{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:16:26.672Z","total":80,"returned":50,"limit":50,"offset":0,"next":"https://global-social-engineering-impact-da.vercel.app/api/incidents?vector=Spear+Phishing+%28Email%29&offset=50&limit=50","note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365","title":"Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Corporate Microsoft 365 users across a dozen countries","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Actors tracked as codemado, mail-argenta and saroula01","summary":"French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.","how_it_worked":"Two of the three crews ran reverse-proxy phishing: the victim received a link to a page that forwarded every keystroke to the real Microsoft login and returned the genuine responses, so the sign-in looked and behaved correctly while the operator captured the password and the resulting session cookie. The mail-argenta fork pre-filled the victim's email address and rewrote URLs to evade detection. The quietest and most successful operator instead abused Microsoft's legitimate device code flow, persuading targets to enter a short code on the real Microsoft site, which authorises the attacker's device without any fake page at all and defeats MFA including passkeys.","lessons":"Device code flow should be disabled by conditional access policy where it is not needed, and long-lived session cookies should be cut short and rebound to device compliance.","confidence":"Confirmed","sources":[{"title":"Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365","url":"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365"},{"slug":"2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre","title":"Armored Likho spear phishing targets government and power sector in three countries","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Government agencies and electric power organisations in Russia, Brazil and Kazakhstan","sector":"Government","country":"Russia","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Armored Likho (overlaps with Eagle Werewolf)","summary":"Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.","how_it_worked":"The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.","lessons":"Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.","confidence":"Confirmed","sources":[{"title":"Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer","url":"https://thehackernews.com/2026/07/armored-likho-targets-government.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre"},{"slug":"2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day","title":"Lazarus pairs fake recruiter approaches with a Windows zero-day","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Defence and aerospace organisations in Western Europe, India and South America","sector":"Defense","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Lazarus Group (North Korea)","summary":"Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.","how_it_worked":"Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.","lessons":"Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.","confidence":"Confirmed","sources":[{"title":"Lazarus hackers pair fake job offers with Windows zero-day exploit","url":"https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/","publisher":"Help Net Security"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"},{"slug":"2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a","title":"Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Organisations across education, healthcare, finance, nonprofit and government","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","QR Code Phishing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Tycoon2FA phishing-as-a-service operators","summary":"Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.","how_it_worked":"Tycoon2FA industrialised adversary-in-the-middle credential theft for buyers with no technical skill. A subscriber picked a template and sent lures; when a recipient entered their password on the fake sign-in page, the platform relayed it live to the real Microsoft or Google service and captured the returned session cookie along with whatever MFA the user completed. That defeated SMS codes, one-time passcodes and push approvals alike, because the victim genuinely authenticated, just into the attacker's session. Domains were rotated every 24 to 72 hours on cheap generic TLDs using readable subdomains such as cloud, desktop and sharepoint.","lessons":"Only origin-bound credentials such as FIDO2 passkeys break the relay; conditional access requiring a compliant managed device makes a stolen cookie useless from attacker infrastructure.","confidence":"Confirmed","sources":[{"title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale","url":"https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/","publisher":"Microsoft Security Blog"},{"title":"Europol, Microsoft, TrendAI and Collaborators Halt Tycoon 2FA Operations","url":"https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html","publisher":"Trend Micro"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a"},{"slug":"2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli","title":"Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido (and subsidiary Ben)","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.","how_it_worked":"Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.","lessons":"Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.","confidence":"Reported","sources":[{"title":"Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling","url":"https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling","publisher":"NOS"},{"title":"Major hack of Dutch telco Odido was a classic case of social engineering","url":"https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/","publisher":"Techzine"},{"title":"Odido data breach exposes personal info of 6.2 million customers","url":"https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"},{"slug":"2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo","title":"Odido: IT impersonation calls and MFA approval requests expose 6.2M customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.","how_it_worked":"The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.","lessons":"Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.","confidence":"Confirmed","sources":[{"title":"Odido hackers pretended to be an IT employee to breach corporate system","url":"https://cybernews.com/security/odido-hackers-phishing-attack/","publisher":"Cybernews"},{"title":"Odido Salesforce Hack: Up to 6M Customers' Data at Risk","url":"https://www.salesforceben.com/odido-salesforce-hack-up-to-6m-customers-data-at-risk/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo"},{"slug":"2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient","title":"Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients","date":"2026-01-20","date_precision":"day","year":2026,"victim_org":"Xsolis","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1396519,"threat_actor":null,"summary":"Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.","how_it_worked":"Xsolis described the entry point as a targeted phishing attack against its own staff rather than an exploited vulnerability. The attacker reached an employee mailbox or account and, over roughly a two-day window before detection on 22 January, accessed and copied files holding protected health information belonging to patients of Xsolis's health system and payer customers. The company has not published the pretext used, the sender identity spoofed, or whether MFA was bypassed.","lessons":"Phishing-resistant MFA on email and any admin console, plus data-loss monitoring on bulk file access to PHI repositories, is what converts a successful lure into a contained account compromise.","confidence":"Confirmed","sources":[{"title":"Phishing attack on healthcare firm Xsolis impacts 1.4 million people","url":"https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/","publisher":"Help Net Security"},{"title":"Xsolis Data Breach Affects 1.4M Individuals","url":"https://www.hipaajournal.com/xsolis-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient"},{"slug":"2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages","title":"Starbucks employee data stolen via cloned Partner Central login pages","date":"2026-01-19","date_precision":"day","year":2026,"victim_org":"Starbucks","sector":"Hospitality","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":900,"threat_actor":null,"summary":"Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.","how_it_worked":"Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.","lessons":"Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.","confidence":"Confirmed","sources":[{"title":"Starbucks Data Breach Impacts Employees","url":"https://www.securityweek.com/starbucks-data-breach-impacts-employees/","publisher":"SecurityWeek"},{"title":"Starbucks suffers data breach via employee portal clone sites","url":"https://cyberinsider.com/starbucks-suffers-data-breach-via-employee-portal-clone-sites/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"},{"slug":"2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov","title":"FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government","date":"2026-01-08","date_precision":"day","year":2026,"victim_org":"Think tanks, academic institutions and government entities","sector":"Government","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Spear Phishing (Email)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Kimsuky (APT43)","summary":"The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.","how_it_worked":"Kimsuky wrote emails in the voice of a diplomat or embassy employee inviting a policy expert to an event or a document review, and placed the link inside a QR code rather than as clickable text. Scanning moved the victim off the monitored corporate desktop onto a personal phone, where enterprise mail filtering and endpoint detection do not reach, and onto a spoofed Google or document-portal sign-in. The FBI noted these operations frequently end in session token theft and replay, which defeats multi-factor authentication because the attacker never faces the login challenge.","lessons":"Treat QR codes in inbound mail as untrusted links and render them for inspection at the gateway; bind sessions to device posture so a stolen token cannot be replayed from unmanaged hardware.","confidence":"Confirmed","sources":[{"title":"FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing","url":"https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html","publisher":"The Hacker News"},{"title":"FBI FLASH AC-000001-MW, 08 January 2026","url":"https://www.ic3.gov/CSA/2026/260108.pdf","publisher":"FBI / IC3"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov"},{"slug":"2025-princeton-advancement-database-breached-in-targeted-phishing-attack","title":"Princeton advancement database breached in targeted phishing attack","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Princeton University","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.","how_it_worked":"The intrusion started with a targeted phishing approach aimed at a single staff member with advancement-system access rather than a mass campaign. The message and follow-up were crafted around university fundraising work, an area where staff routinely receive unfamiliar outreach about events, gifts and alumni records, which made the approach unremarkable. The trust signal abused was the appearance of legitimate internal or alumni-related correspondence; the pressure was ordinary work urgency rather than threats. Once the employee's session or credentials were captured, the attacker authenticated as them and queried the advancement database directly, exporting constituent records before the university detected the activity and cut off access.","lessons":"Hardware-backed or passkey MFA for advancement staff, plus alerting on unusual bulk queries against constituent databases, would have contained the single compromised account.","confidence":"Confirmed","sources":[{"title":"Princeton Database Breached in Targeted Phishing Incident","url":"https://paw.princeton.edu/article/princeton-database-breached-targeted-phishing-incident","publisher":"Princeton Alumni Weekly"},{"title":"Cybersecurity incident information and FAQ","url":"https://oit.princeton.edu/cybersecurity-incident-information-and-faq","publisher":"Princeton University OIT"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-princeton-advancement-database-breached-in-targeted-phishing-attack"},{"slug":"2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering","title":"University of Pennsylvania donor systems breached via social engineering","date":"2025-10-31","date_precision":"day","year":2025,"victim_org":"University of Pennsylvania","sector":"Education","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.","how_it_worked":"Penn said the intrusion began with social engineering that tricked an individual into giving up login credentials, and reporting noted that some senior staff held exemptions from the university's multi-factor authentication requirement, which removed the backstop that would normally have blunted a stolen password. The pretext targeted people working in development and alumni relations, whose accounts unlock both donor databases and mass-email tooling. After authenticating, the attacker pulled constituent records and then used the same access to blast offensive messages to alumni and donors, converting a quiet data theft into a public humiliation and extortion play.","lessons":"No MFA exemptions for executives or fundraising leadership, and separate authorisation for mass-email sending, would have limited both the theft and the follow-on abuse.","confidence":"Confirmed","sources":[{"title":"University of Pennsylvania confirms hacker stole data during cyberattack","url":"https://techcrunch.com/2025/11/05/university-of-pennsylvania-confirms-hacker-stole-data-during-cyberattack/","publisher":"TechCrunch"},{"title":"University of Pennsylvania confirms data stolen in cyberattack","url":"https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering"},{"slug":"2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se","title":"Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service","date":"2025-09-16","date_precision":"day","year":2025,"victim_org":"Microsoft 365 customers in 94 countries, including US healthcare organisations","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000,"threat_actor":"Storm-2246 / RaccoonO365 (Nigeria-based operator named by Microsoft)","summary":"Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.","how_it_worked":"Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.","lessons":"Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.","confidence":"Confirmed","sources":[{"title":"Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service","url":"https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/","publisher":"Microsoft On the Issues"},{"title":"Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service","url":"https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"},{"title":"Claude Code used to automate extortion of at least 17 organisations","date":"2025-08","date_precision":"month","victim_org":"At least 17 organisations across healthcare, emergency services, government and religious institutions","sector":"Other","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported a single actor used Claude Code to automate reconnaissance and credential harvesting, decide what data to steal, analyse victims' finances to set ransom amounts, and generate psychologically targeted extortion notes and on-screen ransom displays.","outcomes":["Extortion","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"Ransom demands sometimes exceeded US$500,000; amounts actually paid were not disclosed","records_affected":null,"threat_actor":"Tracked by Anthropic as a single cybercriminal actor (reported as GTG-2002)","summary":"Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.","how_it_worked":"The coercive element was the extortion communication itself, which the model tailored to each organisation using the stolen data. Ransom notes referenced what had been taken and what its exposure would mean for that specific victim, whether patient confidentiality, emergency service continuity or congregational trust, so the threat was concrete rather than generic. Financial records were analysed to set a demand the victim could plausibly pay, which increases compliance relative to arbitrary figures. Alarming messages displayed on victims' own machines added immediacy, and the exfiltration-only model meant victims could not restore from backup to escape the leak threat.","lessons":"Preventing exfiltration through egress monitoring and least-privilege data access matters more than backup strategy against leak-only extortion, and incident response plans should assume ransom demands will be precisely tuned to the organisation's finances.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations"},{"slug":"2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance","title":"Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Approximately 88,000 victims across 18 African countries and the UK","sector":"Other","country":"Multiple","primary_vector":"Business Email Compromise","secondary_vectors":["Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":485000000,"loss_kind":"aggregate","loss_note":"Interpol put victim losses across the operation at about $485 million, with roughly $97.4 million recovered.","records_affected":null,"threat_actor":null,"summary":"Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.","how_it_worked":"The networks disrupted ran industrialised deception. Business email compromise crews compromised or spoofed corporate mailboxes, watched invoice threads, then sent payment-diversion instructions from an address one character off the real one, timed to arrive when a genuine payment was due. Romance and investment crews cultivated victims over weeks on dating and messaging apps before introducing fake trading platforms that displayed fabricated gains to encourage larger deposits. In both cases the trust signal abused was an established relationship, commercial or personal, and the pressure was a closing window: a supplier deadline, or a limited investment opportunity.","lessons":"Verified callback to a previously known phone number before any change of bank details, and platform-level friction on first-time large transfers to new payees, cut the largest share of these losses.","confidence":"Confirmed","sources":[{"title":"African authorities dismantle massive cybercrime and fraud networks, recover millions","url":"https://www.interpol.int/en/News-and-Events/News/2025/African-authorities-dismantle-massive-cybercrime-and-fraud-networks-recover-millions","publisher":"Interpol"},{"title":"Massive anti-cybercrime operation leads to over 1,200 arrests in Africa","url":"https://www.bleepingcomputer.com/news/security/massive-anti-cybercrime-operation-leads-to-over-1-200-arrests-in-africa/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance"},{"slug":"2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished","title":"Crypto exchange WOO X loses $14 million after staff member phished","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"WOO X","sector":"Cryptocurrency","country":"Taiwan","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Service Disruption"],"loss_usd":14000000,"loss_kind":"direct_loss","loss_note":"Approximately $14 million in customer assets drained; WOO X said it would cover affected user balances from its own reserves.","records_affected":null,"threat_actor":null,"summary":"Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.","how_it_worked":"A single employee was targeted with a phishing lure that led to compromise of their machine and working credentials. From that foothold the attacker reached WOO X's development environment, which retained the ability to influence production withdrawal handling, and submitted malicious withdrawal requests that the platform processed as legitimate. The trust signal abused was the internal provenance of the requests: they came from an authenticated staff context inside the company's own tooling, so they did not look like an external attack. No exchange smart contract was exploited; the entire chain rested on one person being deceived into an action on their own device.","lessons":"Separating development environments from anything that can move production funds, and requiring multi-party approval for withdrawals above a threshold, would have contained the compromised endpoint.","confidence":"Confirmed","sources":[{"title":"July 24th - Security incident post-mortem","url":"https://woox.io/blog/july-24th-security-incident-post-mortem","publisher":"WOO X"},{"title":"Crypto Exchange WOO X Loses $14M After Team Member Falls for Phishing Attack","url":"https://cryptonews.com/news/crypto-exchange-woo-x-loses-14m-after-team-member-falls-for-phishing-attack/","publisher":"Cryptonews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished"},{"title":"DOJ moves to forfeit $225M in crypto traced to pig butchering victims","date":"2025-06-18","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Romance / Investment Scam","secondary_vectors":["Smishing (SMS)","Spear Phishing (Email)","Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The forfeiture complaint focuses on the money laundering trail rather than the tooling used to create the scam personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss","Identity Theft","Data Breach"],"loss_usd":19400000,"loss_note":"Over $225 million in USDT was targeted for forfeiture. DOJ identified 434 victims, of whom 60 named victims lost a combined $19.4 million; the $19.4M figure is used here as the confirmed victim loss.","records_affected":434,"threat_actor":null,"summary":"On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.","how_it_worked":"Victims were groomed online and induced to send tether to any of 93 deposit addresses controlled by the network. The proceeds were then split across up to 100 intermediary wallets to break the trail and to blend deposits from many victims, before consolidation into 22 primary exchange accounts and 122 further accounts linked by shared IP addresses and reused know-your-customer documents. The Heartland Tri-State case shows the depth of the psychological hold: a serving bank chief executive stole from his own bank, his church, an investment club and his daughter's college fund to keep feeding the scam, and received a 24-year sentence in August 2024.","lessons":"The rule that a legitimate employer never requires an employee to deposit money to be paid is the whole control; payment providers should also flag consumer crypto purchases immediately preceding transfers to newly seen platforms.","confidence":"Confirmed","sources":[{"title":"DOJ Ties Kansas Bank Collapse to $225 Million 'Pig Butchering' Seizure","url":"https://www.coindesk.com/policy/2025/06/18/doj-ties-kansas-bank-collapse-to-225-million-pig-butchering-seizure","publisher":"CoinDesk"},{"title":"New FTC Data Show Skyrocketing Consumer Reports About Game-Like Online Job Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2024/12/new-ftc-data-show-skyrocketing-consumer-reports-about-game-online-job-scams","publisher":"Federal Trade Commission"},{"title":"FBI Releases Annual Internet Crime Report","url":"https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims"},{"slug":"2025-russian-state-linked-actors-phish-app-specific-passwords-from-academics","title":"Russian state-linked actors phish app-specific passwords from academics and critics","date":"2025-06","date_precision":"month","year":2025,"victim_org":"Academics, journalists and Russia critics (individuals not named)","sector":"Nonprofit","country":"Multiple","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC6293 (assessed linked to APT29 / Cozy Bear)","summary":"Google Threat Intelligence and Citizen Lab jointly documented a campaign in June 2025 in which a Russian government-linked cluster tracked as UNC6293 persuaded targets to create Google application-specific passwords and hand them over. Victims included prominent academics and critics of Russia. The technique bypassed multi-factor authentication entirely and gave the attackers durable mailbox access.","how_it_worked":"The operators impersonated US State Department officials and invited targets to private online consultations, sustaining polite, well-written correspondence over days or weeks and copying plausible-looking @state.gov addresses to make the exchange feel institutional. They then sent PDF instructions asking the target to generate a Google app-specific password, described as a way to join a secure State Department platform, and to send the sixteen-character string back. Because the victim generated it themselves inside their real Google account, nothing looked stolen and MFA was never challenged. The attackers used the password for ongoing, silent access to the mailbox.","lessons":"Disable app-specific passwords for at-risk users, enrol them in Google's Advanced Protection Program, and treat any request to generate an account credential for a third party as a red flag regardless of who is asking.","confidence":"Confirmed","sources":[{"title":"Same Sea, New Phish: Russian Government-Linked Social Engineering Targets App-Specific Passwords","url":"https://citizenlab.ca/research/russian-government-linked-social-engineering-targets-app-specific-passwords/","publisher":"The Citizen Lab"},{"title":"Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign","url":"https://thehackernews.com/2025/06/russian-apt29-exploits-gmail-app.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-russian-state-linked-actors-phish-app-specific-passwords-from-academics"},{"title":"Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft","date":"2025-05-08","date_precision":"day","victim_org":"BitoPro","sector":"Cryptocurrency","country":"Taiwan","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":11500000,"loss_note":"About $11.5 million in suspicious withdrawals, disclosed publicly on June 3, 2025. BitoPro said reserves were sufficient and user functions were unaffected.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), attributed by BitoPro","summary":"Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.","how_it_worked":"BitoPro described the entry point only as social engineering against a cloud operations employee and did not disclose the specific channel or pretext used; the vector is recorded here as targeted phishing on that basis and the channel remains unconfirmed. Malware planted on the employee's device let the attackers hijack AWS session tokens, which sidestepped multi-factor authentication entirely because a live session had already satisfied it. Holding valid session tokens, they took control of BitoPro's cloud infrastructure and used their command server to inject scripts into the hot wallet system while a scheduled wallet upgrade and asset transfer was in progress. The malicious withdrawals were timed and shaped to mimic the legitimate migration traffic around them.","lessons":"Binding cloud session tokens to device posture and network origin, so a stolen token is unusable elsewhere, plus freezing automated wallet operations during manual migrations, would have denied both halves of this attack.","confidence":"Reported","sources":[{"title":"BitoPro exchange links Lazarus hackers to $11 million crypto heist","url":"https://www.bleepingcomputer.com/news/security/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/","publisher":"BleepingComputer"},{"title":"Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hack","url":"https://fortune.com/crypto/2025/06/03/taiwanese-crypto-exchange-bitopro-confirms-hack/","publisher":"Fortune"}],"entry_type":"incident","slug":"2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef"},{"slug":"2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509","title":"Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Arizona Arthritis and Rheumatology Associates","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5509,"threat_actor":null,"summary":"Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.","how_it_worked":"Staff received phishing email designed to look like routine Microsoft 365 account or document notifications and entered their work credentials on an attacker-controlled sign-in page. The trust signals abused were the familiar Microsoft branding and the ordinary rhythm of clinic email, where staff process insurance, referral and scheduling messages all day and open unfamiliar attachments as a matter of course. With valid credentials the attacker signed into the mailboxes and had immediate access to months of patient correspondence. Because the access used legitimate credentials from a normal cloud client, nothing looked malicious until sign-in anomalies were reviewed.","lessons":"Phishing-resistant MFA on clinical email accounts, plus conditional access blocking unfamiliar sign-in locations, would have made the harvested passwords useless.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509"},{"slug":"2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients","title":"Monongalia Health System email phishing breach affects 4,895 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Monongalia Health System (Mon Health)","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4895,"threat_actor":null,"summary":"West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.","how_it_worked":"Employees were sent phishing messages that imitated routine internal or Microsoft 365 notifications and were induced to enter their work credentials on a lookalike sign-in page. Hospital email is a high-yield target because clinical and billing staff exchange large volumes of patient-identifying correspondence with outside parties, so an unexpected message about a shared document or account issue does not stand out. With the harvested credentials the attacker signed in as the employee and had access to the full mailbox history. The activity resembled normal user logins, which is why detection depended on account anomaly review rather than malware alerts.","lessons":"Enforcing phishing-resistant MFA and automatically expiring or archiving mailbox contents containing PHI would have both blocked the login and limited what a single compromised account exposed.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients"},{"title":"Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI","date":"2025-02-21","date_precision":"day","victim_org":"Bybit","sector":"Cryptocurrency","country":"United Arab Emirates","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":1500000000,"loss_note":"Approximately 401,000 ETH and stETH, valued between roughly $1.4 billion and $1.5 billion at the time depending on the analysis. It is the largest cryptocurrency theft on record.","records_affected":null,"threat_actor":"Lazarus Group / TraderTraitor (DPRK)","summary":"On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.","how_it_worked":"The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.","lessons":"Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.","confidence":"Confirmed","sources":[{"title":"Lazarus hacked Bybit via breached Safe{Wallet} developer machine","url":"https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/","publisher":"BleepingComputer"},{"title":"In-Depth Technical Analysis of the Bybit Hack","url":"https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/","publisher":"NCC Group"},{"title":"Sygnia's Investigation into the Bybit Hack: What We Know So Far","url":"https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/","publisher":"Sygnia"},{"title":"Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B Hack","url":"https://www.coindesk.com/business/2025/02/26/bybit-and-safe-custody-blame-each-other-over-usd1-5b-hack","publisher":"CoinDesk"},{"title":"How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist","url":"https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa"},{"slug":"2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts","title":"Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts","date":"2025-02-13","date_precision":"day","year":2025,"victim_org":"Multiple government, NGO, defence and energy organisations","sector":"Government","country":"Multiple","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Storm-2372 (assessed Russian-aligned)","summary":"Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.","how_it_worked":"The actor built rapport first, messaging targets over WhatsApp, Signal or Teams while posing as a prominent person relevant to the victim's work. It then sent what looked like an invitation to a Teams meeting or a document, containing a genuine Microsoft device code page and a code to type in. Because the sign-in page was real Microsoft infrastructure and the victim entered the code themselves, the flow looked entirely legitimate and MFA prompts appeared expected. Completing it issued the attacker valid access and refresh tokens for the victim's account, giving persistent mailbox and file access without ever handling a password.","lessons":"Disable the device code authentication flow where it is not needed via Conditional Access, and train staff that a legitimate meeting invitation never requires typing a code into a separate sign-in page.","confidence":"Confirmed","sources":[{"title":"Storm-2372 conducts device code phishing campaign","url":"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/","publisher":"Microsoft Security"},{"title":"Phishing campaign targets Microsoft device-code authentication flows","url":"https://www.cybersecuritydive.com/news/phishing-campaign-targets-microsoft-device-code-authentication-flows/740201/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts"},{"slug":"2025-vc-firm-insight-partners-breached-through-social-engineering-attack","title":"VC firm Insight Partners breached through social engineering attack","date":"2025-01","date_precision":"month","year":2025,"victim_org":"Insight Partners","sector":"Financial Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.","how_it_worked":"Insight Partners stated publicly that the intrusion was the result of a social engineering attack rather than an exploited vulnerability. Investment firms are a high-value pretext environment: staff routinely exchange documents and wire instructions with founders, co-investors, lawyers and limited partners they have never met in person, so an approach from an unfamiliar sender referencing a live deal reads as normal. The attackers used that trust to obtain access to internal systems, then spent time collecting fund-level financial data, banking and tax details for individuals, and transaction records, before the activity was detected and remediated.","lessons":"For deal-driven firms, phishing-resistant MFA plus verified out-of-band confirmation for any document or credential request from outside the firm is the control that matters.","confidence":"Confirmed","sources":[{"title":"Statement from Insight Partners on Cyber Incident","url":"https://www.insightpartners.com/ideas/statement-from-insight-partners-on-cyber-incident/","publisher":"Insight Partners"},{"title":"VC giant Insight Partners notifies staff and limited partners after data breach","url":"https://techcrunch.com/2025/09/17/vc-giant-insight-partners-notifies-staff-and-limited-partners-after-data-breach/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-vc-firm-insight-partners-breached-through-social-engineering-attack"},{"title":"ClickFix fake-CAPTCHA social engineering floods the threat landscape","date":"2025","date_precision":"year","victim_org":"Multiple organisations and consumers (technique)","sector":"Other","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam","Spear Phishing (Email)"],"ai_involvement":"Unknown","ai_notes":"Some ClickFix lure pages and follow-on infrastructure have been reported as AI-assisted in their construction, but Proofpoint's reporting does not confirm AI involvement in the technique itself.","outcomes":["Credential Theft","Ransomware Deployment","Data Breach"],"loss_usd":null,"loss_note":"No aggregate loss figure; this entry documents a technique adopted across many criminal and state-linked actors rather than a single victim.","records_affected":null,"threat_actor":"Multiple, including cybercriminal and state-aligned groups tracked by Proofpoint","summary":"Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.","how_it_worked":"The victim reaches a page, often through malvertising, a compromised site, a search result or an emailed link, that presents a plausible obstacle: 'verify you are human', 'this document failed to load, run the fix', or a fake Chrome update error. Instructions walk the user through pressing Windows+R, pressing Ctrl+V and pressing Enter. The clipboard has already been populated by JavaScript with a PowerShell or mshta command, frequently padded with whitespace so the malicious portion is scrolled out of view in the Run box. Executing it downloads and runs the payload under the user's own privileges, sidestepping email attachment scanning, macro blocking and download reputation checks entirely because the user is the delivery mechanism.","lessons":"Disable or monitor the Run dialog through policy, alert on clipboard-sourced script execution, and train staff on the single unambiguous rule that no legitimate website ever asks you to paste a command into your operating system.","confidence":"Confirmed","sources":[{"title":"Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape","url":"https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape","publisher":"Proofpoint"},{"title":"Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware","url":"https://securityonline.info/deceptive-captcha-clickfix-campaign-uses-clipboard-injection-to-deliver-malware/","publisher":"SecurityOnline"},{"title":"Inside ClickFix: How Fake Prompts Took Over the Web","url":"https://netlas.io/blog/fake_prompts/","publisher":"Netlas"}],"entry_type":"campaign","slug":"2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape"},{"title":"FBI warns criminals are using generative AI to scale voice-clone and identity fraud","date":"2024-12-03","date_precision":"day","victim_org":"US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Deepfake Video Call","Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The entire advisory concerns criminal use of generative AI: AI text for phishing and fake profiles, AI images for fake IDs and personas, voice cloning to impersonate relatives and account holders, and real-time video synthesis to impersonate executives and authorities.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Extortion","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"The advisory does not publish an aggregate loss figure for AI-enabled fraud.","records_affected":null,"threat_actor":null,"summary":"On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.","how_it_worked":"Voice cloning is the pivotal technique for consumer harm. A short sample of a person's speech, readily available from social media video, is enough to synthesise a distressed relative calling to say they have been in an accident or arrested and need money immediately. The lever is the recognisable voice of a loved one under duress, which suppresses verification instincts far more effectively than any script. The same technology is used to satisfy bank voice authentication as an account holder, and real-time video synthesis extends it to live calls impersonating executives or providing proof of legitimacy to a romance or investment target. AI translation also strips the grammatical errors that once exposed foreign operators.","lessons":"The FBI's own recommendation is the practical control: agree a family or organisational verification code word in advance, and independently call back on a known number before acting on any urgent request.","confidence":"Confirmed","sources":[{"title":"Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud","url":"https://www.ic3.gov/PSA/2024/PSA241203","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide"},{"title":"US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM","date":"2024-09","date_precision":"month","victim_org":"Office of US Senator Ben Cardin, Senate Foreign Relations Committee","sector":"Government","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Senate security officials described the video call participant as an apparent deepfake of former Ukrainian foreign minister Dmytro Kuleba that matched his appearance and voice from prior encounters.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.","how_it_worked":"The pretext exploited a routine of the job: a foreign official Cardin had genuinely met requesting a follow-up video call on a live policy question. Because the identity was plausible and the scheduling followed normal staff channels, the meeting went ahead without independent verification through the State Department. On camera the deepfake supplied the visual and vocal confirmation staff expected. The impersonator then pushed for on-the-record statements that could be clipped and weaponised, applying pressure by demanding immediate answers. The tell was behavioural rather than technical: the real Kuleba would not badger a committee chair for soundbites, and the mismatch in conduct ended the call.","lessons":"Legislative offices should route requests for meetings with foreign officials through the State Department or the relevant embassy for confirmation before a call is scheduled.","confidence":"Reported","sources":[{"title":"Ben Cardin targeted in apparent deepfake call with someone posing as Dmytro Kuleba","url":"https://www.nbcnews.com/politics/congress/ben-cardin-targeted-apparent-deep-fake-call-dmytro-kuleba-rcna172776","publisher":"NBC News"},{"title":"Elaborate Deepfake Operation Takes a Meeting With US Senator","url":"https://www.darkreading.com/cyberattacks-data-breaches/elaborate-deepfake-operation-meeting-us-senator","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s"},{"title":"Iran's APT42 phishes Israeli and US officials with think-tank impersonation","date":"2024-08-14","date_precision":"day","victim_org":"Current and former Israeli and US government officials, diplomats and political campaign staff","sector":"Government","country":"Israel and United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No monetary loss; the objective was intelligence collection.","records_affected":null,"threat_actor":"APT42 / Charming Kitten (Iranian IRGC-linked)","summary":"On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.","how_it_worked":"APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.","lessons":"High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.","confidence":"Confirmed","sources":[{"title":"Iranian backed group steps up phishing campaigns against Israel, U.S.","url":"https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat"},{"slug":"2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou","title":"Ascension ransomware attack began when an employee downloaded a malicious file","date":"2024-05-08","date_precision":"day","year":2024,"victim_org":"Ascension","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5600000,"threat_actor":"Black Basta (reported)","summary":"Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.","how_it_worked":"A staff member downloaded a file to a work computer in the belief that it was legitimate, which is the form of compromise that has largely replaced the classic attachment: the user is looking for something, a document, an update, a utility, and takes delivery of malware from what appears to be an ordinary source. That single endpoint gave the operators their foothold in a health system spanning 140 hospitals, where the pressure to keep clinical systems continuously available works against aggressive segmentation. The attackers reached and exfiltrated data from seven servers before deploying encryption, forcing weeks of downtime procedures across the network.","lessons":"Application allowlisting and blocking user-initiated downloads of executables on clinical endpoints, combined with segmentation, are what keep one mistaken download from stopping 140 hospitals.","confidence":"Confirmed","sources":[{"title":"Ascension hacked after employee downloaded malicious file","url":"https://www.bleepingcomputer.com/news/security/ascension-hacked-after-employee-downloaded-malicious-file/","publisher":"BleepingComputer"},{"title":"Ascension cyberattack exposes data from 5.6 million people","url":"https://www.healthcaredive.com/news/ascension-cyberattack-data-breach-5-6-million/736167/","publisher":"Healthcare Dive"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou"},{"title":"WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read","date":"2024-05","date_precision":"month","victim_org":"WPP","sector":"Media & Entertainment","country":"United Kingdom","primary_vector":"Deepfake Video Call","secondary_vectors":["Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers set up a WhatsApp account using a publicly available image of chief executive Mark Read, then ran a Microsoft Teams meeting using YouTube footage of him alongside an AI voice clone.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.","how_it_worked":"The pretext was a new business opportunity that a chief executive might plausibly want to explore quietly with one trusted agency leader, which explained both the confidentiality and the unusual approach. The attackers assembled several weak trust signals into a convincing whole: a WhatsApp profile with Read's real photo, a Teams invite from an apparently senior source, video that showed his face and a synthetic voice on the line, and chat messages written in his persona. The technical staging papered over the gaps, with camera and audio problems used to explain why the video looked like recorded footage. The target was asked to move on money and personal information without touching normal corporate process.","lessons":"Verifying meeting invitations through the corporate directory rather than a messaging-app contact, and refusing to progress financial arrangements outside standard process, are what stopped this.","confidence":"Confirmed","sources":[{"title":"CEO of world's biggest ad firm targeted by deepfake scam","url":"https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam","publisher":"The Guardian"},{"title":"Scammers Reportedly Used AI Voice Clone and YouTube Footage to Impersonate WPP CEO","url":"https://incidentdatabase.ai/cite/983/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark"},{"slug":"2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200","title":"Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected","date":"2024-02-19","date_precision":"day","year":2024,"victim_org":"Los Angeles County Department of Public Health","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":200000,"threat_actor":null,"summary":"The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.","how_it_worked":"A phishing email circulated through the department and 53 separate employees entered their credentials on the attacker's page within roughly 24 hours, which shows the message was well matched to the environment rather than obviously fraudulent. With valid log-ins the attacker read the contents of those mailboxes, which in a county public health agency contain case correspondence carrying patient names, diagnoses, prescriptions and benefit identifiers. The department responded by disabling accounts, resetting devices, blocking the phishing sites and quarantining the messages, but by then two days of mailbox access across dozens of accounts had already occurred.","lessons":"Phishing-resistant MFA across county staff accounts would have made the harvested passwords useless, and rapid cross-department alerting would have cut the exposure window.","confidence":"Confirmed","sources":[{"title":"200,000 Impacted by Data Breach at Los Angeles County Public Health Agency","url":"https://www.securityweek.com/200000-impacted-by-data-breach-at-los-angeles-county-public-health-agency/","publisher":"SecurityWeek"},{"title":"Los Angeles Public Health Department Discloses Large Data Breach","url":"https://www.infosecurity-magazine.com/news/los-angeles-health-data-breach/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200"},{"title":"Arup Hong Kong office loses about $25 million in deepfake video call scam","date":"2024-02","date_precision":"month","victim_org":"Arup Group (Hong Kong office)","sector":"Professional Services","country":"Hong Kong","primary_vector":"Deepfake Video Call","secondary_vectors":["Business Email Compromise","Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":25000000,"loss_note":"HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.","records_affected":null,"threat_actor":null,"summary":"In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.","how_it_worked":"The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.","lessons":"High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.","confidence":"Confirmed","sources":[{"title":"Deepfaked video conference call makes employee send $25 million to scammers","url":"https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/","publisher":"Help Net Security"},{"title":"Arup Group (fraud incident section)","url":"https://en.wikipedia.org/wiki/Arup_Group","publisher":"Wikipedia"},{"title":"Business Email Compromise: Virtual Meeting Platforms","url":"https://www.ic3.gov/PSA/2022/PSA220216","publisher":"FBI IC3"},{"title":"Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee","url":"https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk","publisher":"CNN"},{"title":"'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage","publisher":"South China Morning Post"}],"entry_type":"incident","slug":"2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"},{"title":"Ledger Connect Kit poisoned after a former employee's npm account was phished","date":"2023-12-14","date_precision":"day","victim_org":"Ledger SAS","sector":"Cryptocurrency","country":"France","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Cryptocurrency Theft","Credential Theft"],"loss_usd":600000,"loss_note":"Commonly reported as roughly $600,000 drained; CoinDesk cited an on-chain figure of about $484,000 in the immediate aftermath. Ledger said proceeds were split 85/15 between the attacker and the Angel Drainer service.","records_affected":null,"threat_actor":"Operator using the Angel Drainer drainer-as-a-service","summary":"On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.","how_it_worked":"The former employee's access to Ledger's internal systems had been revoked at offboarding, but their npmjs publishing rights had not been manually removed. A phishing attack captured a valid session token rather than a password, which sidestepped the account's 2FA entirely and let the attacker publish new Connect Kit versions. Those versions injected the Angel Drainer script into any decentralised application that loaded the library, prompting users to sign transactions that transferred their assets to the attacker. Ledger shipped a clean version within about 40 minutes of learning of the compromise, but CDN caching kept the poisoned file reachable for roughly five hours in total.","lessons":"Offboarding must enumerate and revoke package-registry and other third-party publishing rights, and releases to public package registries should require hardware-key-backed signing plus a second approver rather than a single session.","confidence":"Confirmed","sources":[{"title":"Security Incident Report","url":"https://www.ledger.com/blog/security-incident-report","publisher":"Ledger"},{"title":"Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft","url":"https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html","publisher":"The Hacker News"},{"title":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph"},{"title":"QR code phishing campaign targets a major US energy company's Microsoft logins","date":"2023-08","date_precision":"month","victim_org":"Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets)","sector":"Energy & Utilities","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Credential Theft","Attempt Blocked"],"loss_usd":null,"loss_note":"No loss figure; Cofense reported the campaign volume rather than confirmed compromises.","records_affected":null,"threat_actor":null,"summary":"Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.","how_it_worked":"Emails spoofed Microsoft security notifications and told recipients they had to update account security relating to two-factor or multifactor authentication. Rather than a clickable link, the message carried a QR code inside an image or PDF attachment, which defeated URL scanning in email gateways because the destination was encoded in pixels. Scanning the code moved the victim onto a personal mobile phone, typically outside corporate device management and web filtering, where a credential harvesting page imitating Microsoft sign-in captured the username and password. Attackers also used redirects through legitimate services such as Bing to further obscure the final destination.","lessons":"Email security needs to decode QR images rather than only parse hyperlinks, and enrolling users in phishing-resistant authentication means a credential captured on an unmanaged phone is not enough to sign in.","confidence":"Confirmed","sources":[{"title":"Major Energy Company Targeted in Large QR Code Campaign","url":"https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign","publisher":"Cofense"},{"title":"QR Code Phishing Campaign Targets Top US Energy Company","url":"https://www.darkreading.com/cyberattacks-data-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company","publisher":"Dark Reading"},{"title":"Phishing campaign used QR codes to target large energy company","url":"https://therecord.media/phishing-campaign-used-qr-codes-to-target-energy-firm","publisher":"The Record"}],"entry_type":"campaign","slug":"2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft"},{"slug":"2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro","title":"EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts","date":"2023-08","date_precision":"month","year":2023,"victim_org":"More than 100 organisations worldwide (Proofpoint-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.","how_it_worked":"Emails impersonated widely trusted services such as Adobe, DocuSign and Concur, and pushed recipients through redirect chains to an EvilProxy page that relayed the real Microsoft 365 log-in. Victims entered their password and completed their genuine MFA challenge, and the proxy captured the resulting session cookie, so MFA provided no protection. The campaign filtered its own traffic, screening out non-target regions and security-research infrastructure, and deliberately concentrated on executives whose mailboxes carry payment authority and confidential deal information. Successful intrusions were consolidated by enrolling an attacker-controlled MFA method, converting a one-time theft into durable access.","lessons":"Phishing-resistant FIDO2 credentials for high-value roles, and alerting whenever a new MFA method is registered on an executive account, are the controls that matter here.","confidence":"Confirmed","sources":[{"title":"EvilProxy Phishing Used for Cloud Account Takeover Campaign","url":"https://www.proofpoint.com/us/blog/email-and-cloud-threats/cloud-account-takeover-campaign-leveraging-evilproxy-targets-top-level","publisher":"Proofpoint"},{"title":"EvilProxy phishing campaign targets 120,000 Microsoft 365 users","url":"https://www.bleepingcomputer.com/news/security/evilproxy-phishing-campaign-targets-120-000-microsoft-365-users/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro"},{"title":"Reddit source code stolen via a phishing site cloning its intranet gateway","date":"2023-02-05","date_precision":"day","victim_org":"Reddit","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.","how_it_worked":"The campaign sent plausible-sounding prompts to employees pointing at a cloned intranet gateway login page. One employee entered their credentials and their second-factor token into the clone; because the token was relayed immediately, the attacker completed a session on the real gateway. During a limited window the intruder accessed internal documents, limited source code, some internal dashboards and contact information for a few hundred current and former employees, plus information on advertisers. The employee self-reported quickly, which let Reddit revoke the session and lock the account, limiting dwell time to hours rather than weeks.","lessons":"Phishing-resistant MFA defeats token-relay pages outright, and a blame-free self-reporting culture is what turned this into hours of exposure rather than months.","confidence":"Confirmed","sources":[{"title":"Reddit says limited amount of source code, employee data accessed in phishing attack","url":"https://www.cybersecuritydive.com/news/reddit-source-code-employee-data-phishing/642510/","publisher":"Cybersecurity Dive"},{"title":"Reddit Suffers Security Breach Exposing Internal Documents and Source Code","url":"https://thehackernews.com/2023/02/reddit-suffers-security-breach-exposing.html","publisher":"The Hacker News"},{"title":"Reddit discloses security breach that exposed source code and internal docs","url":"https://securityaffairs.com/142071/data-breach/reddit-security-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-reddit-source-code-stolen-via-a-phishing-site-cloning-its-intranet-gatew","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-reddit-source-code-stolen-via-a-phishing-site-cloning-its-intranet-gatew"},{"title":"Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing","date":"2022-10-14","date_precision":"day","victim_org":"Dropbox","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.","how_it_worked":"The lure imitated CircleCI, a service Dropbox developers used and which legitimately prompts users to sign in with GitHub, so the request to authenticate looked routine. The phishing page collected the GitHub username, password and the time-based one-time passcode, which the attacker replayed immediately to establish a session. With developer access they cloned 130 private repositories containing modified third-party libraries, internal prototypes, and some security team tools and configuration files, along with a few thousand names and email addresses for employees, current and past customers, sales leads and vendors. Dropbox rotated credentials and moved to accelerate its rollout of hardware security keys.","lessons":"Time-based one-time passcodes are phishable in real time; WebAuthn keys on source-control accounts, and machine-to-machine tokens scoped per repository, remove both halves of this attack.","confidence":"Confirmed","sources":[{"title":"130 Dropbox code repos plundered after successful phishing attack","url":"https://www.helpnetsecurity.com/2022/11/02/dropbox-data-breach/","publisher":"Help Net Security"},{"title":"Dropbox Suffers Data Breach From Phishing Attack, Exposing Customer and Employee Emails","url":"https://blog.gitguardian.com/dropbox-breach-hack-github-circleci/","publisher":"GitGuardian"},{"title":"Dropbox confirms serious security breach in which hackers stole code from 130 GitHub repositories","url":"https://betanews.com/2022/11/02/dropbox-confirms-serious-security-breach-in-which-hackers-stole-code-from-130-github-repositories/","publisher":"BetaNews"}],"entry_type":"incident","slug":"2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing"},{"slug":"2022-bed-bath-beyond-discloses-data-breach-to-sec-after-an-employee-was-phish","title":"Bed Bath & Beyond discloses data breach to SEC after an employee was phished","date":"2022-10","date_precision":"month","year":2022,"victim_org":"Bed Bath & Beyond","sector":"Retail","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.","how_it_worked":"A single employee at the retailer was targeted with a phishing message and fell for it, handing the attacker access to that employee's account. What followed illustrates why one employee's compromise is rarely contained to one employee: the attacker reached not only files on the individual's own hard drive but also the shared network drives that the account had rights to open. Corporate shared drives accumulate years of departmental documents that no one has reviewed for sensitivity. The retailer disclosed the event as a material item to the SEC while investigation was still under way, and did not detail the phishing method used.","lessons":"Least-privilege access to shared drives and periodic review of what accumulates on them decide how much one phished account is actually worth.","confidence":"Confirmed","sources":[{"title":"Bed, Bath & Beyond confirms data breach following employee phishing attack","url":"https://techcrunch.com/2022/10/31/bed-bath-beyond-data-breach/","publisher":"TechCrunch"},{"title":"Bed Bath & Beyond Investigating Data Breach After Employee Falls for Phishing Attack","url":"https://www.securityweek.com/bed-bath-beyond-investigating-data-breach-after-employee-falls-phishing-attack/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-bed-bath-beyond-discloses-data-breach-to-sec-after-an-employee-was-phish"},{"slug":"2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or","title":"Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations","date":"2022-07-12","date_precision":"day","year":2022,"victim_org":"More than 10,000 organisations targeted (Microsoft-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Business Email Compromise","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.","how_it_worked":"Targets received phishing emails, often disguised as voice message notifications, linking to a proxy server that displayed the genuine Microsoft log-in page. The victim typed their real password and completed their real MFA challenge, both of which were passed straight through to Microsoft, so the experience was indistinguishable from a normal log-in. The proxy captured the resulting session cookie, which the attacker replayed to enter the mailbox without any further authentication. Microsoft observed operators moving to payment fraud within minutes, hunting invoice threads, adding hidden mailbox rules to suppress replies and emailing the victim's suppliers with altered bank details.","lessons":"Standard MFA is not proof against session-token theft; phishing-resistant credentials bound to the origin, plus conditional access on device compliance and token protection, are what break the proxy.","confidence":"Confirmed","sources":[{"title":"From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud","url":"https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/","publisher":"Microsoft Security Blog"},{"title":"Microsoft: 10,000 Organizations Targeted in Large-Scale Phishing Campaign","url":"https://www.securityweek.com/microsoft-10000-organizations-targeted-large-scale-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or"},{"slug":"2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m","title":"American Airlines discloses breach after phishing compromised employee mailboxes","date":"2022-07","date_precision":"month","year":2022,"victim_org":"American Airlines","sector":"Transportation & Logistics","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1708,"threat_actor":null,"summary":"American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.","how_it_worked":"Attackers phished American Airlines employees and captured their mailbox credentials. The consequences ran in two directions. Inbound, the mailboxes held correspondence containing customer and employee identity documents, passport and driver's licence numbers among them, which is what made a small number of accounts a reportable data breach. Outbound, the attackers used the genuine airline accounts to send more phishing, because a message that actually originates from an American Airlines address passes authentication checks and carries the brand's credibility with recipients. The airline said it had no evidence of misuse but notified affected individuals and offered identity protection.","lessons":"MFA on corporate mail plus data-loss controls that keep identity documents out of mailboxes limit both the exposure and the reuse of the account for onward phishing.","confidence":"Confirmed","sources":[{"title":"American Airlines discloses data breach after employee email compromise","url":"https://www.bleepingcomputer.com/news/security/american-airlines-discloses-data-breach-after-employee-email-compromise/","publisher":"BleepingComputer"},{"title":"American Airlines Says Personal Data Exposed After Email Phishing Attack","url":"https://www.securityweek.com/american-airlines-says-personal-data-exposed-after-email-phishing-attack/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m"},{"title":"Phishing of a Harmony developer preceded the $100M Horizon Bridge theft","date":"2022-06-23","date_precision":"day","victim_org":"Harmony (Horizon Bridge)","sector":"Cryptocurrency","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":100000000,"loss_note":"The FBI put the theft at $100 million in virtual currency, spanning 14 bridged assets including USDC, ETH, USDT and BNB.","records_affected":null,"threat_actor":"Lazarus Group and APT38 (DPRK), per FBI attribution","summary":"Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.","how_it_worked":"Harmony stated the attackers 'employed a phishing scheme to trick at least one software developer to install malicious software on their laptop.' That access let them read internal chat threads to learn how the bridge was operated and reach non-public bridge infrastructure code, then obtain backdoor access to one or more servers. Because the Horizon Bridge used a multisignature scheme requiring only two of five signatures, compromising the operational hosts holding those keys was enough to authorise transfers. On June 23 the attackers moved fourteen bridged asset types out in a series of transactions. Harmony emphasised the bridge contracts themselves were never exploited.","lessons":"Raising the signature threshold and isolating signing keys on dedicated hardware away from developer workstations would have meant that phishing one laptop could not produce a valid bridge withdrawal.","confidence":"Confirmed","sources":[{"title":"Summary of the Harmony Horizon Bridge Incident","url":"https://medium.com/harmony-one/summary-of-the-harmony-horizon-bridge-incident-f9bd87c0c68e","publisher":"Harmony"},{"title":"FBI: North Korean hackers stole $100 million in Harmony crypto hack","url":"https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft"},{"title":"FBI: business email compromise exposed $43 billion in losses across 177 countries","date":"2022-05-04","date_precision":"day","victim_org":"Businesses, government entities and individuals worldwide (multi-victim campaign)","sector":"Financial Services","country":"Global","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"The 2022 advisory does not describe AI-enabled BEC.","outcomes":["Wire Fraud / Financial Loss","Data Breach","Cryptocurrency Theft"],"loss_usd":43312749946,"loss_note":"$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.","records_affected":241206,"threat_actor":null,"summary":"On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.","how_it_worked":"BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.","lessons":"Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.","confidence":"Confirmed","sources":[{"title":"Business Email Compromise: The $43 Billion Scam","url":"https://www.ic3.gov/PSA/2022/PSA220504","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co","year":2022,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"},{"title":"Ghostwriter credential phishing against Ukrainian government and military accounts","date":"2022-05","date_precision":"month","victim_org":"Ukrainian government and military personnel","sector":"Government","country":"Ukraine","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Credential Theft","Espionage","Attempt Blocked"],"loss_usd":null,"loss_note":"No monetary loss; Google reported no accounts were compromised in the Ghostwriter campaign it described.","records_affected":null,"threat_actor":"Ghostwriter / UNC1151 (Belarus-attributed), alongside APT28 and Turla activity","summary":"Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.","how_it_worked":"Ghostwriter sent messages containing links to legitimate but compromised third-party websites that hosted the first-stage phishing page, which lends the URL an innocuous reputation and defeats simple domain blocklists. Users who clicked were redirected to attacker-controlled infrastructure presenting a replica webmail sign-in page, where entered credentials were captured. The campaign leaned on wartime urgency and the volume of official correspondence flowing to government and military staff, conditions in which recipients process messages quickly and are primed to expect unfamiliar senders and new systems.","lessons":"Enrolling government and military accounts in advanced protection with hardware security keys, and treating links to unfamiliar third-party sites as untrusted regardless of domain reputation, blocks this class of harvesting.","confidence":"Confirmed","sources":[{"title":"Update on cyber activity in Eastern Europe","url":"https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar"},{"title":"Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds","date":"2022-04-03","date_precision":"day","victim_org":"SatoshiLabs (Trezor), via email provider Mailchimp","sector":"Cryptocurrency","country":"Czech Republic","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Data Breach","Credential Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Neither Trezor nor Mailchimp published a loss figure, and Trezor said at the time it was unclear whether any funds were successfully stolen. The '106,856 customers' figure that circulated came from the phishing email itself and was attacker-authored text, not a confirmed breach count.","records_affected":null,"threat_actor":"Unattributed actor targeting cryptocurrency-sector Mailchimp tenants","summary":"Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.","how_it_worked":"The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.","lessons":"Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.","confidence":"Confirmed","sources":[{"title":"Ongoing phishing attacks on Trezor users","url":"https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304","publisher":"Trezor (SatoshiLabs)"},{"title":"Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam","url":"https://decrypt.co/96942/mailchimp-insider-targets-trezor-crypto-wallets-phishing-scam","publisher":"Decrypt"}],"entry_type":"incident","slug":"2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"},{"title":"Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF","date":"2022-03-23","date_precision":"day","victim_org":"Sky Mavis (Ronin Network / Axie Infinity)","sector":"Cryptocurrency","country":"Vietnam","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona and interview process were run by humans.","outcomes":["Cryptocurrency Theft"],"loss_usd":620000000,"loss_note":"173,600 ETH and 25.5 million USDC were drained; the value is commonly reported as roughly $540 million at the time of the hack and about $620-625 million at the time of disclosure, depending on the valuation date.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); sanctioned by the US Treasury in April 2022","summary":"On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.","how_it_worked":"Attackers posing as a non-existent company recruited a senior engineer over LinkedIn with an unusually generous compensation package, running a plausible multi-round interview process to build credibility. The final offer arrived as a PDF; downloading and opening it on a company machine executed spyware that gave the attackers a foothold in Sky Mavis systems. From there they obtained the private keys for four of the nine Ronin validator nodes, and used a still-active allowlist permission previously granted by Sky Mavis to the Axie DAO to obtain a fifth signature, reaching the five-of-nine threshold needed to authorise withdrawals from the bridge.","lessons":"Validator key material should live in hardware security modules on isolated machines that never render untrusted documents, and delegated signing permissions must expire automatically rather than persist after a temporary need ends.","confidence":"Confirmed","sources":[{"title":"How a fake job offer took down the world's most popular crypto game","url":"https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","publisher":"The Block"},{"title":"Hackers Used Fake Job Offer to Hack and Steal $540 Million from Axie Infinity","url":"https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","publisher":"The Hacker News"},{"title":"Spear Phishing Fake Job Offer Likely Behind Axie Infinity's Lazarus $600m Hack","url":"https://www.infosecurity-magazine.com/news/fake-job-offer-behind-axie/","publisher":"Infosecurity Magazine"},{"title":"Hackers stole $620 million from Axie Infinity via fake job interviews","url":"https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake-job-interviews/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf"},{"title":"Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge","date":"2022","date_precision":"year","victim_org":"Unnamed aerospace company in Spain","sector":"Defense","country":"Spain","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona was operated manually over LinkedIn Messaging.","outcomes":["Espionage","Data Breach"],"loss_usd":null,"loss_note":"No financial loss reported; the objective was espionage.","records_affected":null,"threat_actor":"Lazarus Group (North Korea), Operation Dream Job","summary":"ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.","how_it_worked":"A fake recruiter contacted employees through LinkedIn Messaging claiming to be running a Meta hiring process. The candidate was sent two supposed C++ programming tests, Quiz1.exe and Quiz2.exe, packaged inside ISO images hosted on cloud storage; one printed 'Hello, World!' and the other computed Fibonacci numbers, so the tasks appeared genuine. Running them side-loaded a malicious DLL that installed the NickelLoader downloader, which fetched miniBlindingCan and LightlessCan. LightlessCan supports up to 68 commands and reimplements many Windows utilities internally rather than spawning visible processes, reducing the telemetry available to endpoint monitoring during the espionage phase.","lessons":"Recruitment materials should never be executed on corporate endpoints; disposable virtual machines for candidate exercises plus application allow-listing eliminate this entire vector.","confidence":"Confirmed","sources":[{"title":"Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company","url":"https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/","publisher":"ESET WeLiveSecurity"},{"title":"North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain","url":"https://www.eset.com/us/about/newsroom/press-releases/north-korea-linked-lazarus-impersonates-meta-on-linkedin-to-attack-an-aerospace-company-in-spain/","publisher":"ESET"},{"title":"Lazarus hackers breach aerospace firm with new LightlessCan malware","url":"https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding"},{"title":"Sequoia Capital investor data exposed after employee falls for phishing email","date":"2021-02","date_precision":"month","victim_org":"Sequoia Capital","sector":"Financial Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed; the associated fraudulent transfer attempt was reported as unsuccessful.","records_affected":null,"threat_actor":null,"summary":"Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.","how_it_worked":"An employee at the firm received and acted on a phishing email, handing over credentials that gave the attacker access to their corporate mailbox. The intruder used that mailbox to read stored correspondence containing investor personal and financial details, and attempted to leverage the account for fraudulent payment instructions in the style of a business email compromise, which was not successful. Sequoia notified affected limited partners, engaged outside investigators and law enforcement, and offered credit monitoring. No malware deployment or wider network intrusion was reported.","lessons":"Phishing-resistant MFA on cloud mailboxes plus alerting on anomalous mailbox rules and sign-in locations catches this pattern in hours rather than weeks.","confidence":"Reported","sources":[{"title":"Scoop: Sequoia Capital says it was hacked","url":"https://www.axios.com/2021/02/20/sequoia-capital-says-it-was-hacked","publisher":"Axios"},{"title":"VC Giant Sequoia Capital Informs Investors of Data Breach","url":"https://www.securityweek.com/vc-giant-sequoia-capital-informs-investors-data-breach/","publisher":"SecurityWeek"},{"title":"VC giant Sequoia Capital discloses data breach after failed BEC attack","url":"https://www.bleepingcomputer.com/news/security/vc-giant-sequoia-capital-discloses-data-breach-after-failed-bec-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing"},{"slug":"2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a","title":"Baltimore County schools ransomware started with a contractor opening a phishing email","date":"2020-11-24","date_precision":"day","year":2020,"victim_org":"Baltimore County Public Schools","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Service Disruption","Data Breach"],"loss_usd":9700000,"loss_kind":"business_impact","loss_note":"About US$9.7 million in recovery and remediation costs according to the Maryland Office of the Inspector General for Education; no ransom was paid.","records_affected":null,"threat_actor":"Ryuk (reported)","summary":"Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.","how_it_worked":"A contractor working with the district opened a malicious email attachment, which established the foothold that led to district-wide encryption on the eve of the Thanksgiving holiday, a timing choice that maximised the gap before anyone noticed. The Inspector General's report placed the weight of the finding not on the click but on what surrounded it: the district had received specific security recommendations from a prior state audit and had not implemented them, and had extended network access to a contractor without correspondingly hardened controls. Remote learning for 115,000 students halted, and rebuilding cost nearly ten million dollars.","lessons":"Contractor accounts need the same email defences, MFA and least privilege as employees, and audit findings left unimplemented become the incident's root cause.","confidence":"Confirmed","sources":[{"title":"Baltimore County schools ignored warnings before 2020 cyberattack, audit finds","url":"https://statescoop.com/baltimore-county-schools-ransomware-attack-2020-inspector-general/","publisher":"StateScoop"},{"title":"Report: Contractor 'mistakenly' opened email starting Baltimore County school cyberattack","url":"https://foxbaltimore.com/news/local/investigative-report-released-2-years-after-baltimore-county-schools-cyberattack","publisher":"Fox Baltimore (WBFF)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a"},{"title":"WHO impersonation surge during COVID-19 targets donors and staff","date":"2020-04-23","date_precision":"day","victim_org":"World Health Organization and the general public (multi-victim campaign)","sector":"Healthcare","country":"Global","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in 2020.","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_note":"WHO did not publish a total for donations diverted by impersonators.","records_affected":450,"threat_actor":null,"summary":"On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.","how_it_worked":"Attackers exploited the single most trusted authority of the moment. Emails carrying WHO branding promised guidance on the outbreak and asked recipients to click through to a credential capture page or open an attachment, and separate campaigns solicited donations to a fake version of the COVID-19 Solidarity Response Fund or issued invoices purporting to come from it. The lever was fear plus civic goodwill under acute uncertainty, when recipients were actively seeking official pandemic information and wanted to help. The leaked credentials came from an older extranet system used by current staff, retired employees and partners.","lessons":"Legacy extranets holding partner credentials must be retired or moved behind modern multi-factor authentication, and public-facing agencies should publish a single authoritative donation channel to make impersonation obvious.","confidence":"Confirmed","sources":[{"title":"WHO reports fivefold increase in cyber attacks, urges vigilance","url":"https://www.who.int/news/item/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance","publisher":"World Health Organization"},{"title":"Cyber security: beware of criminals pretending to be WHO","url":"https://www.who.int/about/cyber-security","publisher":"World Health Organization"}],"entry_type":"campaign","slug":"2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff"},{"slug":"2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c","title":"Magellan Health ransomware began with a phishing email impersonating a client","date":"2020-04-06","date_precision":"day","year":2020,"victim_org":"Magellan Health","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Credential Theft","Extortion"],"loss_usd":1430000,"loss_kind":"business_impact","loss_note":"US$1.43 million class-action settlement resolving claims over the breach and the delay in notification.","records_affected":364892,"threat_actor":null,"summary":"Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.","how_it_worked":"The attacker impersonated one of Magellan's own clients, which is a stronger pretext than a generic executive spoof because a managed care company's staff correspond with client organisations constantly and are expected to be responsive to them. The employee provided access credentials in response to that message. Over the following five days the attackers moved through the network, reached a corporate server holding employee records including tax documentation with Social Security numbers, exfiltrated a subset of it, and installed software to harvest further log-ins before triggering encryption. The five-day dwell time is where the data theft happened.","lessons":"Client-impersonation phishing defeats seniority-based suspicion, so the control is MFA plus detection of internal reconnaissance in the days between the click and the encryption.","confidence":"Confirmed","sources":[{"title":"Data Stolen in Magellan Health Ransomware Attack","url":"https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/","publisher":"HIPAA Journal"},{"title":"Healthcare giant Magellan Health hit by ransomware attack","url":"https://www.bleepingcomputer.com/news/security/healthcare-giant-magellan-health-hit-by-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c"},{"slug":"2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake","title":"Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow","date":"2019-07","date_precision":"month","year":2019,"victim_org":"Lancaster University","sector":"Education","country":"United Kingdom","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":12500,"threat_actor":null,"summary":"Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.","how_it_worked":"Phishing against university staff yielded access to the applicant records system. What made this breach unusual is the immediate monetisation: rather than selling the data, the attacker used it to send fraudulent invoices directly to undergraduate applicants. Those recipients were the ideal targets, because a prospective student who has just applied is expecting communication from the university about fees and accommodation, and has no baseline for what a genuine invoice looks like. The stolen contact details supplied exactly the personalisation, real name, real address, real course application, that makes a fake bill credible. The university reported to the ICO and warned applicants directly.","lessons":"Multi-factor authentication on staff accounts, plus a published policy that the university never invoices applicants by email, closes both the intrusion and the downstream fraud.","confidence":"Confirmed","sources":[{"title":"Lancaster University Confirms Data Breach, Applicants Targeted","url":"https://www.infosecurity-magazine.com/news/lancaster-university-breach/","publisher":"Infosecurity Magazine"},{"title":"Lancaster University data breach","url":"https://www.theregister.com/2019/07/23/lancaster_university_data_breach/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake"}]}