{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:34.991Z","total":23,"returned":23,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text","title":"Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Consumers and card issuers worldwide (Google plaintiff)","sector":"Consumer","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"Court filings and researchers cited estimates of many millions of compromised cards; no single verified loss figure was published.","records_affected":null,"threat_actor":"Smishing Triad / 'Lighthouse' phishing-as-a-service","summary":"In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.","how_it_worked":"Victims received a text claiming an unpaid road toll, a stuck parcel or a suspended account, with a short deadline and a link to a convincing replica of the relevant agency or brand. Toll authorities and postal services were chosen because almost everyone plausibly has an outstanding interaction with one, and because the sums demanded were small enough not to warrant scrutiny. The site collected card details and then, critically, the one-time passcode sent by the bank, which let the operators load the stolen card into a mobile wallet on their own phone. The kit also spoofed sender identities and rotated domains to evade filtering.","lessons":"Banks should refuse to provision cards into wallets on the strength of an SMS passcode alone, and consumers should reach toll and postal accounts only through an app or a typed-in official domain.","confidence":"Confirmed","sources":[{"title":"Google Sues to Disrupt Chinese SMS Phishing Triad","url":"https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/","publisher":"Krebs on Security"},{"title":"Google sues to dismantle Chinese phishing platform behind US toll scams","url":"https://www.bleepingcomputer.com/news/security/google-sues-to-dismantle-chinese-phishing-platform-behind-us-toll-scams/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text"},{"title":"Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds","date":"2025-10-14","date_precision":"day","victim_org":"Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign)","sector":"Consumer","country":"Cambodia","primary_vector":"Romance / Investment Scam","secondary_vectors":["Fake Job Offer / Recruitment Lure","Smishing (SMS)"],"ai_involvement":"Unknown","ai_notes":"The indictment does not attribute the schemes to AI tooling, though contemporaneous reporting on the sector describes AI-assisted personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss"],"loss_usd":15000000000,"loss_note":"Approximately 127,271 bitcoin, worth roughly $15 billion at the time, were seized in what DOJ called its largest forfeiture action ever. This is the seizure value, not a per-victim loss total.","records_affected":null,"threat_actor":"Chen Zhi and the Prince Holding Group (indicted)","summary":"On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.","how_it_worked":"Workers inside the compounds contacted strangers through messaging apps and social media using fabricated personas, opening with an apparent wrong number or a friendly cold approach. Over weeks or months they built a personal relationship, often romantic, before introducing a cryptocurrency investment opportunity backed by a fake trading platform that displayed rising balances and permitted small early withdrawals to prove legitimacy. Victims were then pressed to deposit progressively larger sums, and any attempt to withdraw triggered demands for taxes or fees. The compound operators tracked which schemes ran from which rooms and logged the profits.","lessons":"Banks and exchanges need behavioural interdiction for customers making escalating transfers to newly seen crypto addresses after prolonged online-only relationships, since the victim will defend the transaction when asked directly.","confidence":"Reported","sources":[{"title":"Chairman of Prince Group Indicted for Operating Cambodian Forced Labor Scam Compounds","url":"https://www.justice.gov/opa/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged","publisher":"U.S. Department of Justice"},{"title":"U.S. and U.K. Take Largest Action Ever Targeting Cybercriminal Networks in Southeast Asia","url":"https://home.treasury.gov/news/press-releases/sb0278","publisher":"U.S. Department of the Treasury"}],"entry_type":"campaign","slug":"2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri","year":2025,"loss_kind":"seizure","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri"},{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},{"title":"Workday discloses CRM breach after social engineering of employees","date":"2025-08-06","date_precision":"day","victim_org":"Workday","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign","summary":"Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.","how_it_worked":"Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.","lessons":"Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.","confidence":"Confirmed","sources":[{"title":"Workday hit by social engineering data breach targeting its CRM platform","url":"https://therecord.media/workday-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Human resources firm Workday disclosed a data breach","url":"https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-workday-discloses-crm-breach-after-social-engineering-of-employees","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"},{"slug":"2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing","title":"Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Cryptocurrency holders and companies targeted by the group","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft","Identity Theft"],"loss_usd":13000000,"loss_kind":"direct_loss","loss_note":"About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.","records_affected":null,"threat_actor":"Scattered Spider","summary":"A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.","how_it_worked":"The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.","lessons":"Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.","confidence":"Confirmed","sources":[{"title":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years","url":"https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/","publisher":"Krebs on Security"},{"title":"Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution","url":"https://therecord.media/scattered-spider-affiliate-sentenced-10-years","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"},{"title":"DOJ moves to forfeit $225M in crypto traced to pig butchering victims","date":"2025-06-18","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Romance / Investment Scam","secondary_vectors":["Smishing (SMS)","Spear Phishing (Email)","Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The forfeiture complaint focuses on the money laundering trail rather than the tooling used to create the scam personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss","Identity Theft","Data Breach"],"loss_usd":19400000,"loss_note":"Over $225 million in USDT was targeted for forfeiture. DOJ identified 434 victims, of whom 60 named victims lost a combined $19.4 million; the $19.4M figure is used here as the confirmed victim loss.","records_affected":434,"threat_actor":null,"summary":"On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.","how_it_worked":"Victims were groomed online and induced to send tether to any of 93 deposit addresses controlled by the network. The proceeds were then split across up to 100 intermediary wallets to break the trail and to blend deposits from many victims, before consolidation into 22 primary exchange accounts and 122 further accounts linked by shared IP addresses and reused know-your-customer documents. The Heartland Tri-State case shows the depth of the psychological hold: a serving bank chief executive stole from his own bank, his church, an investment club and his daughter's college fund to keep feeding the scam, and received a 24-year sentence in August 2024.","lessons":"The rule that a legitimate employer never requires an employee to deposit money to be paid is the whole control; payment providers should also flag consumer crypto purchases immediately preceding transfers to newly seen platforms.","confidence":"Confirmed","sources":[{"title":"DOJ Ties Kansas Bank Collapse to $225 Million 'Pig Butchering' Seizure","url":"https://www.coindesk.com/policy/2025/06/18/doj-ties-kansas-bank-collapse-to-225-million-pig-butchering-seizure","publisher":"CoinDesk"},{"title":"New FTC Data Show Skyrocketing Consumer Reports About Game-Like Online Job Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2024/12/new-ftc-data-show-skyrocketing-consumer-reports-about-game-online-job-scams","publisher":"Federal Trade Commission"},{"title":"FBI Releases Annual Internet Crime Report","url":"https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims"},{"title":"Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers","date":"2025-06","date_precision":"month","victim_org":"US State Department; three foreign ministers, a US governor and a member of Congress","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"A State Department cable described an impostor using AI-generated voice and text to mimic Secretary of State Marco Rubio, leaving Signal voicemails for at least two targets.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.","how_it_worked":"The impostor exploited the fact that senior diplomats routinely use Signal for informal contact, so a message from an account labelled with the Secretary's official email address fit the expected pattern. Rather than opening with a request, the actor left short voicemails in a cloned voice and sent texts inviting the target to continue the conversation on Signal, which builds familiarity before anything is asked. The trust signal was the combination of a recognisable voice and a display name resembling a state.gov address, neither of which is authenticated by the platform. Targets who engaged would then have been positioned for requests for information or for account access.","lessons":"Display names and voices are not identity: diplomatic contact should be initiated or confirmed through embassy and ministry channels, and platforms used for official business need verified organisational identity.","confidence":"Confirmed","sources":[{"title":"Imposter used AI to pose as Marco Rubio and contact foreign ministers","url":"https://feeds.bbci.co.uk/news/articles/crrqkyyjewno","publisher":"BBC News"},{"title":"A Marco Rubio impostor is using AI voice to call high-level officials","url":"https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/","publisher":"The Washington Post"}],"entry_type":"incident","slug":"2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore"},{"title":"UK 'safe account' bank and police impersonation drives £450.7M in APP fraud","date":"2025-05-19","date_precision":"day","victim_org":"UK banking customers (multi-victim campaign)","sector":"Financial Services","country":"United Kingdom","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"UK Finance's 2024 reporting does not break out AI-enabled impersonation as a separate category.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Credential Theft"],"loss_usd":null,"loss_note":"Losses are reported in sterling: £1.17 billion total fraud in 2024, of which £450.7 million was authorised push payment fraud (£365.7 million personal and £84.9 million non-personal) across under 186,000 cases. Safe account impersonation losses fell 16 percent and cases fell 32 percent year on year.","records_affected":186000,"threat_actor":null,"summary":"UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.","how_it_worked":"A caller presents as the victim's bank fraud team or as police, often after a preparatory text or a spoofed caller ID matching the number on the back of the bank card. The victim is told their account has been compromised by a criminal, potentially an insider at the bank, and that the only way to protect the balance is to transfer it immediately to a new safe account which the caller supplies. Because the victim authorises the payment themselves, normal card fraud controls do not apply. The levers are institutional authority, fear of loss, and the instruction not to discuss it with branch staff who might be complicit.","lessons":"No bank or police force ever asks a customer to move money to a safe account; confirmation of payee checks, in-app warnings at the point of transfer and mandatory delays on first-time large payees are the effective controls.","confidence":"Confirmed","sources":[{"title":"Fraud continues to pose a major threat with over £1 billion stolen in 2024","url":"https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2025-press-release","publisher":"UK Finance"},{"title":"Smishing: Package Tracking Text Scams","url":"https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams","publisher":"United States Postal Inspection Service"}],"entry_type":"campaign","slug":"2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud"},{"title":"FBI warns of AI voice-cloning campaign impersonating senior US officials","date":"2025-05-15","date_precision":"day","victim_org":"Current and former senior US federal and state officials and their contacts","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The FBI stated that malicious actors were sending AI-generated voice messages, alongside text messages, that purported to come from senior US officials.","outcomes":["Credential Theft","Identity Theft","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.","how_it_worked":"The campaign traded on the recipient's relationship with a named senior official rather than on any technical exploit. An initial text or voicemail in a cloned voice established that the official was reaching out personally, which for a colleague or former colleague is unremarkable. Once a reply came, targets were invited to continue on a separate messaging platform, a request that reads as security-conscious in government circles, and the link supplied there led to a credential-harvesting page or a device-linking flow. Each successful compromise fed the next round, since messages arriving from a genuinely compromised official account carry far more weight than any spoof.","lessons":"Officials and their contacts should verify unexpected outreach through a separately known number or channel, and adopt phishing-resistant authentication on personal accounts, which are typically the weak point rather than official systems.","confidence":"Confirmed","sources":[{"title":"Senior US Officials Impersonated in Malicious Messaging Campaign (PSA250515)","url":"https://www.ic3.gov/PSA/2025/PSA250515","publisher":"FBI Internet Crime Complaint Center"},{"title":"FBI warns senior US officials are being impersonated using texts, AI-based voice cloning","url":"https://www.cybersecuritydive.com/news/fbi-us-officials-impersonated-text-ai-voice/748334/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","slug":"2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials"},{"title":"AI voice impersonation of White House chief of staff Susie Wiles targets Republicans","date":"2025-05","date_precision":"month","victim_org":"The White House; senators, governors and business executives contacted","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Officials cited by news reports believed the impersonator used AI to replicate Susie Wiles's voice on phone calls; the contact list appears to have come from her compromised personal phone.","outcomes":["Identity Theft","Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.","how_it_worked":"The attack started from a compromised personal phone, which supplied both the target list and the context needed to make each approach specific. Messages and calls appeared to come from someone recipients genuinely deal with, and the requests, a pardon shortlist or a favour involving money, are the kind of sensitive, informal business that plausibly happens by phone rather than through official channels precisely because it is delicate. The cloned voice removed the last check most recipients would apply. Suspicion emerged from content rather than technology: some recipients noticed the requests did not match how Wiles operates, and the messages came from an unfamiliar number.","lessons":"Senior staff should keep official business off personal devices and pre-agree verification practices with frequent contacts, so that an unexpected request from a new number is confirmed before anyone acts.","confidence":"Reported","sources":[{"title":"White House responds to attempts to impersonate Trump advisor Susie Wiles","url":"https://www.newsweek.com/white-house-susie-wiles-trump-impersonate-fbi-2078802","publisher":"Newsweek"},{"title":"Trump officials keep getting targeted by 'vishing'","url":"https://time.com/7301176/impersonation-ai-voice-vishing-scam-rubio-wiles-trump-fbi-advice/","publisher":"TIME"}],"entry_type":"incident","slug":"2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets"},{"title":"Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO","date":"2025-03","date_precision":"month","victim_org":"Unnamed multinational firm, Singapore office","sector":"Other","country":"Singapore","primary_vector":"Deepfake Video Call","secondary_vectors":["Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Singapore Police said deepfake technology was used to render the company's chief financial officer, chief executive and other officials during a Zoom video conference.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":499000,"loss_note":"Over US$499,000 transferred; funds recovered by Singapore and Hong Kong police within days","records_affected":null,"threat_actor":null,"summary":"On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.","how_it_worked":"The approach opened on WhatsApp, a channel where an executive contact request feels informal but not alarming, and offered a business rationale, a confidential regional restructuring, that justified both secrecy and an unusual payment. The video conference supplied the decisive trust signal by putting the target in a room with the two most senior people in his reporting line plus other familiar faces. An outside lawyer and an NDA added procedural theatre that made the transaction look governed rather than improvised, while also formalising the instruction not to tell colleagues. Compliance was easy because the finance director was doing precisely his job, executing a payment approved by the CFO.","lessons":"Payments authorised on a video call should still require callback verification to a directory-listed number and dual approval; the fast bank and police escalation here is what made recovery possible.","confidence":"Confirmed","sources":[{"title":"Singapore firm nearly lost $500,000 after deepfake video scam: police","url":"https://www.hcamag.com/asia/specialisation/hr-technology/singapore-firm-nearly-lost-500000-after-deepfake-video-scam-police/531450","publisher":"Human Resources Director Asia"}],"entry_type":"incident","slug":"2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w"},{"title":"Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question","date":"2024-07","date_precision":"month","victim_org":"Ferrari","sector":"Manufacturing","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The caller used a synthetic voice that reproduced chief executive Benedetto Vigna's southern Italian accent; the target noticed slightly mechanical intonation.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.","how_it_worked":"The approach started on WhatsApp from an unfamiliar number, with the mismatch explained away by the claim that the deal was so sensitive it required a separate line, a pretext that turns a red flag into evidence of importance. The escalation to a voice call added the strongest trust signal available, the chief executive's distinctive accent and manner discussing an unannounced acquisition. Confidentiality supplied the reason not to consult anyone, and a currency hedge gave a technical, plausible-sounding financial action. The executive interrupted the frame by asking a shared-knowledge question with no public answer, which the synthetic caller could not handle.","lessons":"A pre-agreed challenge based on shared private knowledge, or a codeword for executive payment requests, reliably breaks a voice clone that cannot improvise.","confidence":"Reported","sources":[{"title":"Ferrari narrowly dodges deepfake scam simulating deal-hungry CEO","url":"https://www.spokesman.com/stories/2024/jul/26/ferrari-narrowly-dodges-deepfake-scam-simulating-d/","publisher":"Bloomberg via The Spokesman-Review"},{"title":"Ferrari CEO Deepfake Shows Growing Threat of AI Scams Impersonating Executives","url":"https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo","publisher":"Bloomberg"}],"entry_type":"incident","slug":"2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu"},{"title":"Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks","date":"2024-04-12","date_precision":"day","victim_org":"US drivers and toll customers (multi-victim campaign)","sector":"Transportation & Logistics","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"The IC3 alert does not attribute the campaign to AI tooling.","outcomes":["Identity Theft","Wire Fraud / Financial Loss","Credential Theft"],"loss_usd":null,"loss_note":"IC3 did not publish an aggregate loss figure for the toll smishing campaign.","records_affected":2000,"threat_actor":null,"summary":"On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.","how_it_worked":"Recipients received a text stating that an outstanding toll amount of $12.51 had been noticed on their record and that visiting a link would settle the balance and avoid a $50 late fee. The lever is a small, plausible, low-stakes debt: the sum is too trivial to warrant checking with the tolling authority, and the late fee creates just enough urgency to act immediately. The linked site cloned the state tolling agency's branding and collected card details and personal information for payment fraud and identity theft. Attackers rotated the impersonated agency by recipient area code, so the message named a tolling authority the target plausibly uses.","lessons":"Never transact from a link in an unsolicited text; navigate to the tolling agency independently. Carrier-level detection of newly registered look-alike tolling domains is the scalable control.","confidence":"Confirmed","sources":[{"title":"Smishing Scam Regarding Debt for Road Toll Services","url":"https://www.ic3.gov/PSA/2024/PSA240412","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"campaign","slug":"2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee"},{"title":"LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO","date":"2024-04","date_precision":"month","victim_org":"LastPass","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.","how_it_worked":"The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.","lessons":"A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.","confidence":"Confirmed","sources":[{"title":"Attempted Audio Deepfake Call Targets LastPass Employee","url":"https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee","publisher":"LastPass"},{"title":"LastPass: Hackers targeted employee in failed deepfake CEO call","url":"https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/","publisher":"BleepingComputer"},{"title":"LastPass employee targeted via an audio deepfake call","url":"https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"},{"title":"Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee","date":"2023-08-27","date_precision":"day","victim_org":"Retool","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Voice Clone / Audio Deepfake","Vishing (Voice Phishing)","Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Retool stated the caller used a deepfaked voice imitating a specific member of its IT team, whom the target employee knew. This is one of the earliest well-documented uses of voice cloning in a corporate intrusion.","outcomes":["Data Breach","Cryptocurrency Theft","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Retool reported no loss of its own; downstream, cryptocurrency customer Fortress Trust separately reported a theft of roughly $15 million tied to the compromise, a figure attributed to Fortress Trust rather than confirmed by Retool.","records_affected":27,"threat_actor":null,"summary":"Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.","how_it_worked":"The employee received a text claiming to be from Retool IT about a payroll and healthcare enrolment issue, with a link to a page cloning the company's internal identity portal. After the employee submitted credentials and an MFA code, the attacker phoned them; the voice was a deepfake of a specific IT team member the employee recognised, and the caller was familiar with office layout, colleagues and internal processes. During the call the employee provided an additional MFA code, which let the attacker add their own device to the employee's Okta account. From there they reached the employee's Google account, where Authenticator's cloud sync had backed up OTP seeds, and used those to pivot into internal admin systems and alter customer accounts.","lessons":"Voice is no longer an identity proof; hardware security keys plus a policy that MFA codes are never read aloud, and disabling authenticator cloud sync on enterprise accounts, close both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Retool blames breach on Google Authenticator MFA cloud sync feature","url":"https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/","publisher":"BleepingComputer"},{"title":"Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients","url":"https://thehackernews.com/2023/09/retool-falls-victim-to-sms-based.html","publisher":"The Hacker News"},{"title":"Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks","url":"https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/","publisher":"SecurityWeek"},{"title":"When MFA isn't actually MFA","url":"https://retool.com/blog/mfa-isnt-mfa","publisher":"Retool"}],"entry_type":"incident","slug":"2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp"},{"title":"Coinbase employee phished by SMS then talked through by a fake IT caller","date":"2023-02-05","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.","outcomes":["Data Breach","Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No customer funds or customer data were lost; exposure was limited to some employee contact details.","records_affected":null,"threat_actor":"Reported as the 0ktapus / Scattered Spider cluster","summary":"In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.","how_it_worked":"The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.","lessons":"Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.","confidence":"Confirmed","sources":[{"title":"Social Engineering - A Coinbase Case Study","url":"https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study","publisher":"Coinbase"},{"title":"Coinbase cyberattack targeted employees with fake SMS alert","url":"https://www.bleepingcomputer.com/news/security/coinbase-cyberattack-targeted-employees-with-fake-sms-alert/","publisher":"BleepingComputer"},{"title":"Coinbase breached by social engineers, employee data stolen","url":"https://news.sophos.com/en-us/2023/02/21/coinbase-breached-by-social-engineers-employee-data-stolen","publisher":"Sophos News"}],"entry_type":"incident","slug":"2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller"},{"title":"FTC: business and government impersonation scams hit $1.1 billion in 2023","date":"2023","date_precision":"year","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Callback Phishing (TOAD)"],"ai_involvement":"Unknown","ai_notes":"The 2024 data spotlight does not break out AI-enabled impersonation.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft","Identity Theft"],"loss_usd":1100000000,"loss_note":"$1.1 billion in combined reported losses to business and government impersonation scams in 2023, more than triple the $310 million reported in 2020. Over 330,000 business impersonation reports and nearly 160,000 government impersonation reports, together about 48 percent of fraud reports made directly to the FTC.","records_affected":490000,"threat_actor":null,"summary":"An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.","how_it_worked":"The dominant openers are bogus account security alerts purporting to come from a company such as Amazon or from a bank, claiming unauthorised activity and steering the victim toward transferring funds or feeding cash into a Bitcoin ATM to protect their money. A second pattern is the fake subscription renewal notice, often impersonating Geek Squad, which offers a refund and then coerces the victim into buying gift cards and reading out the numbers. The most damaging innovation is the multi-agency handoff: scammers who begin as a business then transfer the victim to a fake bank representative, FBI agent or even a purported FTC employee, so that each successive persona corroborates the last.","lessons":"No government agency or legitimate business asks anyone to move money to protect it or to pay in gift cards or Bitcoin ATM deposits; retailer and ATM operator interdiction prompts at the point of payment are the strongest late-stage control.","confidence":"Confirmed","sources":[{"title":"Impersonation scams: not what they used to be","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2024/04/impersonation-scams-not-what-they-used-be","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023"},{"title":"Activision breached after an HR employee falls for an SMS phishing message","date":"2022-12-04","date_precision":"day","victim_org":"Activision Blizzard","sector":"Gaming & Casino","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":19444,"threat_actor":null,"summary":"Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.","how_it_worked":"The attacker sent text messages to an HR employee that led to credential capture, then used the account to move into internal collaboration systems. Once inside Slack, the intruder posted messages attempting to lure additional employees into clicking further links, using the credibility of an internal account to widen the compromise. They also accessed a spreadsheet of employee information including names, email addresses, phone numbers, salaries and office locations, and the marketing content calendar. Screenshots of the internal Slack activity and the stolen data were later published by researchers and on a hacking forum.","lessons":"Phishing-resistant MFA on corporate identity, plus alerting on internal chat messages that contain newly-registered external links, limits both the initial takeover and the internal spread.","confidence":"Reported","sources":[{"title":"Activision confirms data breach exposing employee and game info","url":"https://www.bleepingcomputer.com/news/security/activision-confirms-data-breach-exposing-employee-and-game-info/","publisher":"BleepingComputer"},{"title":"Hackers steal Activision games and employee data","url":"https://techcrunch.com/2023/02/21/hackers-allegedly-steal-activision-games-and-employee-data/","publisher":"TechCrunch"},{"title":"Activision Data Breach Contains Employee Details, Call of Duty's Future, and More","url":"https://insider-gaming.com/activision-data-breach/","publisher":"Insider Gaming"},{"title":"Threat actors leak Activision employee data on hacking forum","url":"https://securityaffairs.com/142779/data-breach/activision-data-leak.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2022-activision-breached-after-an-hr-employee-falls-for-an-sms-phishing-messa","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-activision-breached-after-an-hr-employee-falls-for-an-sms-phishing-messa"},{"title":"Zendesk breach followed successful SMS phishing of employees","date":"2022-10","date_precision":"month","victim_org":"Zendesk","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.","how_it_worked":"Employees received text messages that led to a page impersonating Zendesk's single sign-on portal. Several staff entered their credentials, which the attacker used to authenticate to internal systems. Because Zendesk operates a support ticketing platform for other businesses, mailboxes and ticket stores can contain customer correspondence, attachments and account details belonging to Zendesk's own clients, which is what created the downstream exposure. Zendesk described the incident as a sophisticated SMS phishing campaign, disabled the affected accounts and notified customers whose service data may have been reached.","lessons":"SaaS providers holding tenant data should mandate phishing-resistant MFA for all staff and alert on employee logins from unfamiliar devices to tenant-facing consoles.","confidence":"Reported","sources":[{"title":"Zendesk Hacked After Employees Fall for Phishing Attack","url":"https://www.securityweek.com/zendesk-hacked-after-employees-fall-for-phishing-attack/","publisher":"SecurityWeek"},{"title":"Compromised Zendesk Employee Credentials Lead to Breach","url":"https://www.darkreading.com/application-security/compromised-zendesk-employee-credentials-breach","publisher":"Dark Reading"},{"title":"Zendesk hit by phishing-related data breach","url":"https://www.scworld.com/brief/zendesk-hit-by-phishing-related-data-breach","publisher":"SC Media"}],"entry_type":"incident","slug":"2022-zendesk-breach-followed-successful-sms-phishing-of-employees","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-zendesk-breach-followed-successful-sms-phishing-of-employees"},{"title":"DoorDash customer data exposed through phished third-party vendor employees","date":"2022-08-25","date_precision":"day","victim_org":"DoorDash","sector":"Transportation & Logistics","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (the campaign that also hit Twilio)","summary":"DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.","how_it_worked":"The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.","lessons":"Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.","confidence":"Confirmed","sources":[{"title":"DoorDash hit by data breach linked to Twilio hackers","url":"https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/","publisher":"TechCrunch"},{"title":"DoorDash discloses new data breach tied to Twilio hackers","url":"https://www.bleepingcomputer.com/news/security/doordash-discloses-new-data-breach-tied-to-twilio-hackers/","publisher":"BleepingComputer"},{"title":"DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others","url":"https://www.securityweek.com/doordash-data-compromised-following-twilio-hack/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ"},{"title":"Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers","date":"2022-08-04","date_precision":"day","victim_org":"Twilio","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the kit relayed credentials to operators via Telegram in real time.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published across the affected organisations.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (tracked by Okta and Group-IB; overlaps with Scattered Spider reporting)","summary":"In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.","how_it_worked":"The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.","lessons":"SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.","confidence":"Confirmed","sources":[{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Twilio confirms data breach after its employees got phished","url":"https://www.helpnetsecurity.com/2022/08/09/twilio-phished-data-breach/","publisher":"Help Net Security"},{"title":"Twilio says breach also compromised Authy two-factor app users","url":"https://techcrunch.com/2022/08/26/twilio-breach-authy/","publisher":"TechCrunch"},{"title":"Incident Report: Employee and Customer Account Compromise","url":"https://www.twilio.com/en-us/blog/archive/2022/august-2022-social-engineering-attack","publisher":"Twilio"}],"entry_type":"incident","slug":"2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust"},{"slug":"2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org","title":"0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations","date":"2022-08","date_precision":"month","year":2022,"victim_org":"Over 130 organisations targeted (Group-IB tracked campaign)","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":9931,"threat_actor":"0ktapus (linked to Scattered Spider / UNC3944 activity)","summary":"Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.","how_it_worked":"Employees received text messages, often outside working hours, claiming their VPN session had expired or that a schedule change required immediate action, with a link to what looked like their employer's Okta single sign-on page. The pages were cloned per target company, so each recipient saw their own branding. Victims typed their username, password and then the one-time MFA code, all of which were relayed to the operators in real time and used to log in before the code expired. SMS was chosen deliberately: it arrives on a phone, outside corporate email defences, and reads as urgent IT housekeeping rather than an attack.","lessons":"Only phishing-resistant authentication such as FIDO2 security keys defeats a real-time relay of passwords and one-time codes; SMS-delivered lures also need out-of-band IT verification channels staff actually know to use.","confidence":"Confirmed","sources":[{"title":"Roasting 0ktapus: The phishing campaign going after Okta identity credentials","url":"https://www.group-ib.com/blog/0ktapus/","publisher":"Group-IB"},{"title":"0ktapus Phishing Campaign Targets Okta Identity Credentials","url":"https://www.infosecurity-magazine.com/news/0ktapus-phishing-targets-okta/","publisher":"Infosecurity Magazine"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org"},{"title":"Cloudflare blocks the same SMS phishing attack that breached Twilio","date":"2022-07-20","date_precision":"day","victim_org":"Cloudflare","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; the intrusion attempt failed at the authentication step.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (same actor as the Twilio campaign)","summary":"On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.","how_it_worked":"The SMS lures directed staff to a convincing clone of Cloudflare's Okta sign-in page. Credentials typed into the clone were relayed in real time over Telegram, and the page also prompted for the second factor so operators could complete the login within the code's validity window. It additionally attempted to push AnyDesk remote access software to visitors for persistence if the credential path failed. Three employees submitted credentials, but the hardware keys are bound to the legitimate origin and would not produce a valid assertion for the attacker's domain, so no session was ever established. Cloudflare Gateway also blocked the malicious domain on corporate devices, and none of the targets installed the remote access tool.","lessons":"This is the control demonstration for the whole category: origin-bound hardware security keys make credential relay structurally impossible, regardless of how convincing the lure is.","confidence":"Confirmed","sources":[{"title":"The mechanics of a sophisticated phishing scam and how we stopped it","url":"https://blog.cloudflare.com/2022-07-sms-phishing-attacks/","publisher":"Cloudflare Blog"},{"title":"Cloudflare employees also hit by hackers behind Twilio breach","url":"https://www.bleepingcomputer.com/news/security/cloudflare-employees-also-hit-by-hackers-behind-twilio-breach/","publisher":"BleepingComputer"},{"title":"Cloudflare scuppers Twilio-like cyber attack with hardware keys","url":"https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys","publisher":"IT Pro"}],"entry_type":"incident","slug":"2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio"}]}