{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:13:59.099Z","total":18,"returned":18,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman","title":"700+ education and tech sites hijacked to serve ClickFix paste-the-command lures","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Visitors to 700+ compromised university and technology company websites","sector":"Education","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.","how_it_worked":"The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.","lessons":"Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.","confidence":"Confirmed","sources":[{"title":"700+ education and tech websites hijacked in huge ClickFix malware campaign","url":"https://www.malwarebytes.com/blog/bugs/2026/05/700-education-and-tech-websites-hijacked-in-huge-clickfix-malware-campaign","publisher":"Malwarebytes"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"},{"title":"Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware","date":"2026-02","date_precision":"month","victim_org":"An unnamed cryptocurrency company executive","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Deepfake Video Call","secondary_vectors":["Tech Support Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.","records_affected":null,"threat_actor":"UNC1069 (DPRK), tracked by Mandiant since 2018","summary":"Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.","how_it_worked":"Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.","lessons":"No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.","confidence":"Confirmed","sources":[{"title":"North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam","url":"https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix","publisher":"The Record (Recorded Future News)"},{"title":"North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms","url":"https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"},{"title":"STAC4749 Teams vishing campaign led to Chaos ransomware in North America","date":"2026-02","date_precision":"month","victim_org":"Dozens of North American organisations (unnamed)","sector":"Manufacturing","country":"Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No ransom or loss totals were disclosed.","records_affected":null,"threat_actor":"STAC4749, deploying Chaos ransomware","summary":"Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.","how_it_worked":"The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.","lessons":"Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.","confidence":"Confirmed","sources":[{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","url":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america"},{"slug":"2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering","title":"$282M in Bitcoin and Litecoin stolen from a holder via social engineering","date":"2026-01-10","date_precision":"day","year":2026,"victim_org":"Unnamed cryptocurrency holder","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Cryptocurrency Theft"],"loss_usd":282000000,"loss_kind":"direct_loss","loss_note":"USD value at time of theft of 1,459 BTC and 2.05 million LTC; no recovery reported.","records_affected":null,"threat_actor":null,"summary":"On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.","how_it_worked":"Reporting characterised the theft as a support-impersonation social engineering attack of the kind that has become the dominant loss driver in crypto: the attacker poses as an employee of a wallet or exchange provider, builds trust with the holder, and persuades them to hand over a seed phrase, sign a malicious transaction or surrender login details. The theft came days after hardware-wallet maker Ledger disclosed a breach exposing customer names and contact details, the kind of list that makes such calls credible. The victim has not been identified and the exact pretext was not published.","lessons":"No legitimate wallet or exchange support agent ever needs a seed phrase or a remote-access session; large holdings belong behind multi-signature approval with an out-of-band co-signer.","confidence":"Reported","sources":[{"title":"Hacker steals $282 million crypto from a victim in social-engineering attack","url":"https://www.coindesk.com/business/2026/01/16/hacker-steals-usd282-milion-in-hardware-wallet-social-engineering-attack","publisher":"CoinDesk"},{"title":"Crypto User Loses $282 Million in Bitcoin and Litecoin to Social Engineering Scam","url":"https://bravenewcoin.com/insights/crypto-user-loses-282-million-in-bitcoin-and-litecoin-to-social-engineering-scam","publisher":"Brave New Coin"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"},{"slug":"2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands","title":"CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Users of malicious Chrome extension impersonating uBlock Origin Lite","sector":"Technology","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.","how_it_worked":"The lure inverted the usual ClickFix pattern. Rather than a fake CAPTCHA, the attackers manufactured a real, visible fault: the installed extension broke the victim's browser, then presented a repair prompt that looked like a security notice. Because the user had genuinely just experienced a crash, the instruction to paste a command into a terminal read as a fix rather than an attack. Operators showed selectivity, deploying extra backdoors only where the compromised host was domain-joined, indicating they were filtering for enterprise environments worth returning to.","lessons":"Blocking clipboard-to-shell execution patterns and restricting extension installation to an allowlist stops the paste step, which is the only point where the user's action is required.","confidence":"Confirmed","sources":[{"title":"New ClickFix variant 'CrashFix' deploying Python Remote Access Trojan","url":"https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands"},{"title":"Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access","date":"2025-07-22","date_precision":"day","victim_org":"Multiple businesses and critical infrastructure organisations (campaign)","sector":"Healthcare","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the advisory.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the advisory notes Interlock does not state an initial ransom amount in its notes.","records_affected":null,"threat_actor":"Interlock ransomware group","summary":"A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.","how_it_worked":"Visitors to compromised but otherwise legitimate websites were served a page claiming they needed to prove they were human or fix a display problem. The page silently copied a command to the clipboard and instructed the user to open the Windows Run dialog, paste and press Enter, which executed PowerShell that fetched a remote access trojan. Because the victim types the command themselves, no download prompt or macro warning appears and email gateways are entirely bypassed. Interlock operators then used the foothold for credential theft with infostealers and keyloggers, lateral movement over RDP, data exfiltration to cloud storage, and double-extortion encryption of Windows and Linux systems.","lessons":"Instrument and alert on PowerShell or mshta launched from explorer.exe via the Run dialog, and block clipboard-to-shell execution paths through application control; no legitimate CAPTCHA ever asks a user to run a command.","confidence":"Confirmed","sources":[{"title":"#StopRansomware: Interlock (AA25-203A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a","publisher":"CISA / FBI / HHS / MS-ISAC"},{"title":"#StopRansomware: Interlock (PDF)","url":"https://www.ic3.gov/CSA/2025/250722.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Feds Issue Interlock Ransomware Warning as Healthcare Attacks Spike","url":"https://www.hipaajournal.com/interlock-ransomware-alert-2025/","publisher":"HIPAA Journal"}],"entry_type":"campaign","slug":"2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce"},{"title":"DOJ moves to forfeit $225M in crypto traced to pig butchering victims","date":"2025-06-18","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Romance / Investment Scam","secondary_vectors":["Smishing (SMS)","Spear Phishing (Email)","Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The forfeiture complaint focuses on the money laundering trail rather than the tooling used to create the scam personas.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss","Identity Theft","Data Breach"],"loss_usd":19400000,"loss_note":"Over $225 million in USDT was targeted for forfeiture. DOJ identified 434 victims, of whom 60 named victims lost a combined $19.4 million; the $19.4M figure is used here as the confirmed victim loss.","records_affected":434,"threat_actor":null,"summary":"On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.","how_it_worked":"Victims were groomed online and induced to send tether to any of 93 deposit addresses controlled by the network. The proceeds were then split across up to 100 intermediary wallets to break the trail and to blend deposits from many victims, before consolidation into 22 primary exchange accounts and 122 further accounts linked by shared IP addresses and reused know-your-customer documents. The Heartland Tri-State case shows the depth of the psychological hold: a serving bank chief executive stole from his own bank, his church, an investment club and his daughter's college fund to keep feeding the scam, and received a 24-year sentence in August 2024.","lessons":"The rule that a legitimate employer never requires an employee to deposit money to be paid is the whole control; payment providers should also flag consumer crypto purchases immediately preceding transfers to newly seen platforms.","confidence":"Confirmed","sources":[{"title":"DOJ Ties Kansas Bank Collapse to $225 Million 'Pig Butchering' Seizure","url":"https://www.coindesk.com/policy/2025/06/18/doj-ties-kansas-bank-collapse-to-225-million-pig-butchering-seizure","publisher":"CoinDesk"},{"title":"New FTC Data Show Skyrocketing Consumer Reports About Game-Like Online Job Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2024/12/new-ftc-data-show-skyrocketing-consumer-reports-about-game-online-job-scams","publisher":"Federal Trade Commission"},{"title":"FBI Releases Annual Internet Crime Report","url":"https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims"},{"title":"Bribed overseas support agents leaked Coinbase data; $20M extortion refused","date":"2025-05-15","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in Coinbase's disclosure.","outcomes":["Data Breach","Extortion","Insider Access","Cryptocurrency Theft","Identity Theft"],"loss_usd":null,"loss_note":"Coinbase refused the $20 million demand and instead established a $20 million reward fund for information leading to arrests. Aggregate customer losses from the resulting social engineering were not quantified in the disclosure.","records_affected":69461,"threat_actor":"Unattributed extortion group","summary":"Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.","how_it_worked":"The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.","lessons":"Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.","confidence":"Confirmed","sources":[{"title":"Protecting Our Customers - Standing Up to Extortionists","url":"https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists","publisher":"Coinbase"},{"title":"Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails","url":"https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html","publisher":"The Hacker News"},{"title":"Coinbase confirms insiders handed over data of 70K users","url":"https://www.theregister.com/2025/05/21/coinbase_confirms_insider_breach_affects/","publisher":"The Register"}],"entry_type":"incident","slug":"2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse"},{"title":"FBI warns Silent Ransom Group is callback-phishing US law firms","date":"2025-05","date_precision":"month","victim_org":"US law firms and legal services organisations (campaign)","sector":"Legal","country":"United States","primary_vector":"Callback Phishing (TOAD)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the FBI advisory.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the group extorts victims after data theft without deploying encryption.","records_affected":null,"threat_actor":"Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, UNC3753)","summary":"The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.","how_it_worked":"The primary lure is a telephone-oriented attack delivery email: a message claims a small subscription has been renewed and will be charged unless the recipient calls a number to cancel. There is no link or attachment, so the mail passes gateway filtering. When the victim calls, the operator, posing as support, directs them to a website and has them install a legitimate remote access utility such as Zoho Assist, Syncro, AnyDesk, SuperOps or Atera. The group has also skipped the email entirely and simply telephoned employees claiming to be the firm's own IT department with an after-hours maintenance request. Once connected, the operators escalate where possible, use tools such as WinSCP or Rclone to exfiltrate documents, then extort the firm by threatening publication on a leak site.","lessons":"Application control that blocks unapproved remote access tools is the decisive check here, since the email carries no malicious payload for a gateway to catch; staff also need a verified internal number for IT so an unexpected support call can be refused.","confidence":"Confirmed","sources":[{"title":"FBI warns of Luna Moth extortion attacks targeting law firms","url":"https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/","publisher":"BleepingComputer"},{"title":"Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign","url":"https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html","publisher":"The Hacker News"},{"title":"FBI warns of cybercriminals impersonating IT staff to breach law firms","url":"https://www.floridabar.org/the-florida-bar-news/fbi-warns-of-cybercriminals-impersonating-it-staff-to-breach-law-firms/","publisher":"The Florida Bar"}],"entry_type":"campaign","slug":"2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms"},{"title":"'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders","date":"2025-03","date_precision":"month","victim_org":"Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully","sector":"Cryptocurrency","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The campaign used roughly 30 sock-puppet social media accounts and fabricated company websites; no confirmed use of AI-generated media was reported in the analyses reviewed.","outcomes":["Cryptocurrency Theft","Credential Theft"],"loss_usd":null,"loss_note":"Security Alliance's incident log attributes millions of dollars of stolen funds to the group. No single confirmed per-victim figure was published in the reporting reviewed.","records_affected":null,"threat_actor":"Elusive Comet, tracked by the Security Alliance and assessed as North Korea-linked","summary":"From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.","how_it_worked":"The lure was flattery with a business rationale: an investment conversation or an invitation onto a podcast, backed by around thirty sock-puppet accounts and fabricated corporate websites so that a quick check appeared to confirm the entity. On the call the attacker asked to screen share, then requested remote control. The critical trick was renaming their Zoom display name to 'Zoom' so that the permission prompt read as though it came from the application itself rather than from another participant. A victim clicking approve on what looked like a system dialog handed over interactive control of their machine, at which point infostealers or remote access trojans were installed and wallet material harvested. Tell-tale signs included consumer Zoom accounts used by supposed Bloomberg staff.","lessons":"Disabling Zoom remote control at the account level, and treating any unsolicited investor or media approach that moves to screen control as hostile, removes the single click this campaign depends on.","confidence":"Reported","sources":[{"title":"'Elusive Comet' Attackers Use Zoom to Swindle Victims","url":"https://www.darkreading.com/remote-workforce/elusive-comet-zoom-victims","publisher":"Dark Reading"},{"title":"North Korean Cryptocurrency Thieves Caught Hijacking Zoom 'Remote Control' Feature","url":"https://www.securityweek.com/north-korean-cryptocurrency-thieves-caught-hijacking-zoom-remote-control-feature/","publisher":"SecurityWeek"}],"entry_type":"campaign","slug":"2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders"},{"title":"ClickFix fake-CAPTCHA social engineering floods the threat landscape","date":"2025","date_precision":"year","victim_org":"Multiple organisations and consumers (technique)","sector":"Other","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam","Spear Phishing (Email)"],"ai_involvement":"Unknown","ai_notes":"Some ClickFix lure pages and follow-on infrastructure have been reported as AI-assisted in their construction, but Proofpoint's reporting does not confirm AI involvement in the technique itself.","outcomes":["Credential Theft","Ransomware Deployment","Data Breach"],"loss_usd":null,"loss_note":"No aggregate loss figure; this entry documents a technique adopted across many criminal and state-linked actors rather than a single victim.","records_affected":null,"threat_actor":"Multiple, including cybercriminal and state-aligned groups tracked by Proofpoint","summary":"Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.","how_it_worked":"The victim reaches a page, often through malvertising, a compromised site, a search result or an emailed link, that presents a plausible obstacle: 'verify you are human', 'this document failed to load, run the fix', or a fake Chrome update error. Instructions walk the user through pressing Windows+R, pressing Ctrl+V and pressing Enter. The clipboard has already been populated by JavaScript with a PowerShell or mshta command, frequently padded with whitespace so the malicious portion is scrolled out of view in the Run box. Executing it downloads and runs the payload under the user's own privileges, sidestepping email attachment scanning, macro blocking and download reputation checks entirely because the user is the delivery mechanism.","lessons":"Disable or monitor the Run dialog through policy, alert on clipboard-sourced script execution, and train staff on the single unambiguous rule that no legitimate website ever asks you to paste a command into your operating system.","confidence":"Confirmed","sources":[{"title":"Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape","url":"https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape","publisher":"Proofpoint"},{"title":"Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware","url":"https://securityonline.info/deceptive-captcha-clickfix-campaign-uses-clipboard-injection-to-deliver-malware/","publisher":"SecurityOnline"},{"title":"Inside ClickFix: How Fake Prompts Took Over the Web","url":"https://netlas.io/blog/fake_prompts/","publisher":"Netlas"}],"entry_type":"campaign","slug":"2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape"},{"title":"Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin","date":"2024-08-19","date_precision":"day","victim_org":"An individual Genesis creditor in Washington, D.C.","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning or synthetic media was reported; the callers used spoofed caller ID and live pretexting.","outcomes":["Cryptocurrency Theft","Wire Fraud / Financial Loss"],"loss_usd":243000000,"loss_note":"4,064 BTC, worth approximately $243 million at the time. More than $9 million was subsequently frozen and about $500,000 returned to the victim.","records_affected":null,"threat_actor":"Malone Lam ('Greavys'), Jeandiel Serrano ('VersaceGod') and co-conspirators","summary":"On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.","how_it_worked":"The crew opened with a spoofed call presenting as Google support warning of unauthorised account access, which established urgency and a reason for the victim to accept further contact. A second set of callers then posed as Gemini support and walked the victim through resetting the two-factor authentication on the exchange account. Under the guise of remediation, they had the victim install AnyDesk and share their screen, at which point the attackers were able to see private keys held in the victim's Bitcoin Core wallet and to direct transfers to a wallet they controlled. Funds were then split across many wallets and pushed through more than fifteen exchanges. The crew's spending on cars, watches and designer goods exposed an address that let investigators freeze over $9 million.","lessons":"No legitimate provider initiates a call asking you to reset MFA or install remote-desktop software; hanging up and calling back on a number obtained independently is the single control that defeats this entire sequence.","confidence":"Reported","sources":[{"title":"Police Arrest Two People Related to $243M Crypto Heist Targeting Genesis Creditor","url":"https://www.coindesk.com/business/2024/09/19/police-arrests-two-people-related-to-243m-crypto-heist-targeting-genesis-creditor","publisher":"CoinDesk"},{"title":"Hackers Posed as Google Support to Steal $243 Million in Crypto","url":"https://hackread.com/hackers-posed-google-support-steal-243m-crypto/","publisher":"Hackread"}],"entry_type":"incident","slug":"2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit"},{"title":"Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta","date":"2024-05-15","date_precision":"day","victim_org":"Multiple organisations (campaign)","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Tech Support Scam","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"Microsoft reported live human callers, not synthetic voice.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published for the campaign.","records_affected":null,"threat_actor":"Storm-1811, deploying Black Basta ransomware","summary":"Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.","how_it_worked":"The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.","lessons":"Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.","confidence":"Confirmed","sources":[{"title":"Threat actors misusing Quick Assist in social engineering attacks leading to ransomware","url":"https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/","publisher":"Microsoft Security Blog"},{"title":"Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing","url":"https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing","publisher":"Sophos"},{"title":"Windows Quick Assist Anchors Black Basta Ransomware Gambit","url":"https://www.darkreading.com/threat-intelligence/windows-quick-assist-anchors-black-basta-ransomware","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"},{"title":"FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings","date":"2023-09-29","date_precision":"day","victim_org":"US senior citizens (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"The advisory does not describe AI-generated voice or content in this campaign.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":542000000,"loss_note":"IC3 received 19,000 tech support scam complaints between January and June 2023 with estimated victim losses over $542 million; nearly half of victims were over 60 and accounted for 66 percent of losses.","records_affected":19000,"threat_actor":null,"summary":"On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.","how_it_worked":"Phase one is a supposed technology company representative reaching the victim by call, text, email or pop-up, who obtains remote access, shows fabricated virus scan results and reviews the victim's financial accounts to find the largest balance, then warns that the institution's fraud department will be in touch. Phase two is a caller posing as that bank or brokerage saying a foreign hacker has accessed the accounts and the money must be moved to a safe government account by wire, cash or cryptocurrency, with instructions to keep it confidential. Phase three is a purported Federal Reserve or government employee, sometimes sending official-looking letterhead, who confirms the story and presses the victim to complete the transfer.","lessons":"The confidentiality instruction is the diagnostic tell; bank staff trained to treat customer secrecy plus urgent large outbound transfers as a scam indicator, and mandatory cooling-off holds, break the chain.","confidence":"Confirmed","sources":[{"title":"'Phantom Hacker' Scams Target Senior Citizens and Result in Victims Losing their Life Savings","url":"https://www.ic3.gov/PSA/2023/PSA230929","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"campaign","slug":"2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings"},{"title":"Coinbase employee phished by SMS then talked through by a fake IT caller","date":"2023-02-05","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.","outcomes":["Data Breach","Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No customer funds or customer data were lost; exposure was limited to some employee contact details.","records_affected":null,"threat_actor":"Reported as the 0ktapus / Scattered Spider cluster","summary":"In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.","how_it_worked":"The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.","lessons":"Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.","confidence":"Confirmed","sources":[{"title":"Social Engineering - A Coinbase Case Study","url":"https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study","publisher":"Coinbase"},{"title":"Coinbase cyberattack targeted employees with fake SMS alert","url":"https://www.bleepingcomputer.com/news/security/coinbase-cyberattack-targeted-employees-with-fake-sms-alert/","publisher":"BleepingComputer"},{"title":"Coinbase breached by social engineers, employee data stolen","url":"https://news.sophos.com/en-us/2023/02/21/coinbase-breached-by-social-engineers-employee-data-stolen","publisher":"Sophos News"}],"entry_type":"incident","slug":"2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller"},{"title":"FTC: business and government impersonation scams hit $1.1 billion in 2023","date":"2023","date_precision":"year","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Callback Phishing (TOAD)"],"ai_involvement":"Unknown","ai_notes":"The 2024 data spotlight does not break out AI-enabled impersonation.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft","Identity Theft"],"loss_usd":1100000000,"loss_note":"$1.1 billion in combined reported losses to business and government impersonation scams in 2023, more than triple the $310 million reported in 2020. Over 330,000 business impersonation reports and nearly 160,000 government impersonation reports, together about 48 percent of fraud reports made directly to the FTC.","records_affected":490000,"threat_actor":null,"summary":"An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.","how_it_worked":"The dominant openers are bogus account security alerts purporting to come from a company such as Amazon or from a bank, claiming unauthorised activity and steering the victim toward transferring funds or feeding cash into a Bitcoin ATM to protect their money. A second pattern is the fake subscription renewal notice, often impersonating Geek Squad, which offers a refund and then coerces the victim into buying gift cards and reading out the numbers. The most damaging innovation is the multi-agency handoff: scammers who begin as a business then transfer the victim to a fake bank representative, FBI agent or even a purported FTC employee, so that each successive persona corroborates the last.","lessons":"No government agency or legitimate business asks anyone to move money to protect it or to pay in gift cards or Bitcoin ATM deposits; retailer and ATM operator interdiction prompts at the point of payment are the strongest late-stage control.","confidence":"Confirmed","sources":[{"title":"Impersonation scams: not what they used to be","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2024/04/impersonation-scams-not-what-they-used-be","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023","year":2023,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023"},{"title":"FTC data: $147.8M in gift card fraud driven by government and business impersonators","date":"2021-12-08","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam","Romance / Investment Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement described.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":147800000,"loss_note":"$147.8 million reported lost across 39,263 gift card fraud reports in the first nine months of 2021. Government impersonation accounted for 7,844 reports and $39.6 million; business impersonation for 12,239 reports and $35.5 million.","records_affected":39263,"threat_actor":null,"summary":"An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.","how_it_worked":"A caller impersonating the Social Security Administration, another government agency, or a business such as Amazon or Apple tells the victim that money is owed or that an account has been compromised, and instructs them to resolve it immediately by buying gift cards at a nearby retailer. The victim is kept on the phone throughout the drive and the purchase, which prevents consultation with anyone and lets the scammer coach them past cashier questions with a cover story about buying gifts. At the register the victim reads the card numbers and PINs aloud over the phone, and the value is drained within minutes. Gift cards are attractive because they are irreversible and untraceable.","lessons":"Retail checkout interdiction, where staff are trained and empowered to stop high-value gift card purchases by customers on the phone, is the single highest-yield control at the point of loss.","confidence":"Confirmed","sources":[{"title":"Scammers prefer gift cards, but not just any card will do","url":"https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2021/12/scammers-prefer-gift-cards-not-just-any-card-will-do","publisher":"Federal Trade Commission"}],"entry_type":"benchmark","slug":"2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp","year":2021,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp"},{"title":"Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups","date":"2017-05-12","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Callback Phishing (TOAD)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the era predates generative tooling in this scam type.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The FTC stated consumers paid millions of dollars but published no single campaign total. Individual matters included a $27 million default judgment and $1.3 million in forfeited assets.","records_affected":null,"threat_actor":"Repair All PC LLC, Troth Solutions, Vylah Tec, Universal Network Solutions, Click4Support, BigDog Solutions, First Choice Tech Support and others","summary":"On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.","how_it_worked":"Consumers browsing the web were served pop-up advertisements built to mimic genuine security alerts from Microsoft, Apple and other technology companies, warning that the machine was infected or being hacked and instructing the user to call a toll-free number. Telemarketers answering those calls claimed to represent the impersonated vendor, talked the victim into installing remote access software, and ran theatrical fake diagnostic tests that displayed ordinary system logs as evidence of infection. Having manufactured alarm and demonstrated apparent expertise, they sold hundreds of dollars of unnecessary repairs, software and multi-year service plans.","lessons":"Browser and OS vendors blocking full-screen dialog abuse, plus the simple consumer rule that no legitimate vendor puts a support phone number in a security warning, removes the entry point.","confidence":"Confirmed","sources":[{"title":"FTC and Federal, State and International Partners Announce Major Crackdown on Tech Support Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2017/05/ftc-federal-state-international-partners-announce-major-crackdown-tech-support-scams","publisher":"Federal Trade Commission"}],"entry_type":"campaign","slug":"2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support"}]}