes":["Cryptocurrency Theft","Data Breach","Credential Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":118000,"loss_note":"The New York Department of Financial Services investigation report puts the bitcoin obtained through the scam tweets at approximately $118,000.","records_affected":130,"threat_actor":"Graham Ivan Clark and co-conspirators (later criminally charged)","summary":"On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.","how_it_worked":"Callers rang Twitter staff claiming to be from the internal help desk and offering to fix VPN connectivity problems, a plausible complaint during the shift to remote working. They used personal information gathered in advance about each employee to sound credible, then directed the target to a site that mirrored Twitter's real VPN portal. As the employee typed their credentials and MFA code, the attackers entered the same values into the genuine portal, completing the login inside the code's validity window. From there they reached internal account-management tooling and used it to reset the email addresses and disable MFA on high-profile accounts.","lessons":"Phishing-resistant FIDO2/WebAuthn authenticators would have broken the real-time credential relay, and out-of-band callback verification for any unsolicited IT help desk contact would have stopped the pretext at the first call.","confidence":"Confirmed","sources":[{"title":"Twitter Investigation Report","url":"https://www.dfs.ny.gov/system/files/documents/2026/07/Twitter-Investigation-Report.pdf","publisher":"New York State Department of Financial Services"},{"title":"Department of Financial Services Calls for Regulation of Social Media Giants After Twitter Hack Investigation","url":"https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202010141","publisher":"New York State Department of Financial Services"},{"title":"Twitter breach: Staff tricked by 'phone spear phishing'","url":"https://www.welivesecurity.com/2020/07/31/twitter-breach-staff-tricked-phone-spear-phishing/","publisher":"ESET WeLiveSecurity"},{"title":"New York regulator faults Twitter for lax security measures prior to big account breach","url":"https://cyberscoop.com/twitter-hack-social-engineering-new-york-financial-services/","publisher":"CyberScoop"},{"title":"Twitter Investigation Report","url":"https://www.dfs.ny.gov/Twitter_Report","publisher":"New York State Department of Financial Services"},{"title":"Twitter says hackers used a telephone to fool staff and gain access","url":"https://www.nbcnews.com/business/business-news/twitter-says-hackers-used-telephone-fool-staff-gain-access-n1235466","publisher":"NBC News"}],"entry_type":"incident","slug":"2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o","year":2020,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o"},{"title":"AT&T SIM swap drains $24M in crypto from investor Michael Terpin","date":"2018-01","date_precision":"month","victim_org":"Michael Terpin (individual investor; Transform Group)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Insider Recruitment","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media was reported in this case; the attack relied on carrier account takeover and insider assistance.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":24000000,"loss_note":"Approximately $24 million in cryptocurrency at the values cited in Terpin's litigation and contemporaneous reporting. A Los Angeles Superior Court default judgment against Nicholas Truglia totaled $75.8 million including treble RICO damages and prejudgment interest.","records_affected":null,"threat_actor":"Nicholas Truglia and associates; Ellis Pinsky, then 15, later named as a participant","summary":"Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.","how_it_worked":"Attackers targeted the mobile carrier rather than Terpin directly. According to reporting on the litigation, a then-15-year-old and an accomplice bribed an AT&T employee to move Terpin's SIM information onto a blank SIM card in a phone they controlled. Once the number was theirs, inbound SMS one-time codes and password-reset links flowed to the attackers, letting them reset credentials on Terpin's email and exchange accounts and sweep his holdings. Terpin had reportedly already asked AT&T to place additional protections on the account, which the complaint alleged were not effective against an employee acting from inside the carrier's own systems.","lessons":"Removing SMS from the authentication path for high-value crypto accounts, and enforcing dual-control plus supervisory approval on carrier-side SIM changes, would have broken this chain.","confidence":"Confirmed","sources":[{"title":"Cryptocurrency Investor Michael Terpin Wins $75.8 Million Judgment in First-Ever SIM Swap Racketeering Case","url":"https://www.greenbergglusker.com/news/cryptocurrency-investor-michael-terpin-wins-75-8-million-judgment-in-first-ever-sim-swap-racketeering-case","publisher":"Greenberg Glusker"},{"title":"Court revives 2020 AT&T case over $24M crypto theft via SIM swap","url":"https://cointelegraph.com/news/att-court-sim-swap-crypto-theft","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin"},{"title":"Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree","date":"2018","date_precision":"year","victim_org":"Approximately 40 individual cryptocurrency holders","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation","Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":7500000,"loss_note":"CoinDesk reported thefts exceeding $7.5 million across roughly 40 victims, including a single May 2018 theft of more than $5.2 million from a Cupertino entrepreneur. Vice reported the aggregate as 'over $5 million'. About $400,000 was recovered at arrest.","records_affected":null,"threat_actor":"Joel Ortiz","summary":"Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.","how_it_worked":"Ortiz and associates identified crypto holders from conference attendance and social media, then attacked their mobile carrier accounts rather than their wallets. Using victim personal data and, in the wider SIM-swap ecosystem the task force mapped, cooperative or deceived retail carrier staff, they had target numbers ported onto SIM cards they controlled. Possession of the number let them intercept SMS one-time passcodes and password-reset links, take over email and exchange accounts, and transfer funds out. One May 2018 swap moved more than $5.2 million within minutes. Proceeds went to club spending, a helicopter rental and designer goods.","lessons":"Carrier port-out PINs and number-lock features, plus app- or hardware-based MFA instead of SMS on exchange accounts, remove the single point of failure this scheme depended on.","confidence":"Confirmed","sources":[{"title":"Student Gets 10-Year Jail Term for SIM-Swap Crypto Thefts Worth $7.5 Million","url":"https://www.coindesk.com/markets/2019/04/23/student-gets-10-year-jail-term-for-sim-swap-crypto-thefts-worth-75-million","publisher":"CoinDesk"},{"title":"Hacker Who Stole $5 Million By SIM Swapping Gets 10 Years in Prison","url":"https://www.vice.com/en/article/hacker-joel-ortiz-sim-swapping-10-years-in-prison/","publisher":"Vice / Motherboard"}],"entry_type":"incident","slug":"2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"}]}