{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:14:23.940Z","total":8,"returned":8,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Six-month DPRK social engineering operation preceded $285M Drift Protocol theft","date":"2026-04-01","date_precision":"day","victim_org":"Drift Protocol","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Physical Pretexting","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.","outcomes":["Cryptocurrency Theft"],"loss_usd":285000000,"loss_note":"USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.","records_affected":null,"threat_actor":"UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence","summary":"Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.","how_it_worked":"This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.","lessons":"Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.","confidence":"Reported","sources":[{"title":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","publisher":"The Hacker News"},{"title":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks","publisher":"TRM Labs"}],"entry_type":"incident","slug":"2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol","year":2026,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"},{"title":"BlackFile extortion gang runs vishing campaign against retail and hospitality","date":"2026-02","date_precision":"month","victim_org":"Multiple retail and hospitality organisations (unnamed)","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.","records_affected":null,"threat_actor":"BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)","summary":"BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.","how_it_worked":"Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.","lessons":"Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.","confidence":"Confirmed","sources":[{"title":"New BlackFile extortion gang targets retail and hospitality orgs","url":"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"},{"title":"25 Canadians charged over $21M grandparent scam targeting seniors in 40 states","date":"2025-03-05","date_precision":"day","victim_org":"Elderly US residents in more than 40 states (multi-victim campaign)","sector":"Consumer","country":"United States and Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"The indictment describes live callers posing as grandchildren and lawyers; it does not allege voice cloning.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":21000000,"loss_note":"Over $21 million in losses, per the charging announcement.","records_affected":null,"threat_actor":"Montreal-area call center network (25 Canadian nationals charged)","summary":"On 5 March 2025 US authorities announced charges against 25 Canadian nationals over a grandparent scam run from call centers in and around Montreal that defrauded elderly people in more than 40 states of over $21 million. Twenty-three defendants were arrested on 4 March and two remained at large. Money was moved to Canada after cash pickups, sometimes through cryptocurrency, to obscure its source.","how_it_worked":"Callers phoned elderly Americans and claimed to be a grandchild who had been arrested after a car crash and needed bail money immediately. A second conspirator came on the line posing as an attorney to lend procedural credibility, and told the victim a gag order forbade discussing the case with anyone, an instruction that isolates the target from the family members who would otherwise puncture the story. The emotional lever was fear for a grandchild in custody, layered with legal authority and enforced secrecy. Collection was in person: a conspirator posing as a bail bondsman came to the victim's home to take the cash.","lessons":"A pre-agreed family code word and an absolute rule of hanging up and calling the relative back on a known number defeats this script, since the scam depends on the victim never independently verifying.","confidence":"Reported","sources":[{"title":"25 Canadian nationals connected to nationwide multi-million dollar 'grandparent scam' charged in Vermont","url":"https://www.ice.gov/news/releases/25-canadian-nationals-connected-nationwide-multi-million-dollar-grandparent-scam","publisher":"U.S. Immigration and Customs Enforcement"}],"entry_type":"campaign","slug":"2025-25-canadians-charged-over-21m-grandparent-scam-targeting-seniors-in-40-s","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-25-canadians-charged-over-21m-grandparent-scam-targeting-seniors-in-40-s"},{"title":"SIM swap of the SEC's X account posted a fake Bitcoin ETF approval","date":"2024-01-09","date_precision":"day","victim_org":"U.S. Securities and Exchange Commission","sector":"Government","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physically printed counterfeit ID card.","outcomes":["Identity Theft","Service Disruption","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"No direct loss to the SEC was published. The fake post moved bitcoin roughly $1,000 higher, then more than $2,000 lower once the SEC disclosed the compromise. Council was paid about $50,000 in bitcoin for performing SIM swaps and was ordered to forfeit that amount.","records_affected":null,"threat_actor":"Eric Council Jr. and co-conspirators","summary":"On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.","how_it_worked":"Council printed a counterfeit identification card on a portable card printer using personal details supplied by co-conspirators, then walked into an AT&T store in Huntsville, Alabama and asked for a replacement SIM for the number tied to the @SECgov account. Store staff issued it against the fake document. He activated the SIM in a newly purchased iPhone, received the password-reset code for the X account, and passed it to the conspirators, who posted the fabricated ETF approval. Bitcoin moved over $1,000 within minutes. The FBI later found fake-ID templates and searches about FBI investigations at his residence.","lessons":"High-consequence institutional social accounts should be secured with hardware security keys rather than SMS-based recovery, and carrier retail ID checks need document-authentication technology rather than visual inspection.","confidence":"Confirmed","sources":[{"title":"Alabama Man Sentenced in Hack of SEC X Account that Spiked the Value of Bitcoin","url":"https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin","publisher":"U.S. Department of Justice"},{"title":"Hacker pleads guilty to SIM swap attack on US SEC X account","url":"https://www.bleepingcomputer.com/news/security/hacker-pleads-guilty-to-sim-swap-attack-on-us-sec-x-account/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval"},{"title":"SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night","date":"2022-11-11","date_precision":"day","victim_org":"FTX (referred to as 'Victim 1' in the indictment)","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physical fake ID at a retail store.","outcomes":["Cryptocurrency Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_note":"The DOJ indictment concerns a theft of roughly $400 million. FTX administrators reported $413 million in unauthorised transfers, and Elliptic valued the outflow at $477 million. Prosecutors have not officially named FTX as the victim.","records_affected":null,"threat_actor":"Robert Powell ('ElSwapo1', the 'Powell SIM Swapping Crew'), Emily Hernandez, Carter Rohn","summary":"On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.","how_it_worked":"A member of the crew walked into an AT&T retail location carrying a counterfeit ID in the target's name and asked staff to move the number to a new device. The store employee, following normal identity-check procedure against a document that looked genuine, completed the port. From that point every SMS one-time code and password-reset link for the target's accounts arrived on the attackers' handset. The crew used those codes to reach account credentials and then initiated the transfers out of FTX wallets, timed to a night when the company was in bankruptcy chaos and unusual outflows were least likely to be challenged.","lessons":"Enterprise-controlled authentication that never touches a consumer mobile number, combined with number-lock and in-person ID escalation at carrier retail, closes the pathway a physical fake ID otherwise opens.","confidence":"Reported","sources":[{"title":"Arrests in $400M SIM-Swap Tied to Heist at FTX?","url":"https://krebsonsecurity.com/2024/02/arrests-in-400m-sim-swap-tied-to-heist-at-ftx/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night"},{"title":"Sarah Palin Yahoo email account taken over via password-reset questions","date":"2008-09","date_precision":"month","victim_org":"Sarah Palin (then Governor of Alaska and vice-presidential candidate)","sector":"Government","country":"United States","primary_vector":"Physical Pretexting","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the attack relied on publicly available biographical facts.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss reported; the harm was disclosure of private correspondence during a national election campaign.","records_affected":null,"threat_actor":"David C. Kernell (convicted)","summary":"During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.","how_it_worked":"Kernell did not exploit a software flaw. He used the provider's self-service password reset flow, which authenticated the requester by asking knowledge-based security questions such as birth date, postal code and where the account holder met her spouse. Because the account holder was a sitting governor and national candidate, all of those answers were recoverable from publicly published biography and news coverage. Supplying them let him set a new password and read the mailbox, and he then published screenshots, turning a consumer account recovery convenience into a national political disclosure.","lessons":"Knowledge-based authentication is unusable for public figures whose life details are published; account recovery should use possession-based factors such as a registered device or hardware key.","confidence":"Confirmed","sources":[{"title":"Tennessee Man Sentenced for Illegally Accessing Former Governor Sarah Palin's E-mail Account","url":"https://www.justice.gov/archives/opa/pr/tennessee-man-sentenced-illegally-accessing-former-governor-sarah-palin-s-e-mail-account-and","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions","year":2008,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions"},{"title":"HP boardroom pretexting scandal: investigators impersonate directors to phone carriers","date":"2006-10-04","date_precision":"day","victim_org":"Hewlett-Packard directors, journalists and their family members","sector":"Technology","country":"United States","primary_vector":"Physical Pretexting","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No direct theft; the consequences were criminal charges, executive resignations and reputational damage.","records_affected":13,"threat_actor":"Security Outsourcing Solutions and Action Research Group investigators retained by HP","summary":"California Attorney General Bill Lockyer filed criminal charges on 4 October 2006 against former HP chairwoman Patricia Dunn, former HP ethics chief Kevin Hunsaker and three outside investigators. To identify the source of boardroom leaks to the press, investigators obtained the private telephone billing records of 12 people by impersonating them to phone carriers. Personal identifying information for 13 board members, journalists and family members was obtained and used unlawfully. Each defendant faced four felony counts.","how_it_worked":"Investigators working for HP called telephone carriers and posed as the account holders, supplying names, phone numbers and Social Security numbers to satisfy the carriers' identity checks and unlock the account. Carrier call center agents, whose job incentives favored resolving customer problems quickly, released detailed billing and call-detail records. Those records were then correlated to link directors and reporters and identify the leak. The lever was ordinary customer service helpfulness combined with weak caller verification, and the extracted action was disclosure of confidential subscriber records.","lessons":"Carriers needed possession-based caller verification such as a callback to the number of record or an account PIN rather than knowledge of publicly obtainable identifiers; the case directly prompted federal pretexting legislation for phone records.","confidence":"Confirmed","sources":[{"title":"Attorney General Lockyer Files Criminal Charges Against Former Hewlett-Packard Chairwoman, Others","url":"https://www.oag.ca.gov/news/press-releases/attorney-general-lockyer-files-criminal-charges-against-former-hewlett-packard","publisher":"California Office of the Attorney General"}],"entry_type":"incident","slug":"2006-hp-boardroom-pretexting-scandal-investigators-impersonate-directors-to-p","year":2006,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2006-hp-boardroom-pretexting-scandal-investigators-impersonate-directors-to-p"},{"title":"Kevin Mitnick's telecom pretexting campaign and 1995 arrest","date":"1995-02-15","date_precision":"day","victim_org":"Pacific Bell, Digital Equipment Corporation and other telecommunications and computer firms","sector":"Telecom","country":"United States","primary_vector":"Physical Pretexting","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the era predates generative tooling.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"Loss estimates in the case were heavily disputed at the time and are not stated here.","records_affected":null,"threat_actor":"Kevin Mitnick","summary":"Kevin Mitnick was arrested by the FBI in Raleigh, North Carolina on 15 February 1995 and found with cloned cellular phones, more than 100 cloned cellular phone codes and multiple pieces of false identification. In 1999 he pleaded guilty to four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting wire communications, and admitted copying proprietary software from large cellular telephone and computer companies. He was sentenced to 46 months plus 22 months for violating supervised release. His case is the formative reference point for social engineering as a discipline.","how_it_worked":"Mitnick's intrusions leaned far more on telephone pretexting than on exploits. He would call employees while posing as a colleague from another department, a vendor engineer or an internal support technician, using accurate internal jargon, employee names and project references gathered from earlier calls and from discarded documents. Each call extracted a small, individually harmless item, a dial-in number, a system name, a temporary password reset, and those items compounded into working access. The lever was deference to apparent internal authority and the desire to be helpful to a co-worker under time pressure.","lessons":"Identity verification for any internal request must be independent of the caller's own claims, and password resets should require an out-of-band confirmation the caller cannot supply by talking.","confidence":"Reported","sources":[{"title":"Kevin Mitnick","url":"https://en.wikipedia.org/wiki/Kevin_Mitnick","publisher":"Wikipedia"}],"entry_type":"incident","slug":"1995-kevin-mitnick-s-telecom-pretexting-campaign-and-1995-arrest","year":1995,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/1995-kevin-mitnick-s-telecom-pretexting-campaign-and-1995-arrest"}]}