{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:33.857Z","total":17,"returned":17,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Kraken refuses extortion after two support insiders accessed client data","date":"2026-04-13","date_precision":"day","victim_org":"Kraken","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported in this case.","outcomes":["Extortion","Insider Access","Attempt Blocked"],"loss_usd":null,"loss_note":"Kraken refused to pay and reported no funds at risk; no loss figure disclosed.","records_affected":2000,"threat_actor":null,"summary":"CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.","how_it_worked":"The route in was people, not software. Criminals worked through members of Kraken's own customer support team to reach client support data, mirroring the bribery-of-support-agents pattern seen at Coinbase a year earlier. The stolen material was then repackaged as leverage: the extortionists produced video framed to look like live access to Kraken's internal systems and demanded payment to suppress it. Kraken said its systems were never breached and that the access was terminated, controls tightened, affected clients notified, and law enforcement engaged, with sufficient evidence to identify those responsible.","lessons":"Scoped, justification-based access in support consoles plus insider-risk monitoring limits both what an insider can reach and how long it goes unnoticed.","confidence":"Confirmed","sources":[{"title":"Crypto exchange Kraken targeted in extortion attempt, but says there was no breach and no client funds at risk","url":"https://www.coindesk.com/business/2026/04/13/crypto-exchange-kraken-targeted-in-extortion-attempt-but-says-there-was-no-breach-and-no-client-funds-at-risk","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data"},{"title":"Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders","date":"2025-11-20","date_precision":"day","victim_org":"AT&T and T-Mobile customers, including four Manhattan residents","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":435000,"loss_note":"$435,000 stolen from four Manhattan residents, with additional victims identified in other jurisdictions. The indictment covers conduct from October 2021 through July 2022.","records_affected":null,"threat_actor":"Eleven indicted defendants, including AT&T and T-Mobile retail employees Jadakiss Bonilla, Kendrah Vasquez, Amanda Rodado and Jared Moreland","summary":"Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.","how_it_worked":"Ringleaders identified targets and passed their account details to retail store employees on the inside. Rather than talk a rep into a fraudulent swap, the crew paid the reps directly: the store workers used their own authorised access to customer account information to execute the SIM swaps, and in some cases signed in under a coworker's credentials so the audit trail pointed at the wrong person. Once a victim's number was ported to a device the ring controlled, incoming SMS one-time passcodes and password-reset links let them take over bank and payment accounts and move money out through wire transfers and peer-to-peer payment apps before the victim understood why their handset had lost service.","lessons":"Carriers need per-employee SIM-change rate monitoring, mandatory customer confirmation on a second channel, and credential controls that make shared or borrowed logins impossible, since insider swaps look identical to legitimate ones.","confidence":"Alleged","sources":[{"title":"D.A. Bragg Announces Indictment Of SIM-Swapping ID Theft Ring, Including AT&T And T-Mobile Employees","url":"https://manhattanda.org/d-a-bragg-announces-indictment-of-sim-swapping-id-theft-ring-including-att-and-t-mobile-employees/","publisher":"Manhattan District Attorney's Office"}],"entry_type":"campaign","slug":"2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside"},{"slug":"2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack","title":"US ransomware negotiators charged with running their own BlackCat attacks","date":"2025-11-03","date_precision":"day","year":2025,"victim_org":"US medical device company, pharmaceutical firm, drone maker and other victims","sector":"Professional Services","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Extortion","Insider Access"],"loss_usd":1274000,"loss_kind":"ransom_paid","loss_note":"One victim, a Florida medical device company, paid about $1.27 million in bitcoin according to the indictment.","records_affected":null,"threat_actor":"ALPHV / BlackCat affiliates","summary":"US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.","how_it_worked":"This was a trusted-insider abuse rather than an external deception. The defendants worked in roles that put them inside the ransomware economy, negotiating on behalf of victims and responding to intrusions, which gave them privileged knowledge of how victims behave, what they pay and how affiliates operate. Prosecutors alleged they used that position to run attacks of their own with the ALPHV/BlackCat toolkit and extort the companies. The trust abused was institutional: organisations hand incident responders and negotiators deep access and complete candour during a crisis, and the employers' own vetting did not surface the conduct until federal investigators did.","lessons":"Firms handling victim data and ransom negotiations need separation of duties, monitored access to case material and periodic re-vetting of staff with that level of insight.","confidence":"Confirmed","sources":[{"title":"DOJ accuses US ransomware negotiators of launching their own ransomware attacks","url":"https://techcrunch.com/2025/11/03/doj-accuses-us-ransomware-negotiators-of-launching-their-own-ransomware-attacks/","publisher":"TechCrunch"},{"title":"Ransomware responders plead guilty to using ALPHV in attacks on US organizations","url":"https://therecord.media/ransomware-responders-guilty-plea-using-alphv-blackcat-us-attacks","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack"},{"slug":"2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c","title":"Five plead guilty to helping North Korean IT workers infiltrate 136 US companies","date":"2025-11","date_precision":"month","year":2025,"victim_org":"136 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":2200000,"loss_kind":"criminal_proceeds","loss_note":"About $2.2 million in revenue generated for the North Korean government through the roles obtained; one defendant agreed to forfeit more than $1.4 million.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.","how_it_worked":"Three of the defendants let overseas workers use their real US identities to apply for and hold remote IT jobs, so background checks returned clean results for genuine Americans. Others hosted company-issued laptops at their homes and installed remote desktop software so workers abroad appeared to be sitting at a US desk. A fourth trafficked stolen and rented identities through a website marketed at overseas jobseekers. The deception targeted HR and IT onboarding rather than any technical control: the trust signals abused were verified identity documents, a US shipping address and a US-looking network origin, all of which onboarding processes treat as proof of presence.","lessons":"Tie identity verification to a live check at onboarding and re-verify periodically; monitor corporate laptops for remote-control tooling and for logins whose network geography does not match the employee's stated location.","confidence":"Confirmed","sources":[{"title":"Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies","url":"https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html","publisher":"The Hacker News"},{"title":"Ukrainian national pleads guilty in 'laptop farm' scheme that generated income for North Korean IT workers","url":"https://www.justice.gov/usao-dc/pr/ukrainian-pleads-guilty-dc-laptop-farm-scheme-generated-income-north-korean-it-workers","publisher":"US Department of Justice"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c"},{"title":"US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud","date":"2025-09-08","date_precision":"day","victim_org":"US, European and Chinese scam victims (multi-victim campaign)","sector":"Consumer","country":"Myanmar and Cambodia","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Romance / Investment Scam","Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"The sanctions announcement does not characterise AI use in the compounds' scam operations.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":10000000000,"loss_note":"Over $10 billion in losses to Americans was cited in connection with the announcement; this is a sector-wide aggregate, not a single-incident figure.","records_affected":null,"threat_actor":"Shwe Kokko / Yatai International Holdings Group network and Cambodian casino operators","summary":"On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.","how_it_worked":"The compounds are staffed by recruitment fraud. Thousands of people are lured with fake job offers, typically advertised as customer service, translation or IT work at attractive salaries in Thailand or Cambodia, then transported across borders, held against their will and forced to run scams targeting people in the United States, Europe and China. Inside, workers follow scripted romance and investment playbooks against assigned target lists, with quotas enforced by violence. The compound model industrialises social engineering: the recruitment lure supplies the labour, and the labour supplies the volume of romance and investment approaches.","lessons":"Because the front-line operators are themselves trafficking victims, effective controls sit upstream in sanctions, telecom and payment infrastructure rather than in prosecuting individual callers.","confidence":"Confirmed","sources":[{"title":"US sanctions companies behind cyber scam centers in Cambodia, Myanmar","url":"https://therecord.media/us-sanctions-companies-southeast-asia-scam-compounds","publisher":"The Record (Recorded Future News)"},{"title":"Myanmar Military Arrests Hundreds in Raid on Thai-Border Scam Center","url":"https://www.occrp.org/en/news/myanmar-military-arrests-hundreds-in-raid-on-thai-border-scam-center","publisher":"OCCRP"}],"entry_type":"campaign","slug":"2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la"},{"slug":"2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f","title":"Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"More than 300 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_kind":"criminal_proceeds","loss_note":"Approximately $17 million in wages and revenue generated for North Korea through the scheme; the defendant was ordered to forfeit roughly $284,000 and pay about $177,000 in restitution.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.","how_it_worked":"Overseas operatives applied for remote IT roles using stolen or borrowed US identities and forged documents, passing HR checks and video screening because the identity paperwork was genuine and the impersonation was rehearsed. Companies shipped corporate laptops to what they believed was the employee's US home address; in fact the machines were racked at the facilitator's house, where remote access software let workers in Asia operate them from apparently American IP addresses. The trust signals abused were a valid Social Security number, a plausible US address and a working corporate device. Payroll then flowed to US accounts before being laundered abroad.","lessons":"Verify remote hires with live identity proofing tied to the device shipping address, and alert on remote-management software or geographic mismatch on corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced in $17M IT worker fraud scheme that illegally generated revenue for North Korea","url":"https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north","publisher":"US Department of Justice"},{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f"},{"title":"US sweep seizes 200 computers from North Korean IT worker laptop farms","date":"2025-06-30","date_precision":"day","victim_org":"More than 100 US companies, including many Fortune 500 firms","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"DOJ described stolen and fraudulent identities; the announcement reviewed did not specify AI-generated personas.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access","Espionage","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ cited at least $3 million in victim-company losses for legal fees and remediation, more than $5 million in revenue in one Massachusetts scheme, roughly $915,000 in virtual currency stolen in a Georgia case, and a civil forfeiture action covering over $7.74 million in digital assets. US facilitators received at least $696,000.","records_affected":null,"threat_actor":"DPRK remote IT worker networks and US-based facilitators (Zhenxing 'Danny' Wang, Kejia Wang and others)","summary":"On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.","how_it_worked":"North Korean workers obtained remote US employment using stolen and fabricated identities that cleared employer background checks. US-based facilitators supplied the American presence the scheme needed: they registered shell companies and fraudulent websites so the identities had verifiable employment history, received the employers' shipped laptops, and installed keyboard-video-mouse switches and remote access software so overseas operators could drive the machines as though sitting in front of them. From inside those employers the workers drew salaries routed to the DPRK, and in several cases went further, exfiltrating sensitive data including export-controlled military technology and stealing virtual currency from employer systems.","lessons":"Employers need live identity proofing tied to the government ID at hire, verification that the issued device is physically where the employee claims to be, and alerting on KVM or remote-access hardware attached to corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers","url":"https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote","publisher":"U.S. Department of Justice"},{"title":"U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms","url":"https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html","publisher":"The Hacker News"}],"entry_type":"campaign","slug":"2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms"},{"title":"Bribed overseas support agents leaked Coinbase data; $20M extortion refused","date":"2025-05-15","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in Coinbase's disclosure.","outcomes":["Data Breach","Extortion","Insider Access","Cryptocurrency Theft","Identity Theft"],"loss_usd":null,"loss_note":"Coinbase refused the $20 million demand and instead established a $20 million reward fund for information leading to arrests. Aggregate customer losses from the resulting social engineering were not quantified in the disclosure.","records_affected":69461,"threat_actor":"Unattributed extortion group","summary":"Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.","how_it_worked":"The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.","lessons":"Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.","confidence":"Confirmed","sources":[{"title":"Protecting Our Customers - Standing Up to Extortionists","url":"https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists","publisher":"Coinbase"},{"title":"Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails","url":"https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html","publisher":"The Hacker News"},{"title":"Coinbase confirms insiders handed over data of 70K users","url":"https://www.theregister.com/2025/05/21/coinbase_confirms_insider_breach_affects/","publisher":"The Register"}],"entry_type":"incident","slug":"2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse"},{"title":"Binance and Kraken block bribery attempts aimed at support staff","date":"2025-05","date_precision":"month","victim_org":"Binance and Kraken","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"Contact was made over Telegram; no AI-generated media was reported.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No losses; both attempts were stopped before any customer data was exposed.","records_affected":null,"threat_actor":null,"summary":"In the weeks around the Coinbase insider breach, the same style of attack was attempted against Binance and Kraken. Bloomberg-sourced reporting said threat actors approached customer support staff at both exchanges over Telegram and offered bribes for system access and customer data. Both exchanges detected and blocked the approaches, and neither reported any user data exposure.","how_it_worked":"Attackers contacted individual support agents directly on Telegram, offering cryptocurrency payment and supplying step-by-step instructions on how to retrieve and exfiltrate customer records, evade internal monitoring, and receive payment. The pitch targeted people rather than systems, on the assumption that a support agent with broad record access is cheaper to buy than a vulnerability is to find. Binance's monitoring flagged the suspicious communication patterns, including bribe-related keywords and outbound Telegram contact attempts, while both exchanges relied on data-access policies tightened in late 2024 to limit what any single agent could pull.","lessons":"Access limits that make a single agent's data reach small, plus monitoring for recruitment-style contact and anomalous record retrieval, turn insider bribery into a detected event rather than a breach.","confidence":"Reported","sources":[{"title":"Social Engineering Plot Foiled at Binance and Kraken After Coinbase Breach Fallout","url":"https://yellow.com/news/social-engineering-plot-foiled-at-binance-and-kraken-after-coinbase-breach-fallout","publisher":"Yellow"}],"entry_type":"incident","slug":"2025-binance-and-kraken-block-bribery-attempts-aimed-at-support-staff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-binance-and-kraken-block-bribery-attempts-aimed-at-support-staff"},{"title":"Rippling sues Deel over a manager allegedly recruited as a corporate spy","date":"2025-03-17","date_precision":"day","victim_org":"Rippling","sector":"Technology","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was alleged.","outcomes":["Insider Access","Espionage","Data Breach"],"loss_usd":null,"loss_note":"No loss figure has been established. The complaint alleges payment to the employee laundered through an intermediary; the allegations are contested and litigation is ongoing.","records_affected":null,"threat_actor":"Alleged: a Rippling employee acting on behalf of competitor Deel. Deel disputes the allegations; a related DOJ inquiry has been reported.","summary":"On March 17, 2025 Rippling sued rival HR and payroll company Deel in the Northern District of California, alleging Deel cultivated a Rippling employee as a spy. The complaint says the employee searched Rippling systems for 'Deel' an average of 23 times a day over four months and accessed Slack channels more than 6,000 times without business justification, funnelling sales pipeline data, pricing, customer churn lists and employee contact details to Deel. Deel denies wrongdoing and the litigation continues.","how_it_worked":"The alleged access was entirely legitimate on its face. A person in a management role at a Rippling affiliate used their normal credentials to run searches and read Slack channels, activity that generated no security alerts because none of it was unauthorised in a technical sense; the abuse was in volume and purpose. Rippling exposed it with a honeypot rather than a detection rule: it sent a letter to three Deel executives referencing a Slack channel called 'd-defectors' that existed but had never contained a single message. Within hours the employee searched for that never-used channel for the first time, which Rippling argues shows the letter's contents were relayed to him. He was confronted when court-appointed solicitors sought his phone.","lessons":"Insider risk programmes need behavioural baselining on internal search and channel access, since a recruited insider's activity is authorised by definition and only its pattern gives it away.","confidence":"Alleged","sources":[{"title":"Lawsuit Alleges $12 Billion 'Unicorn' Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor","url":"https://www.rippling.com/blog/lawsuit-alleges-12-billion-unicorn-deel-cultivated-spy-orchestrated-long-running-trade-secret-theft-corporate-espionage-against-competitor","publisher":"Rippling"},{"title":"Rippling accuses competitor Deel of corporate espionage","url":"https://www.hr-brew.com/stories/2025/03/20/rippling-deel-corporate-espionage","publisher":"HR Brew"}],"entry_type":"incident","slug":"2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy"},{"slug":"2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so","title":"LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code","date":"2022-03","date_precision":"month","year":2022,"victim_org":"T-Mobile US","sector":"Telecom","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Credential Phishing Portal","Insider Recruitment","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Insider Access","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"LAPSUS$ (DEV-0537)","summary":"Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.","how_it_worked":"LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.","lessons":"Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.","confidence":"Confirmed","sources":[{"title":"Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code","url":"https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/","publisher":"Krebs on Security"},{"title":"T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code","url":"https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html","publisher":"The Hacker News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so"},{"title":"Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory","date":"2020-08","date_precision":"month","victim_org":"Tesla, Inc.","sector":"Manufacturing","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss occurred. The targeted employee reported the approach to Tesla and the FBI, and the plot was never executed.","records_affected":null,"threat_actor":"Egor Igorevich Kriuchkov (later pleaded guilty)","summary":"Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.","how_it_worked":"Kriuchkov built rapport with the employee in person over social meetings before naming the ask. The proposal was for the employee to run attacker-supplied ransomware inside the plant network, either by opening a malicious email attachment or plugging in an infected USB stick, while the conspirators ran a simultaneous distributed denial-of-service attack to occupy Tesla's security team. The group intended to exfiltrate Tesla files and extort the company for their non-release; Kriuchkov said the malware itself had cost $250,000 to develop. The scheme died at the first step because the employee, rather than accepting, told Tesla and then wore a wire for the FBI.","lessons":"A no-blame, clearly advertised channel for reporting bribery approaches is the control that actually catches insider recruitment, since no technical control sees the offer being made.","confidence":"Confirmed","sources":[{"title":"How a $1 million plot to hack Tesla failed","url":"https://www.technologyreview.com/2020/08/28/1007752/how-a-1-million-plot-to-hack-tesla-failed/","publisher":"MIT Technology Review"}],"entry_type":"incident","slug":"2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi"},{"title":"Hacker bribed a Roblox support contractor to access user data and reset accounts","date":"2020-05","date_precision":"month","victim_org":"Roblox Corporation","sector":"Gaming & Casino","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Insider Access","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No dollar loss was published. The hacker changed passwords on two accounts and took in-game items from those users.","records_affected":null,"threat_actor":"Unnamed individual who had previously sought a Roblox bug bounty","summary":"A hacker bribed a Roblox customer support representative, listed publicly as an in-game support contractor, to obtain access to the company's customer support panel. The panel exposed personal data on Roblox's user base and allowed password resets, removal of two-factor authentication, account bans and data changes. Roblox said it acted immediately, notified the small number of affected customers, and reported the hacker to HackerOne.","how_it_worked":"The attacker skipped Roblox's perimeter entirely and bought a person instead. He identified a support contractor via LinkedIn and paid them for access to the internal customer support console, which was designed to let agents administer any account. With that console the attacker could read email addresses, force password resets, strip 2FA from targeted accounts, ban users and alter records, including for high-profile creators. He used it to change passwords on two accounts and take their in-game items. Roblox had earlier denied him a bug bounty payout over suspected malicious activity, which appears to have preceded the insider approach.","lessons":"Support consoles that can reset any account need per-record justification, least-privilege scoping and anomaly alerting on bulk or high-profile lookups, so a single bribed agent cannot become a master key.","confidence":"Reported","sources":[{"title":"Hacker Bribed 'Roblox' Insider to Access User Data","url":"https://www.vice.com/en/article/hacker-bribed-roblox-insider-accessed-user-data-reset-passwords/","publisher":"Vice / Motherboard"},{"title":"Hacker Bribed Roblox Worker For Access To Users' Personal Data","url":"https://www.gamespot.com/articles/hacker-bribed-roblox-worker-for-access-to-users-pe/1100-6477149/","publisher":"GameSpot"}],"entry_type":"incident","slug":"2020-hacker-bribed-a-roblox-support-contractor-to-access-user-data-and-reset","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-hacker-bribed-a-roblox-support-contractor-to-access-user-data-and-reset"},{"title":"Mobile carrier employee took $500-a-day bribes to perform SIM swaps","date":"2018-10","date_precision":"month","victim_org":"Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Insider Access","Identity Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ did not state aggregate victim losses in the charging announcement. Defiore received approximately $2,325 across twelve bribe payments, at roughly $500 per day of swaps.","records_affected":19,"threat_actor":"Stephen Daniel Defiore and unnamed co-conspirators","summary":"A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.","how_it_worked":"The deceived party here was the carrier itself, not a customer. Rather than talk a retail rep into a fraudulent swap, the conspiracy simply put one on payroll. A co-conspirator messaged Defiore a target's phone number, account PIN and the SIM identifier to swap the line to; Defiore, who worked at the carrier from August 2017 to November 2018, used his legitimate employee access to execute the change and was paid roughly $500 per day. Because the change was made by an authorized account with a valid business reason on its face, none of the carrier's customer-facing verification controls applied. The hijacked numbers then received the victims' SMS authentication codes.","lessons":"SIM-change transactions need behavioral monitoring on the employee side, including per-rep swap-rate baselining and out-of-band customer confirmation, since insider abuse looks identical to authorized work in the logs.","confidence":"Confirmed","sources":[{"title":"Former Phone Company Employee Charged for Role in SIM Swap Scam That Targeted at Least 19 Customers","url":"https://www.justice.gov/usao-edla/pr/former-phone-company-employee-charged-rolein-sim-swap-scam-targeted-least-19-customers","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps","year":2018,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps"},{"title":"India-based IRS and USCIS impersonation call centers: 24 defendants sentenced","date":"2018-07-20","date_precision":"day","victim_org":"US consumers, many of them elderly (multi-victim campaign)","sector":"Consumer","country":"United States and India","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the calls were made by live scripted operators.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":8970396,"loss_note":"Restitution of $8,970,396 was ordered for identified victims across 22 defendants, with money judgments exceeding $72.9 million; defendants were held liable for laundering between $3.5 million and $25 million collectively.","records_affected":null,"threat_actor":"Ahmedabad-based call center network and US-based runner network","summary":"On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.","how_it_worked":"Operators in Ahmedabad called Americans, many of them elderly or recent immigrants, and identified themselves as IRS or USCIS officials. They asserted that back taxes were owed or that an immigration status problem had been found, and threatened immediate arrest, imprisonment, fines or deportation unless payment was made at once. The lever was raw state authority plus a deliberately compressed timeline that prevented the victim from consulting family or a lawyer. Payment was demanded in stored value cards or wire transfers, and US-based runners then liquidated the cards, bought money orders and collected wires under false identities to launder the proceeds.","lessons":"Public education that tax and immigration agencies never demand payment by gift card or threaten immediate arrest by phone, combined with retailer prompts at gift card checkout, directly disrupts this model.","confidence":"Confirmed","sources":[{"title":"24 Defendants Sentenced in Multimillion Dollar India-Based Call Center Scam Targeting U.S. Victims","url":"https://www.justice.gov/archives/opa/pr/24-defendants-sentenced-multimillion-dollar-india-based-call-center-scam-targeting-us-victims","publisher":"U.S. Department of Justice"}],"entry_type":"campaign","slug":"2018-india-based-irs-and-uscis-impersonation-call-centers-24-defendants-sente","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-india-based-irs-and-uscis-impersonation-call-centers-24-defendants-sente"},{"title":"AT&T SIM swap drains $24M in crypto from investor Michael Terpin","date":"2018-01","date_precision":"month","victim_org":"Michael Terpin (individual investor; Transform Group)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Insider Recruitment","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media was reported in this case; the attack relied on carrier account takeover and insider assistance.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":24000000,"loss_note":"Approximately $24 million in cryptocurrency at the values cited in Terpin's litigation and contemporaneous reporting. A Los Angeles Superior Court default judgment against Nicholas Truglia totaled $75.8 million including treble RICO damages and prejudgment interest.","records_affected":null,"threat_actor":"Nicholas Truglia and associates; Ellis Pinsky, then 15, later named as a participant","summary":"Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.","how_it_worked":"Attackers targeted the mobile carrier rather than Terpin directly. According to reporting on the litigation, a then-15-year-old and an accomplice bribed an AT&T employee to move Terpin's SIM information onto a blank SIM card in a phone they controlled. Once the number was theirs, inbound SMS one-time codes and password-reset links flowed to the attackers, letting them reset credentials on Terpin's email and exchange accounts and sweep his holdings. Terpin had reportedly already asked AT&T to place additional protections on the account, which the complaint alleged were not effective against an employee acting from inside the carrier's own systems.","lessons":"Removing SMS from the authentication path for high-value crypto accounts, and enforcing dual-control plus supervisory approval on carrier-side SIM changes, would have broken this chain.","confidence":"Confirmed","sources":[{"title":"Cryptocurrency Investor Michael Terpin Wins $75.8 Million Judgment in First-Ever SIM Swap Racketeering Case","url":"https://www.greenbergglusker.com/news/cryptocurrency-investor-michael-terpin-wins-75-8-million-judgment-in-first-ever-sim-swap-racketeering-case","publisher":"Greenberg Glusker"},{"title":"Court revives 2020 AT&T case over $24M crypto theft via SIM swap","url":"https://cointelegraph.com/news/att-court-sim-swap-crypto-theft","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin"},{"title":"Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree","date":"2018","date_precision":"year","victim_org":"Approximately 40 individual cryptocurrency holders","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Help Desk Impersonation","Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Identity Theft"],"loss_usd":7500000,"loss_note":"CoinDesk reported thefts exceeding $7.5 million across roughly 40 victims, including a single May 2018 theft of more than $5.2 million from a Cupertino entrepreneur. Vice reported the aggregate as 'over $5 million'. About $400,000 was recovered at arrest.","records_affected":null,"threat_actor":"Joel Ortiz","summary":"Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.","how_it_worked":"Ortiz and associates identified crypto holders from conference attendance and social media, then attacked their mobile carrier accounts rather than their wallets. Using victim personal data and, in the wider SIM-swap ecosystem the task force mapped, cooperative or deceived retail carrier staff, they had target numbers ported onto SIM cards they controlled. Possession of the number let them intercept SMS one-time passcodes and password-reset links, take over email and exchange accounts, and transfer funds out. One May 2018 swap moved more than $5.2 million within minutes. Proceeds went to club spending, a helicopter rental and designer goods.","lessons":"Carrier port-out PINs and number-lock features, plus app- or hardware-based MFA instead of SMS on exchange accounts, remove the single point of failure this scheme depended on.","confidence":"Confirmed","sources":[{"title":"Student Gets 10-Year Jail Term for SIM-Swap Crypto Thefts Worth $7.5 Million","url":"https://www.coindesk.com/markets/2019/04/23/student-gets-10-year-jail-term-for-sim-swap-crypto-thefts-worth-75-million","publisher":"CoinDesk"},{"title":"Hacker Who Stole $5 Million By SIM Swapping Gets 10 Years in Prison","url":"https://www.vice.com/en/article/hacker-joel-ortiz-sim-swapping-10-years-in-prison/","publisher":"Vice / Motherboard"}],"entry_type":"incident","slug":"2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree","year":2018,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"}]}