{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:38.840Z","total":12,"returned":12,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ReliaQuest blocks ShinyHunters vishing attack with device-trust controls","date":"2026-08-24","date_precision":"day","victim_org":"ReliaQuest","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"ReliaQuest did not state whether synthetic voice was used on the calls.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; no customer data was accessed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.","how_it_worked":"The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.","lessons":"Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.","confidence":"Confirmed","sources":[{"title":"ReliaQuest confirms failed data-theft attack after ShinyHunters breach","url":"https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"},{"slug":"2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli","title":"Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido (and subsidiary Ben)","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.","how_it_worked":"Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.","lessons":"Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.","confidence":"Reported","sources":[{"title":"Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling","url":"https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling","publisher":"NOS"},{"title":"Major hack of Dutch telco Odido was a classic case of social engineering","url":"https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/","publisher":"Techzine"},{"title":"Odido data breach exposes personal info of 6.2 million customers","url":"https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"},{"slug":"2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo","title":"Odido: IT impersonation calls and MFA approval requests expose 6.2M customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.","how_it_worked":"The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.","lessons":"Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.","confidence":"Confirmed","sources":[{"title":"Odido hackers pretended to be an IT employee to breach corporate system","url":"https://cybernews.com/security/odido-hackers-phishing-attack/","publisher":"Cybernews"},{"title":"Odido Salesforce Hack: Up to 6M Customers' Data at Risk","url":"https://www.salesforceben.com/odido-salesforce-hack-up-to-6m-customers-data-at-risk/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo"},{"title":"SoundCloud hit as real-time vishing kits drive browsers through SSO logins","date":"2026-01","date_precision":"month","victim_org":"SoundCloud","sector":"Media & Entertainment","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":36000000,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.","how_it_worked":"The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.","lessons":"Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"},{"title":"Okta SSO accounts targeted in vishing campaign against financial firms","date":"2026-01","date_precision":"month","victim_org":"Multiple fintech, wealth management and advisory firms (unnamed)","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_note":"Ransom demands were made by email; no aggregate figure was published for this wave.","records_affected":null,"threat_actor":"ShinyHunters (signed some extortion demands)","summary":"BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.","how_it_worked":"Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.","lessons":"Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.","confidence":"Confirmed","sources":[{"title":"Okta SSO accounts targeted in vishing-based data theft attacks","url":"https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"},{"slug":"2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d","title":"Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware","date":"2025-07","date_precision":"month","year":2025,"victim_org":"US retail, airline, transportation and insurance organisations","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC3944 / Scattered Spider","summary":"Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.","how_it_worked":"Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.","lessons":"Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.","confidence":"Confirmed","sources":[{"title":"Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure","url":"https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html","publisher":"The Hacker News"},{"title":"Scattered Spider targets VMware ESXi using social engineering","url":"https://securityaffairs.com/180466/cyber-crime/scattered-spider-targets-vmware-esxi-in-using-social-engineering/","publisher":"Security Affairs"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d"},{"title":"3AM ransomware affiliate used email bombing plus spoofed IT support calls","date":"2025-05-21","date_precision":"day","victim_org":"Unnamed Sophos client","sector":"Other","country":"Unknown","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"Sophos did not report AI-generated audio; the caller spoofed the victim's real IT department number.","outcomes":["Data Breach","Attempt Blocked"],"loss_usd":null,"loss_note":"No ransom or loss figure disclosed. 868 GB of data was exfiltrated but ransomware encryption was blocked.","records_affected":null,"threat_actor":"3AM ransomware affiliate","summary":"Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.","how_it_worked":"The affiliate first buried a target employee under 24 unsolicited emails in three minutes, manufacturing an apparent IT emergency. While the inbox was still filling, an operator phoned the employee using a spoofed caller ID that matched the company's real IT department number, offered to fix the flood, and asked the employee to start a Microsoft Quick Assist remote session. The employee granted control, giving the attacker hands-on-keyboard access. The attackers then exfiltrated 868 GB to Backblaze cloud storage over nine days before attempting ransomware deployment.","lessons":"A rule that IT never initiates remote-control sessions by inbound call, paired with blocking or alerting on Quick Assist use, breaks the email-bombing-plus-callback pattern.","confidence":"Confirmed","sources":[{"title":"3AM ransomware uses spoofed IT calls, email bombing to breach networks","url":"https://www.bleepingcomputer.com/news/security/3am-ransomware-uses-spoofed-it-calls-email-bombing-to-breach-networks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call"},{"title":"Marks & Spencer attack tied to social engineering of outsourced service desk","date":"2025-04-22","date_precision":"day","victim_org":"Marks & Spencer Group plc","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vendor / Supply Chain Impersonation","Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":null,"loss_note":"M&S publicly guided to a hit of around £300 million to operating profit before mitigation; no USD figure is asserted here.","records_affected":null,"threat_actor":"Scattered Spider, deploying DragonForce ransomware","summary":"Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.","how_it_worked":"Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.","lessons":"Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.","confidence":"Confirmed","sources":[{"title":"M&S hackers gained access through third-party Tata Consulting Services, sources say","url":"https://cybernews.com/news/marks-spencer-hackers-used-employee-login-tsc-tata-consulting-scattered-spider/","publisher":"Cybernews"},{"title":"M&S confirms month-long breach result of third-party vendor phishing attack","url":"https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/","publisher":"Cybernews"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Marks and Spencer confirms data breach after April cyber attack","url":"https://securityaffairs.com/177784/data-breach/marks-and-spencer-confirms-data-breach-after-april-cyber-attack.html","publisher":"Security Affairs"},{"title":"Marks & Spencer breach linked to Scattered Spider ransomware attack","url":"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de"},{"slug":"2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5","title":"Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients","date":"2024-07-30","date_precision":"day","year":2024,"victim_org":"Michigan Medicine (University of Michigan)","sector":"Healthcare","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":57891,"threat_actor":null,"summary":"Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.","how_it_worked":"The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.","lessons":"Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.","confidence":"Confirmed","sources":[{"title":"Michigan Medicine notifies patients of health information breach","url":"https://www.michiganmedicine.org/news-release/michigan-medicine-notifies-patients-health-information-breach-3","publisher":"Michigan Medicine"},{"title":"Michigan Medicine email breach exposes patient information","url":"https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/michigan-medicine-email-breach-exposes-patient-information/","publisher":"Becker's Hospital Review"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5"},{"title":"Uber breached after MFA push bombing and a WhatsApp message posing as IT","date":"2022-09-15","date_precision":"day","victim_org":"Uber Technologies","sector":"Transportation & Logistics","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Insider Access","Service Disruption"],"loss_usd":null,"loss_note":"No monetary loss disclosed; Uber said no public-facing systems or user accounts were accessed.","records_affected":null,"threat_actor":"Lapsus$ (an 18-year-old member was later convicted in the UK)","summary":"In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.","how_it_worked":"With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.","lessons":"Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.","confidence":"Confirmed","sources":[{"title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack","url":"https://www.darkreading.com/cyberattacks-data-breaches/uber-breach-external-contractor-mfa-bombing-attack","publisher":"Dark Reading"},{"title":"Lessons to learn from the Uber security breach","url":"https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/09/27-september-2022-lessons-to-learn-from-the-uber-security-breach.pdf.coredownload.inline.pdf","publisher":"KPMG"},{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Security Update","url":"https://www.uber.com/newsroom/security-update/","publisher":"Uber"},{"title":"Uber links breach to Lapsus$ group, blames contractor for hack","url":"https://www.bleepingcomputer.com/news/security/uber-links-breach-to-lapsus-group-blames-contractor-for-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it"},{"title":"Cisco breached after vishing and MFA fatigue against an employee","date":"2022-05-24","date_precision":"day","victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No financial loss disclosed; Cisco said no impact to its business operations, products or supply chain.","records_affected":null,"threat_actor":"Initial access broker linked to UNC2447, Lapsus$ and Yanluowang","summary":"Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.","how_it_worked":"Credentials saved in Chrome were synchronised to the employee's personal Google account, which the attacker compromised. Holding valid corporate credentials, the attacker triggered a stream of MFA push prompts to wear the user down, while simultaneously calling them in English with a plausible accent posing as support from trusted organisations. The employee eventually approved one push, giving the attacker VPN access. They then enrolled new MFA devices, escalated to administrative privileges, added backdoor accounts, and used remote access tooling and LogMeIn/TeamViewer to maintain persistence, repeatedly attempting to return after eviction.","lessons":"Number matching or FIDO2 keys instead of simple push approval, plus blocking browser credential sync to personal accounts on managed devices, would have closed both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Cisco Talos shares insights related to recent cyber attack on Cisco","url":"https://blog.talosintelligence.com/recent-cyber-attack/","publisher":"Cisco Talos"},{"title":"Cisco Confirms Network Breach Via Hacked Employee Google Account","url":"https://threatpost.com/cisco-network-breach-google/180385/","publisher":"Threatpost"},{"title":"Cisco network hack: Voice phishing and MFA fatigue gave attacker access","url":"https://www.thestack.technology/cisco-network-hack-voice-phishing-mfa-fatigue/","publisher":"The Stack"}],"entry_type":"incident","slug":"2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee"},{"slug":"2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so","title":"LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code","date":"2022-03","date_precision":"month","year":2022,"victim_org":"T-Mobile US","sector":"Telecom","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Credential Phishing Portal","Insider Recruitment","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Insider Access","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"LAPSUS$ (DEV-0537)","summary":"Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.","how_it_worked":"LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.","lessons":"Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.","confidence":"Confirmed","sources":[{"title":"Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code","url":"https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/","publisher":"Krebs on Security"},{"title":"T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code","url":"https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html","publisher":"The Hacker News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so"}]}