{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:16:01.230Z","total":55,"returned":50,"limit":50,"offset":0,"next":"https://global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vendor+%2F+Supply+Chain+Impersonation&offset=50&limit=50","note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Six-month DPRK social engineering operation preceded $285M Drift Protocol theft","date":"2026-04-01","date_precision":"day","victim_org":"Drift Protocol","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Physical Pretexting","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.","outcomes":["Cryptocurrency Theft"],"loss_usd":285000000,"loss_note":"USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.","records_affected":null,"threat_actor":"UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence","summary":"Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.","how_it_worked":"This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.","lessons":"Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.","confidence":"Reported","sources":[{"title":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","publisher":"The Hacker News"},{"title":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks","publisher":"TRM Labs"}],"entry_type":"incident","slug":"2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol","year":2026,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"},{"slug":"2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account","title":"Crunchyroll support tickets stolen via compromised BPO agent SSO account","date":"2026-03-12","date_precision":"day","year":2026,"victim_org":"Crunchyroll","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.","how_it_worked":"The weak point was not Crunchyroll's own workforce but a third-party contact centre agent with standing access to the streaming service's ticketing system. The attacker said malware on the agent's machine captured their credentials, then used the resulting Okta session to authenticate into Zendesk as a legitimate support operator. Because helpdesk agents routinely open and read large numbers of tickets, bulk retrieval did not stand out immediately, and roughly 24 hours passed before access was cut. Some payment card details were exposed only where customers had typed them into tickets.","lessons":"Outsourced agent identities need the same phishing-resistant MFA and device-health enforcement as employees, plus per-agent ticket access rate limits so no single account can enumerate the whole queue.","confidence":"Reported","sources":[{"title":"Crunchyroll probes breach after hacker claims to steal 6.8M users' data","url":"https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/amp/","publisher":"BleepingComputer"},{"title":"1.2 million Crunchyroll users confirmed impacted by data breach","url":"https://cyberinsider.com/1-2-million-crunchyroll-users-confirmed-impacted-by-data-breach/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"},{"slug":"2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors","title":"Contagious Interview: fake developer job interviews deliver backdoors","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Software developers at enterprise solution, media and communications firms","sector":"Technology","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Cryptocurrency Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.","how_it_worked":"The pretext is a career opportunity, and the trust signal is the ordinary shape of a developer hiring process: a recruiter approach, a screening call, then a take-home coding exercise. The malicious step is disguised as the exercise itself, because cloning a repository and running it locally is exactly what a candidate is expected to do. Payloads fire automatically from task configuration files when the repository is opened in Visual Studio Code, so no obviously suspicious action is needed. The malware then harvests API tokens, cloud credentials, cryptocurrency wallets, password manager databases, private keys, source code and clipboard contents.","lessons":"Candidate exercises and any unvetted repository should be run only in a disposable sandbox with no access to corporate credentials, wallets or password vaults.","confidence":"Confirmed","sources":[{"title":"Contagious Interview: Malware delivered through fake developer job interviews","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"},{"slug":"2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec","title":"Dickinson Public Schools loses $4.92M to vendor-impersonation BEC","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Dickinson Public Schools","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4920000,"loss_kind":"direct_loss","loss_note":"USD; two payments diverted from the district's restricted building fund. No recovery reported at time of disclosure.","records_affected":null,"threat_actor":null,"summary":"Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.","how_it_worked":"The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.","lessons":"Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.","confidence":"Confirmed","sources":[{"title":"North Dakota School District Loses $4.9M to Email Scam","url":"https://www.govtech.com/education/k-12/north-dakota-school-district-loses-4-9m-to-email-scam","publisher":"Government Technology"},{"title":"North Dakota school district loses nearly $5 million in sophisticated email scam","url":"https://www.valleynewslive.com/2026/02/11/north-dakota-school-district-loses-nearly-5-million-sophisticated-email-scam/","publisher":"Valley News Live"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"},{"slug":"2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform","title":"Stellantis confirms customer data stolen from Salesforce platform","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Stellantis","sector":"Manufacturing","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered Lapsus$ Hunters (claimed)","summary":"Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.","how_it_worked":"The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.","lessons":"Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.","confidence":"Reported","sources":[{"title":"Automaker giant Stellantis confirms data breach after Salesforce hack","url":"https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/","publisher":"BleepingComputer"},{"title":"Stellantis confirms data breach involving customers' contact information","url":"https://www.engadget.com/big-tech/stellantis-confirms-data-breach-involving-customers-contact-information-194136744.html","publisher":"Engadget"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform"},{"slug":"2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf","title":"Air France and KLM disclose breach of third-party customer service platform","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Air France-KLM","sector":"Transportation & Logistics","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.","how_it_worked":"Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.","lessons":"Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.","confidence":"Reported","sources":[{"title":"Air France and KLM disclose data breaches impacting customers","url":"https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/","publisher":"BleepingComputer"},{"title":"Air France, KLM Say Hackers Accessed Customer Data","url":"https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"},{"slug":"2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach","title":"Chanel notifies US clients after third-party client-care database breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Chanel","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.","how_it_worked":"Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.","lessons":"Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.","confidence":"Reported","sources":[{"title":"Chanel Alerts Client of Third-Party Breach","url":"https://www.darkreading.com/cyberattacks-data-breaches/chanel-alerts-third-party-breach","publisher":"Dark Reading"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach"},{"slug":"2025-pandora-warns-customers-after-third-party-platform-breach","title":"Pandora warns customers after third-party platform breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Pandora A/S","sector":"Retail","country":"Denmark","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.","how_it_worked":"Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.","lessons":"Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.","confidence":"Reported","sources":[{"title":"Pandora and Chanel Customer Data Leaked in Third-Party Breaches","url":"https://www.pymnts.com/cybersecurity/2025/pandora-and-chanel-customer-data-leaked-in-breach/","publisher":"PYMNTS"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-pandora-warns-customers-after-third-party-platform-breach"},{"slug":"2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ","title":"TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs","date":"2025-07-28","date_precision":"day","year":2025,"victim_org":"TransUnion","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4400000,"threat_actor":"ShinyHunters","summary":"Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.","how_it_worked":"TransUnion has described the entry point only as a third-party application serving its consumer support operations and has not publicly confirmed a social engineering pretext. Reporting places the theft in the Salesforce campaign attributed to UNC6040 and ShinyHunters, in which callers impersonating internal IT support telephone employees, cite a routine integration or troubleshooting need, and talk the target through authorising an attacker-controlled connected application inside the genuine Salesforce authorisation screen. The abused trust signal is Salesforce's own real interface combined with a plausible internal support identity; the extraction that follows is automated and needs no further human involvement.","lessons":"Restricting connected-app authorisation to a small set of administrators and alerting on any newly bound application or unusual bulk export from the CRM would have contained this class of intrusion at the moment of consent.","confidence":"Reported","sources":[{"title":"TransUnion suffers data breach impacting over 4.4 million people","url":"https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/","publisher":"BleepingComputer"},{"title":"TransUnion becomes latest victim in major wave of Salesforce-linked cyberattacks, 4.4M Americans affected","url":"https://www.foxnews.com/tech/transunion-becomes-latest-victim-major-wave-salesforce-linked-cyberattacks-4-4m-americans-affected","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"title":"Qantas contact centre platform breached after help desk tricked into adding MFA","date":"2025-07-01","date_precision":"day","victim_org":"Qantas Airways","sector":"Transportation & Logistics","country":"Australia","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.","records_affected":5700000,"threat_actor":"Scattered Spider / Muddled Libra (reported)","summary":"Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.","how_it_worked":"The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.","lessons":"Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.","confidence":"Confirmed","sources":[{"title":"Qantas data breach impacted 5.7 million individuals","url":"https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html","publisher":"Security Affairs"},{"title":"Qantas confirms customer data breach amid Scattered Spider attacks","url":"https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html","publisher":"Security Affairs"},{"title":"Update on Qantas cyber incident: Wednesday 9 July 2025","url":"https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025","publisher":"Qantas Newsroom"},{"title":"Tech support scam caused massive data breach at Australian airline Qantas","url":"https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267","publisher":"The Register"}],"entry_type":"incident","slug":"2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"},{"slug":"2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre","title":"Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility","date":"2025-07","date_precision":"month","year":2025,"victim_org":"HPS Investment Partners (BlackRock)","sector":"Financial Services","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":400000000,"loss_kind":"direct_loss","loss_note":"USD. HPS extended more than $400 million against the disputed receivables, part of roughly $430 million of loans, with BNP Paribas providing leverage on about half. HPS is pursuing recovery through Delaware court action and related bankruptcy proceedings, so the final unrecovered amount has not been published.","records_affected":null,"threat_actor":"Bankim Brahmbhatt and affiliated telecom entities (alleged)","summary":"HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.","how_it_worked":"The borrower supplied invoices purporting to come from large international telecom carriers as collateral for a revolving credit facility, backed by supporting correspondence from email domains crafted to look like those carriers. Credit analysts and underwriters accepted the documents as third-party confirmation of real receivables, and the pattern held for roughly five years because each new drawdown was validated against the same fabricated paper trail. The deception unravelled only when an HPS analyst compared the email domains on the invoices against the real carriers' domains and found mismatches, then found the same discrepancy repeatedly across the portfolio.","lessons":"Out-of-band verification of receivables directly with the named obligor, using contact details sourced independently rather than from the borrower's own documents, would have exposed the fabricated counterparties years earlier.","confidence":"Reported","sources":[{"title":"US Probes Telecom Firms After BlackRock's HPS Uncovers Alleged $400M Fraud","url":"https://www.usnews.com/news/top-news/articles/2025-11-17/us-probes-telecom-firms-after-blackrocks-hps-uncovers-alleged-400m-fraud-financial-times-reports","publisher":"U.S. News / Reuters"},{"title":"How Fake Invoices Duped BlackRock Unit Into a $400 Million Loan (WSJ)","url":"https://www.securitiesdocket.com/2026/02/11/how-fake-invoices-duped-blackrock-unit-into-a-400-million-loan-wsj/","publisher":"Securities Docket / The Wall Street Journal"},{"title":"BlackRock Unit Flags Suspected $400 Million Fraud, Triggering U.S. Probe of Telecom Firms","url":"https://finance.yahoo.com/news/blackrock-unit-flags-suspected-400-150656293.html","publisher":"Yahoo Finance / Bloomberg"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre"},{"title":"BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware","date":"2025-06","date_precision":"month","victim_org":"Employee of a cryptocurrency foundation (Web3 sector)","sector":"Cryptocurrency","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.","outcomes":["Cryptocurrency Theft","Credential Theft","Espionage"],"loss_usd":null,"loss_note":"Amount stolen not disclosed","records_affected":null,"threat_actor":"BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)","summary":"In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.","how_it_worked":"The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.","lessons":"Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.","confidence":"Confirmed","sources":[{"title":"North Korean hackers deepfake execs in Zoom call to spread Mac malware","url":"https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/","publisher":"BleepingComputer"},{"title":"BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware","url":"https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"},{"slug":"2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million","title":"Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers","date":"2025-05-29","date_precision":"day","year":2025,"victim_org":"Farmers Insurance","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1100000,"threat_actor":"ShinyHunters, working with UNC6040 / UNC6240","summary":"Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.","how_it_worked":"In this campaign the caller poses as internal IT or a support desk and tells the employee that a routine tool needs to be connected to the company's Salesforce tenant. The employee is walked to Salesforce's legitimate connected-app authorisation page and given an eight-digit connection code supplied by the attacker, which they enter and approve. Because every screen the employee sees is a real Salesforce page, the trust signal is Salesforce's own interface, not a spoofed one. Approval binds an attacker-controlled data-extraction application to the tenant with the employee's permissions, after which records can be pulled in bulk without any further interaction.","lessons":"Limiting the connected-app authorisation permission to a small admin group and blocking uninstalled or unapproved apps by default removes the single click that this pretext is engineered to obtain.","confidence":"Reported","sources":[{"title":"Farmers Insurance data breach impacts 1.1M people after Salesforce attack","url":"https://www.bleepingcomputer.com/news/security/farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack/","publisher":"BleepingComputer"},{"title":"Farmers Insurance Data Breach Affects 1.1 Million Customers","url":"https://www.secureworld.io/industry-news/farmers-insurance-data-breach","publisher":"SecureWorld"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million"},{"slug":"2025-adidas-customer-data-stolen-through-third-party-customer-service-provide","title":"Adidas customer data stolen through third-party customer service provider","date":"2025-05","date_precision":"month","year":2025,"victim_org":"Adidas","sector":"Retail","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.","how_it_worked":"Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.","lessons":"Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.","confidence":"Reported","sources":[{"title":"April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider","url":"https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider","publisher":"Rescana"},{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"},{"title":"Marks & Spencer attack tied to social engineering of outsourced service desk","date":"2025-04-22","date_precision":"day","victim_org":"Marks & Spencer Group plc","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vendor / Supply Chain Impersonation","Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":null,"loss_note":"M&S publicly guided to a hit of around £300 million to operating profit before mitigation; no USD figure is asserted here.","records_affected":null,"threat_actor":"Scattered Spider, deploying DragonForce ransomware","summary":"Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.","how_it_worked":"Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.","lessons":"Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.","confidence":"Confirmed","sources":[{"title":"M&S hackers gained access through third-party Tata Consulting Services, sources say","url":"https://cybernews.com/news/marks-spencer-hackers-used-employee-login-tsc-tata-consulting-scattered-spider/","publisher":"Cybernews"},{"title":"M&S confirms month-long breach result of third-party vendor phishing attack","url":"https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/","publisher":"Cybernews"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Marks and Spencer confirms data breach after April cyber attack","url":"https://securityaffairs.com/177784/data-breach/marks-and-spencer-confirms-data-breach-after-april-cyber-attack.html","publisher":"Security Affairs"},{"title":"Marks & Spencer breach linked to Scattered Spider ransomware attack","url":"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de"},{"title":"Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI","date":"2025-02-21","date_precision":"day","victim_org":"Bybit","sector":"Cryptocurrency","country":"United Arab Emirates","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":1500000000,"loss_note":"Approximately 401,000 ETH and stETH, valued between roughly $1.4 billion and $1.5 billion at the time depending on the analysis. It is the largest cryptocurrency theft on record.","records_affected":null,"threat_actor":"Lazarus Group / TraderTraitor (DPRK)","summary":"On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.","how_it_worked":"The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.","lessons":"Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.","confidence":"Confirmed","sources":[{"title":"Lazarus hacked Bybit via breached Safe{Wallet} developer machine","url":"https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/","publisher":"BleepingComputer"},{"title":"In-Depth Technical Analysis of the Bybit Hack","url":"https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/","publisher":"NCC Group"},{"title":"Sygnia's Investigation into the Bybit Hack: What We Know So Far","url":"https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/","publisher":"Sygnia"},{"title":"Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B Hack","url":"https://www.coindesk.com/business/2025/02/26/bybit-and-safe-custody-blame-each-other-over-usd1-5b-hack","publisher":"CoinDesk"},{"title":"How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist","url":"https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa"},{"title":"DPRK actor posing as a former contractor took $50M from Radiant Capital","date":"2024-10","date_precision":"month","victim_org":"Radiant Capital","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported; the impersonation relied on a spoofed contractor domain and an existing working relationship.","outcomes":["Cryptocurrency Theft"],"loss_usd":50000000,"loss_note":"Approximately $50 million, with stolen funds moved on October 24, 2024. Radiant Capital later wound down operations.","records_affected":null,"threat_actor":"UNC4736 / Citrine Sleet (DPRK-nexus), assessed with high confidence by Mandiant","summary":"Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.","how_it_worked":"The pretext worked because the sender was someone the team already knew and the ask, review this document, was ordinary. The ZIP contained a decoy PDF that opened normally while a macOS backdoor installed behind it, and because the developer forwarded the file to colleagues for their input, the compromise multiplied across the signer group. With malware on multiple developer machines, the attackers manipulated what those machines displayed: front-end interfaces and simulation tools such as Tenderly showed benign transaction data while malicious transactions were being signed underneath. Radiant noted that traditional checks and simulations showed no obvious discrepancies, so the review process that should have caught the theft confirmed it instead.","lessons":"Signing must happen on dedicated, hardened devices that do nothing else, with the transaction independently verified on separate hardware, because once the reviewer's endpoint is compromised, on-screen verification is worthless.","confidence":"Reported","sources":[{"title":"Radiant Capital says North Korea posed as ex-contractor to carry out $50M hack","url":"https://cointelegraph.com/news/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack","publisher":"Cointelegraph"},{"title":"Radiant Capital Says DPRK Actor Posed as Ex-Contractor to Pull Off $50 Million Hack","url":"https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack","publisher":"Decrypt"}],"entry_type":"incident","slug":"2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital"},{"title":"Iran's APT42 phishes Israeli and US officials with think-tank impersonation","date":"2024-08-14","date_precision":"day","victim_org":"Current and former Israeli and US government officials, diplomats and political campaign staff","sector":"Government","country":"Israel and United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No monetary loss; the objective was intelligence collection.","records_affected":null,"threat_actor":"APT42 / Charming Kitten (Iranian IRGC-linked)","summary":"On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.","how_it_worked":"APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.","lessons":"High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.","confidence":"Confirmed","sources":[{"title":"Iranian backed group steps up phishing campaigns against Israel, U.S.","url":"https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat"},{"title":"WazirX signers approved a spoofed transaction and lost $235M","date":"2024-07-18","date_precision":"day","victim_org":"WazirX","sector":"Cryptocurrency","country":"India","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":234900000,"loss_note":"Approximately $234.9 million in ETH and ERC-20 tokens at the value on July 18, 2024. WazirX and custody provider Liminal publicly disagreed over which side's systems were compromised.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), per multiple third-party analyses","summary":"Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.","how_it_worked":"The signers were the target, and the deception was in what their screens showed them. Analyses of the incident found a discrepancy between how the transaction was rendered in the Liminal custody interface and the actual payload being signed: signers reviewed what appeared to be a routine, whitelisted transfer while the underlying data authorised a malicious contract upgrade. Three WazirX signers and the Liminal signer approved it, satisfying the four-of-six threshold. Because the approval was cryptographically valid, address whitelisting, hardware wallet storage and the multisig scheme itself all passed cleanly, and the attacker gained control to drain the remaining balance without needing any further key.","lessons":"Signers need to verify transaction payloads on an independent, out-of-band device that renders the raw calldata, since any control that trusts the same interface the attacker can influence provides no assurance at all.","confidence":"Reported","sources":[{"title":"2024 WazirX hack","url":"https://en.wikipedia.org/wiki/2024_WazirX_hack","publisher":"Wikipedia"},{"title":"Explained: The WazirX Hack (July 2024)","url":"https://www.halborn.com/blog/post/explained-the-wazirx-hack-july-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m"},{"title":"LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft","date":"2024-05","date_precision":"month","victim_org":"DMM Bitcoin, via wallet software vendor Ginco","sector":"Cryptocurrency","country":"Japan","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in the joint FBI, DC3 and NPA advisory.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":308000000,"loss_note":"4,502.9 BTC, valued at approximately $308 million in the joint FBI/DC3/NPA advisory; Japanese reporting at the time cited roughly $305 million. DMM Bitcoin subsequently wound down, transferring assets to SBI VC Trade.","records_affected":null,"threat_actor":"TraderTraitor (DPRK), per FBI, DC3 and Japan's National Police Agency","summary":"Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.","how_it_worked":"The recruiter pretext delivered a malicious Python script hosted on GitHub, framed as a pre-employment coding assessment. The Ginco employee copied the script into their own GitHub account to work on it, which handed the attacker access to session cookie data. Using those session cookies the attacker impersonated the employee and compromised Ginco's unencrypted internal communications system. From there they waited: in late May a DMM Bitcoin employee submitted a legitimate transaction request through Ginco's system, and the attacker altered it in flight so that the withdrawal, which carried valid authorisation from DMM's side, sent 4,502.9 BTC to attacker-controlled addresses.","lessons":"Take-home coding tasks must be isolated from corporate identity and never touched by an account with production session access, and transaction requests should be verified against an independent channel between exchange and custody vendor before signing.","confidence":"Confirmed","sources":[{"title":"FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com","url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom","publisher":"Federal Bureau of Investigation"},{"title":"FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin","url":"https://cryptoslate.com/fbi-reveals-north-korea-used-linkedin-to-steal-305-million-from-japans-dmm-bitcoin/","publisher":"CryptoSlate"}],"entry_type":"incident","slug":"2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t"},{"title":"Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs","date":"2024-04-01","date_precision":"day","victim_org":"Cisco Duo (via an unnamed telephony supplier)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.","how_it_worked":"The attack did not target Duo at all; it targeted the intermediary that physically delivers Duo's SMS one-time codes, an organisation most Duo customers had never heard of. A single employee's credentials were enough to reach the message log store. The stolen data is second-order ammunition rather than direct access: knowing which phone number belongs to which enterprise user, on which carrier, and when they authenticate, is precisely what a SIM-swap or help-desk-impersonation crew needs to build a convincing call and to time it against a real login.","lessons":"Move off SMS as an MFA channel where possible, and require phishing-resistant authentication and log-access controls from downstream communications suppliers.","confidence":"Confirmed","sources":[{"title":"Cisco Duo warns telephony supplier data breach exposed MFA SMS logs","url":"https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs"},{"title":"FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)","date":"2024","date_precision":"year","victim_org":"Aggregate: U.S. and international BEC victims reporting to FBI IC3","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"The IC3 annual report does not break out AI-enabled BEC as a separate category; separate FBI PSAs have documented deepfake audio and virtual-meeting impersonation used in BEC.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2770151146,"loss_note":"2024 IC3 Annual Report: 21,442 BEC complaints and $2,770,151,146 in adjusted losses. Cumulatively, IC3 recorded 277,918 BEC incidents and roughly $50.9 billion in exposed losses globally from October 2013 through December 2022.","records_affected":null,"threat_actor":null,"summary":"The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.","how_it_worked":"IC3 describes a consistent mechanism across reported cases: criminals compromise or spoof an email account belonging to an executive, employee, vendor or transaction professional, monitor correspondence to identify a pending payment, and then send instructions substituting attacker-controlled bank details. Real estate closings are heavily targeted because buyers, sellers, attorneys, title companies and agents all exchange payment instructions under time pressure. Funds increasingly route to cryptocurrency exchanges and third-party payment processors, with Hong Kong, China, the United Kingdom, Mexico and Singapore among leading destinations. IC3's Recovery Asset Team initiates the Financial Fraud Kill Chain, and most kill-chain requests involve BEC.","lessons":"Reporting a diverted wire to IC3 and the originating bank within 24 to 72 hours is the highest-value response control, and pre-transaction verification of wire instructions is the highest-value prevention control.","confidence":"Confirmed","sources":[{"title":"2024 Internet Crime Report","url":"https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Business Email Compromise: The $50 Billion Scam","url":"https://www.ic3.gov/PSA/2023/PSA230609","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline","year":2024,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline"},{"title":"Ledger Connect Kit poisoned after a former employee's npm account was phished","date":"2023-12-14","date_precision":"day","victim_org":"Ledger SAS","sector":"Cryptocurrency","country":"France","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Cryptocurrency Theft","Credential Theft"],"loss_usd":600000,"loss_note":"Commonly reported as roughly $600,000 drained; CoinDesk cited an on-chain figure of about $484,000 in the immediate aftermath. Ledger said proceeds were split 85/15 between the attacker and the Angel Drainer service.","records_affected":null,"threat_actor":"Operator using the Angel Drainer drainer-as-a-service","summary":"On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.","how_it_worked":"The former employee's access to Ledger's internal systems had been revoked at offboarding, but their npmjs publishing rights had not been manually removed. A phishing attack captured a valid session token rather than a password, which sidestepped the account's 2FA entirely and let the attacker publish new Connect Kit versions. Those versions injected the Angel Drainer script into any decentralised application that loaded the library, prompting users to sign transactions that transferred their assets to the attacker. Ledger shipped a clean version within about 40 minutes of learning of the compromise, but CDN caching kept the poisoned file reachable for roughly five hours in total.","lessons":"Offboarding must enumerate and revoke package-registry and other third-party publishing rights, and releases to public package registries should require hardware-key-backed signing plus a second approver rather than a single session.","confidence":"Confirmed","sources":[{"title":"Security Incident Report","url":"https://www.ledger.com/blog/security-incident-report","publisher":"Ledger"},{"title":"Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft","url":"https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html","publisher":"The Hacker News"},{"title":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph"},{"title":"Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered","date":"2023-08-18","date_precision":"day","victim_org":"Caesars Entertainment","sector":"Gaming & Casino","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Help Desk Impersonation","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Wire Fraud / Financial Loss"],"loss_usd":15000000,"loss_note":"Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.","records_affected":null,"threat_actor":"Scattered Spider, reportedly working with ALPHV/BlackCat","summary":"Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.","how_it_worked":"Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.","lessons":"Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.","confidence":"Confirmed","sources":[{"title":"Caesars Entertainment says social-engineering attack behind August breach","url":"https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/","publisher":"Cybersecurity Dive"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"incident","slug":"2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially","year":2023,"loss_kind":"ransom_paid","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"},{"title":"Clorox attack traced to help desk agents resetting passwords without verification","date":"2023-08-11","date_precision":"day","victim_org":"The Clorox Company","sector":"Manufacturing","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the complaint describes live phone calls.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":380000000,"loss_note":"$380 million is the total damages Clorox sought in its 2025 lawsuit against Cognizant, including about $49 million in direct remediation costs; it is a litigation claim, not an adjudicated loss.","records_affected":null,"threat_actor":"Scattered Spider","summary":"Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.","how_it_worked":"According to the complaint, the attacker called the Cognizant-run service desk multiple times claiming to be a Clorox employee and asked for a password reset. The agent reset the credential and the multifactor enrolment without confirming the caller's identity, and transcripts quoted in the filing show no verification step took place. The attacker used the same technique against a Clorox IT security employee, which yielded privileged network access. From there the intrusion progressed to network-wide disruption; Clorox took systems offline, reverted to manual order processing, and saw sales and shipments fall for months afterwards.","lessons":"Outsourced service desks need contractually mandated, auditable identity proofing before any credential or MFA reset, with higher-assurance checks for accounts holding privileged access.","confidence":"Confirmed","sources":[{"title":"Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit","url":"https://www.bleepingcomputer.com/news/security/hackers-fooled-cognizant-help-desk-says-clorox-in-380m-cyberattack-lawsuit/","publisher":"BleepingComputer"},{"title":"Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack","url":"https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor","publisher":"The Record"},{"title":"Clorox files $380 million suit blaming Cognizant for 2023 cyberattack","url":"https://www.cybersecuritydive.com/news/clorox-380-million-suit-cognizant-cyberattack/753837/","publisher":"Cybersecurity Dive"},{"title":"$380M lawsuit: intruder got Clorox's passwords from Cognizant simply by asking","url":"https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/","publisher":"The Register"},{"title":"Clorox estimates the costs of the August cyberattack will exceed $49 Million","url":"https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver"},{"title":"3CX supply chain attack began with a trojanised X_TRADER installer on staff PC","date":"2023-03-29","date_precision":"day","victim_org":"3CX Ltd.","sector":"Technology","country":"Cyprus","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure published; 3CX said it had over 600,000 customer companies, though only a subset installed the trojanised builds.","records_affected":null,"threat_actor":"UNC4736 / Lazarus-linked North Korean cluster (Mandiant attribution)","summary":"In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.","how_it_worked":"The employee retrieved what appeared to be a legitimate, digitally signed X_TRADER installer from the vendor's website in 2022. The package carried the VEILEDSIGNAL backdoor, giving the attackers a foothold and the employee's 3CX corporate credentials. Using those credentials the intruders moved into 3CX's network, reached the Windows and macOS build systems, and inserted malicious code into the desktop app build pipeline so that shipped, code-signed updates carried a downloader. Affected customer installations fetched encrypted payloads hidden in icon files on GitHub and, for a small number of selected targets, received a second-stage infostealer. Some reporting has also referred to fake-recruiter lures against 3CX staff, but the confirmed initial vector is the trojanised installer.","lessons":"Build systems should be reachable only from hardened, managed workstations with no personal software installation, and installers from any vendor should be validated against a known-good hash and detonated before use.","confidence":"Confirmed","sources":[{"title":"3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise","url":"https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise","publisher":"Mandiant / Google Cloud"},{"title":"3CX Breach Was a Double Supply Chain Compromise","url":"https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/","publisher":"Krebs on Security"},{"title":"Security Update 20 April 2023 - Initial Intrusion Vector Found","url":"https://www.3cx.com/blog/news/mandiant-security-update2/","publisher":"3CX"}],"entry_type":"incident","slug":"2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st"},{"title":"Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers","date":"2023-01-11","date_precision":"day","victim_org":"Mailchimp (Intuit)","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published; downstream Trezor customers were subsequently targeted by wallet-draining phishing.","records_affected":null,"threat_actor":null,"summary":"Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.","how_it_worked":"Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.","lessons":"Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.","confidence":"Confirmed","sources":[{"title":"Mailchimp suffers another data breach after social engineering attack on employees","url":"https://www.computing.co.uk/news/4063093/mailchimp-suffers-breach-social-engineering-attack-employees","publisher":"Computing"},{"title":"DigitalOcean says customer email addresses were exposed","url":"https://techcrunch.com/2022/08/16/digitalocean-emails-mailchimp-breach/","publisher":"TechCrunch"},{"title":"Impact to DigitalOcean customers resulting from Mailchimp security incident","url":"https://www.digitalocean.com/blog/digitalocean-response-to-mailchimp-security-incident","publisher":"DigitalOcean"},{"title":"Mailchimp suffers third breach in 12 months","url":"https://www.computerweekly.com/news/252529368/Mailchimp-suffers-third-breach-in-12-months","publisher":"Computer Weekly"},{"title":"IOTW: Mailchimp suffers another social engineering attack","url":"https://www.cshub.com/attacks/news/iotw-mailchimp-suffers-another-social-engineering-attack","publisher":"Cyber Security Hub"},{"title":"Mailchimp discloses a new security breach, the second one in 6 months","url":"https://securityaffairs.com/140997/data-breach/mailchimp-security-breach.html","publisher":"Security Affairs"},{"title":"Companies impacted by Mailchimp data breach warn their customers","url":"https://securityaffairs.com/141203/data-breach/companies-impacted-by-mailchimp-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor"},{"title":"Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds","date":"2022-11-07","date_precision":"day","victim_org":"Multiple (New York law firm, a Maltese bank, a Qatari businessman, others)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Restitution ordered of $1,732,841. Individual episodes included about $922,857 fraudulently induced from a New York law firm in October 2019 and an intended $14.7 million from a foreign bank cyber-heist; prosecutors said he conspired to launder over $300 million.","records_affected":null,"threat_actor":"Ramon Olorunwa Abbas ('Ray Hushpuppi'), Nigeria/UAE, with co-conspirator Ghaleb Alaumary","summary":"Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.","how_it_worked":"Abbas supplied the financial plumbing that makes BEC profitable. Co-conspirators compromised or spoofed the email of parties to real transactions, such as a law firm holding client funds for a closing, and issued altered wire instructions that matched a payment the victim already expected to make. Abbas provided and coordinated the receiving accounts, including accounts opened with fraudulent identity documents, and moved the proceeds rapidly across jurisdictions to defeat recall. He also ran advance-fee variants, extracting roughly $330,000 from a Qatari businessman seeking a $15 million school loan and then demanding further payments framed as taxes.","lessons":"Payment recipients in escrow and closing transactions should be verified by phone against instructions exchanged before the transaction opened, since the diversion email typically arrives at the exact moment a payment is expected.","confidence":"Confirmed","sources":[{"title":"Nigerian Man Sentenced to Over 11 Years in Federal Prison for Conspiring to Launder Tens of Millions of Dollars from Online Scams","url":"https://www.justice.gov/usao-cdca/pr/nigerian-man-sentenced-over-11-years-federal-prison-conspiring-launder-tens-millions","publisher":"U.S. Department of Justice, C.D. Cal."}],"entry_type":"campaign","slug":"2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce"},{"title":"Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing","date":"2022-10-14","date_precision":"day","victim_org":"Dropbox","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.","how_it_worked":"The lure imitated CircleCI, a service Dropbox developers used and which legitimately prompts users to sign in with GitHub, so the request to authenticate looked routine. The phishing page collected the GitHub username, password and the time-based one-time passcode, which the attacker replayed immediately to establish a session. With developer access they cloned 130 private repositories containing modified third-party libraries, internal prototypes, and some security team tools and configuration files, along with a few thousand names and email addresses for employees, current and past customers, sales leads and vendors. Dropbox rotated credentials and moved to accelerate its rollout of hardware security keys.","lessons":"Time-based one-time passcodes are phishable in real time; WebAuthn keys on source-control accounts, and machine-to-machine tokens scoped per repository, remove both halves of this attack.","confidence":"Confirmed","sources":[{"title":"130 Dropbox code repos plundered after successful phishing attack","url":"https://www.helpnetsecurity.com/2022/11/02/dropbox-data-breach/","publisher":"Help Net Security"},{"title":"Dropbox Suffers Data Breach From Phishing Attack, Exposing Customer and Employee Emails","url":"https://blog.gitguardian.com/dropbox-breach-hack-github-circleci/","publisher":"GitGuardian"},{"title":"Dropbox confirms serious security breach in which hackers stole code from 130 GitHub repositories","url":"https://betanews.com/2022/11/02/dropbox-confirms-serious-security-breach-in-which-hackers-stole-code-from-130-github-repositories/","publisher":"BetaNews"}],"entry_type":"incident","slug":"2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing"},{"slug":"2022-github-warns-of-phishing-campaign-impersonating-circleci-to-steal-develo","title":"GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials","date":"2022-09-16","date_precision":"day","year":2022,"victim_org":"GitHub users and customer organisations (GitHub-reported campaign)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.","how_it_worked":"Developers received emails claiming that CircleCI's terms of service and privacy policy had changed and that they needed to sign in to their GitHub account to keep using the service. The link led to a convincing GitHub log-in page under attacker control, which relayed the entered username, password and TOTP code to the real GitHub in real time. The pretext worked because CircleCI is a legitimate part of many developers' daily toolchain and a policy-update notice is mundane, while the audience, engineers with repository and token privileges, is exactly the population whose accounts unlock source code and downstream software supply chains.","lessons":"Hardware security keys are the only MFA form that survives a real-time relay, and organisations should alert on new personal access tokens, OAuth grants and SSH keys added to developer accounts.","confidence":"Confirmed","sources":[{"title":"Security alert: new phishing campaign targets GitHub users","url":"https://github.blog/news-insights/company-news/security-alert-new-phishing-campaign-targets-github-users/","publisher":"The GitHub Blog"},{"title":"Hackers Using Fake CircleCI Notifications to Hack GitHub Accounts","url":"https://thehackernews.com/2022/09/hackers-using-fake-circleci.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-github-warns-of-phishing-campaign-impersonating-circleci-to-steal-develo"},{"title":"DoorDash customer data exposed through phished third-party vendor employees","date":"2022-08-25","date_precision":"day","victim_org":"DoorDash","sector":"Transportation & Logistics","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (the campaign that also hit Twilio)","summary":"DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.","how_it_worked":"The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.","lessons":"Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.","confidence":"Confirmed","sources":[{"title":"DoorDash hit by data breach linked to Twilio hackers","url":"https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/","publisher":"TechCrunch"},{"title":"DoorDash discloses new data breach tied to Twilio hackers","url":"https://www.bleepingcomputer.com/news/security/doordash-discloses-new-data-breach-tied-to-twilio-hackers/","publisher":"BleepingComputer"},{"title":"DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others","url":"https://www.securityweek.com/doordash-data-compromised-following-twilio-hack/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ"},{"title":"FBI: business email compromise exposed $43 billion in losses across 177 countries","date":"2022-05-04","date_precision":"day","victim_org":"Businesses, government entities and individuals worldwide (multi-victim campaign)","sector":"Financial Services","country":"Global","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"The 2022 advisory does not describe AI-enabled BEC.","outcomes":["Wire Fraud / Financial Loss","Data Breach","Cryptocurrency Theft"],"loss_usd":43312749946,"loss_note":"$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.","records_affected":241206,"threat_actor":null,"summary":"On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.","how_it_worked":"BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.","lessons":"Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.","confidence":"Confirmed","sources":[{"title":"Business Email Compromise: The $43 Billion Scam","url":"https://www.ic3.gov/PSA/2022/PSA220504","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co","year":2022,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"},{"title":"Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds","date":"2022-04-03","date_precision":"day","victim_org":"SatoshiLabs (Trezor), via email provider Mailchimp","sector":"Cryptocurrency","country":"Czech Republic","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Data Breach","Credential Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Neither Trezor nor Mailchimp published a loss figure, and Trezor said at the time it was unclear whether any funds were successfully stolen. The '106,856 customers' figure that circulated came from the phishing email itself and was attacker-authored text, not a confirmed breach count.","records_affected":null,"threat_actor":"Unattributed actor targeting cryptocurrency-sector Mailchimp tenants","summary":"Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.","how_it_worked":"The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.","lessons":"Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.","confidence":"Confirmed","sources":[{"title":"Ongoing phishing attacks on Trezor users","url":"https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304","publisher":"Trezor (SatoshiLabs)"},{"title":"Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam","url":"https://decrypt.co/96942/mailchimp-insider-targets-trezor-crypto-wallets-phishing-scam","publisher":"Decrypt"}],"entry_type":"incident","slug":"2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"},{"title":"Operation Eagle Sweep: 65 arrests in global BEC disruption","date":"2022-03-30","date_precision":"day","victim_org":"Multiple businesses and individuals (500+ U.S. victims)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Attempt Blocked"],"loss_usd":null,"loss_note":"Not a single-victim loss. The targeted actors were tied to more than 500 U.S. victims and over $51 million in losses; FBI noted nearly $2.4 billion in reported BEC/EAC losses in 2021.","records_affected":null,"threat_actor":"BEC networks arrested in Nigeria, South Africa, Canada and Cambodia, plus U.S.-based money laundering cells","summary":"Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.","how_it_worked":"The disrupted crews used compromised or spoofed business email accounts to insert themselves into payment flows, then requested wires or changed the banking details on invoices, closings and payroll so victims paid criminals instead of counterparties. The same organizations also targeted individuals, especially real estate purchasers and elderly victims, using romance and advance-fee variants that share the same laundering back end. Proceeds were collected in U.S.-based mule accounts, often opened with stolen or synthetic identities, and forwarded to Nigeria and other destinations. Enforcement paired arrests of the fraud operators with prosecutions of the laundering cells to reduce the networks' ability to cash out.","lessons":"Because the same infrastructure serves corporate and consumer variants, banks and businesses benefit most from beneficiary-account verification and rapid kill-chain reporting rather than victim-type-specific controls.","confidence":"Confirmed","sources":[{"title":"Global Operation Disrupts Business Email Compromise Schemes","url":"https://www.fbi.gov/news/stories/coordinated-operation-disrupts-global-bec-schemes-033022","publisher":"Federal Bureau of Investigation"}],"entry_type":"campaign","slug":"2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption"},{"slug":"2022-hubspot-employee-account-compromised-exposing-customer-data-at-crypto-fi","title":"HubSpot employee account compromised, exposing customer data at crypto firms","date":"2022-03-18","date_precision":"day","year":2022,"victim_org":"HubSpot","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Supply Chain Compromise","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.","how_it_worked":"The attacker gained control of a single HubSpot employee's account and then used the internal support tooling that comes with it. That tooling is designed to let staff assist customers by reaching into their portals, so once inside there was no further exploitation required, only the normal use of a legitimate function. The attacker moved directly to cryptocurrency customers, exported their marketing contact lists, and thereby obtained the names, email addresses and in some cases phone numbers of people known to hold crypto, which is precisely the targeting list for follow-on phishing. Downstream customers had no visibility into the vendor account that held their data.","lessons":"Internal support tooling that can read customer data needs per-access justification, strict scoping and export alerting, so one compromised staff account cannot silently harvest many tenants.","confidence":"Confirmed","sources":[{"title":"Cryptocurrency Services Hit by Data Breach at CRM Company HubSpot","url":"https://www.securityweek.com/cryptocurrency-services-hit-data-breach-crm-company-hubspot/","publisher":"SecurityWeek"},{"title":"HubSpot Data Breach Ripples Through Cryptocurrency Industry","url":"https://threatpost.com/hubspot-data-breach-crytocurrency-industry/179086/","publisher":"Threatpost"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-hubspot-employee-account-compromised-exposing-customer-data-at-crypto-fi"},{"title":"Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling","date":"2022-01-21","date_precision":"day","victim_org":"Okta (via subprocessor Sitel/Sykes)","sector":"Technology","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Okta did not disclose a financial loss figure.","records_affected":null,"threat_actor":"Lapsus$","summary":"A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.","how_it_worked":"Lapsus$ specialised in abusing the human layer of outsourced IT: support agents at business-process outsourcers hold standing, broadly scoped access to customer tenants but sit outside the customer's own security controls. Having taken over a Sitel engineer's workstation, the actor inherited that trusted seat and drove the Okta SuperUser console as the agent, in the agent's session, from the agent's device. No password or MFA prompt was presented to the attacker because the legitimate operator had already satisfied them. The blast radius was limited only by what the support role could do.","lessons":"Outsourced support seats need the same scrutiny as privileged internal admins: just-in-time, scoped, session-recorded access with device trust, rather than standing tenant-wide impersonation rights.","confidence":"Confirmed","sources":[{"title":"Okta Concludes its Investigation Into the January 2022 Compromise","url":"https://www.okta.com/blog/company-and-culture/okta-concludes-its-investigation-into-the-january-2022-compromise/","publisher":"Okta"},{"title":"Okta says hundreds of companies impacted by security breach","url":"https://techcrunch.com/2022/03/23/okta-breach-sykes-sitel/","publisher":"TechCrunch"}],"entry_type":"incident","slug":"2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling"},{"slug":"2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak","title":"Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover","date":"2021-07","date_precision":"month","year":2021,"victim_org":"Town of Peterborough, New Hampshire","sector":"Government","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2300000,"loss_kind":"direct_loss","loss_note":"About US$2.3 million diverted, roughly 15 percent of the town's annual budget; the US Secret Service recovered US$594,331 that had not yet been converted to cryptocurrency.","records_affected":null,"threat_actor":null,"summary":"The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.","how_it_worked":"After taking over a town finance employee's email account, the attackers read the genuine correspondence with two payees, the regional school district and a bridge construction contractor, both of which had asked to be paid by electronic transfer. They then inserted themselves into those live threads with revised banking details, and deleted the payees' incoming emails so that the real counterparties' queries never reached town staff. The town had procedures requiring notarised change forms and confirmatory phone calls, but staff who were supposed to check each other's work did not follow them, which is what let the diverted payments clear.","lessons":"Existing verification procedures only work if they are enforced; mailbox rule creation and mass deletion in a finance account should also raise an automatic alert.","confidence":"Confirmed","sources":[{"title":"Peterborough payment scam: Single compromised email account led to $2.3M theft","url":"https://ledgertranscript.com/2021/10/05/pbscam-ml-100521-42830401/","publisher":"Monadnock Ledger-Transcript"},{"title":"Cyber-thieves Scam New Hampshire Town Out of $2.3m","url":"https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak"},{"title":"One Treasure Island nonprofit loses $650,000 to hijacked email thread","date":"2021","date_precision":"year","victim_org":"One Treasure Island","sector":"Nonprofit","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":650000,"loss_note":"$650,000 diverted. Funds initially landed at a bank in Odessa, Texas; the nonprofit reported difficulty obtaining law enforcement and bank assistance and no recovery was confirmed in the cited reporting.","records_affected":null,"threat_actor":null,"summary":"One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.","how_it_worked":"The attackers took over the outsourced bookkeeper's mailbox, which sat at the center of the nonprofit's payment approvals, and then replied inside a live thread about a pending grant disbursement rather than starting fresh correspondence. Because the message carried the real address, the real subject line and the real transaction context, the substituted wiring instructions read as an ordinary administrative update. Staff sent the $650,000 grant payment to the criminals' account at a small out-of-state bank, which was then drained onward. The organization discovered the diversion only when the intended recipient reported non-receipt, and small-nonprofit resourcing left it largely on its own to chase the money.","lessons":"Thread hijacking beats sender-address checks, so any change of wire instructions inside an existing thread must trigger a verbal callback to a previously known number before funds move.","confidence":"Reported","sources":[{"title":"Scammed San Francisco Nonprofit Falls Victim to Costliest Type of Cybercrime","url":"https://www.cbsnews.com/sanfrancisco/news/scammed-san-francisco-nonprofit-falls-victim-to-costliest-type-of-cybercrime/","publisher":"CBS News Bay Area / Associated Press"},{"title":"A nonprofit that helps the poor lost $650,000 to scammers","url":"https://www.sfchronicle.com/crime/article/S-F-nonprofit-lost-650-000-to-hackers-and-a-16191669.php","publisher":"San Francisco Chronicle"}],"entry_type":"incident","slug":"2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread","year":2021,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread"},{"slug":"2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a","title":"Baltimore County schools ransomware started with a contractor opening a phishing email","date":"2020-11-24","date_precision":"day","year":2020,"victim_org":"Baltimore County Public Schools","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Service Disruption","Data Breach"],"loss_usd":9700000,"loss_kind":"business_impact","loss_note":"About US$9.7 million in recovery and remediation costs according to the Maryland Office of the Inspector General for Education; no ransom was paid.","records_affected":null,"threat_actor":"Ryuk (reported)","summary":"Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.","how_it_worked":"A contractor working with the district opened a malicious email attachment, which established the foothold that led to district-wide encryption on the eve of the Thanksgiving holiday, a timing choice that maximised the gap before anyone noticed. The Inspector General's report placed the weight of the finding not on the click but on what surrounded it: the district had received specific security recommendations from a prior state audit and had not implemented them, and had extended network access to a contractor without correspondingly hardened controls. Remote learning for 115,000 students halted, and rebuilding cost nearly ten million dollars.","lessons":"Contractor accounts need the same email defences, MFA and least privilege as employees, and audit findings left unimplemented become the incident's root cause.","confidence":"Confirmed","sources":[{"title":"Baltimore County schools ignored warnings before 2020 cyberattack, audit finds","url":"https://statescoop.com/baltimore-county-schools-ransomware-attack-2020-inspector-general/","publisher":"StateScoop"},{"title":"Report: Contractor 'mistakenly' opened email starting Baltimore County school cyberattack","url":"https://foxbaltimore.com/news/local/investigative-report-released-2-years-after-baltimore-county-schools-cyberattack","publisher":"Fox Baltimore (WBFF)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a"},{"title":"WHO impersonation surge during COVID-19 targets donors and staff","date":"2020-04-23","date_precision":"day","victim_org":"World Health Organization and the general public (multi-victim campaign)","sector":"Healthcare","country":"Global","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in 2020.","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_note":"WHO did not publish a total for donations diverted by impersonators.","records_affected":450,"threat_actor":null,"summary":"On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.","how_it_worked":"Attackers exploited the single most trusted authority of the moment. Emails carrying WHO branding promised guidance on the outbreak and asked recipients to click through to a credential capture page or open an attachment, and separate campaigns solicited donations to a fake version of the COVID-19 Solidarity Response Fund or issued invoices purporting to come from it. The lever was fear plus civic goodwill under acute uncertainty, when recipients were actively seeking official pandemic information and wanted to help. The leaked credentials came from an older extranet system used by current staff, retired employees and partners.","lessons":"Legacy extranets holding partner credentials must be retired or moved behind modern multi-factor authentication, and public-facing agencies should publish a single authoritative donation channel to make impersonation obvious.","confidence":"Confirmed","sources":[{"title":"WHO reports fivefold increase in cyber attacks, urges vigilance","url":"https://www.who.int/news/item/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance","publisher":"World Health Organization"},{"title":"Cyber security: beware of criminals pretending to be WHO","url":"https://www.who.int/about/cyber-security","publisher":"World Health Organization"}],"entry_type":"campaign","slug":"2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff"},{"slug":"2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c","title":"Magellan Health ransomware began with a phishing email impersonating a client","date":"2020-04-06","date_precision":"day","year":2020,"victim_org":"Magellan Health","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Credential Theft","Extortion"],"loss_usd":1430000,"loss_kind":"business_impact","loss_note":"US$1.43 million class-action settlement resolving claims over the breach and the delay in notification.","records_affected":364892,"threat_actor":null,"summary":"Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.","how_it_worked":"The attacker impersonated one of Magellan's own clients, which is a stronger pretext than a generic executive spoof because a managed care company's staff correspond with client organisations constantly and are expected to be responsive to them. The employee provided access credentials in response to that message. Over the following five days the attackers moved through the network, reached a corporate server holding employee records including tax documentation with Social Security numbers, exfiltrated a subset of it, and installed software to harvest further log-ins before triggering encryption. The five-day dwell time is where the data theft happened.","lessons":"Client-impersonation phishing defeats seniority-based suspicion, so the control is MFA plus detection of internal reconnaissance in the days between the click and the encryption.","confidence":"Confirmed","sources":[{"title":"Data Stolen in Magellan Health Ransomware Attack","url":"https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/","publisher":"HIPAA Journal"},{"title":"Healthcare giant Magellan Health hit by ransomware attack","url":"https://www.bleepingcomputer.com/news/security/healthcare-giant-magellan-health-hit-by-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c"},{"title":"Puerto Rico government agency sends $2.6 million to fraudulent account","date":"2020-01-17","date_precision":"day","victim_org":"Puerto Rico Industrial Development Company (PRIDCO)","sector":"Government","country":"Puerto Rico","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2600000,"loss_note":"$2.6 million transferred on January 17, 2020. Recovery outcome not confirmed in the cited reporting.","records_affected":null,"threat_actor":null,"summary":"Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.","how_it_worked":"The scheme exploited an inter-agency remittance payment process in which large periodic transfers are routine and the receiving party is trusted. The fraudulent email announced a change of banking details for those remittances, a message finance staff had reason to expect from time to time, and gave no cause for alarm because it referenced a genuine payment relationship. Officials updated the destination details and executed the scheduled payment of $2.6 million into the criminals' account. The loss surfaced only when the legitimate recipient's non-receipt was noticed, by which time the funds had left the account, prompting a complaint to police and a wider review of government payment controls.","lessons":"Government payment offices need a standing rule that account-change notices are never actioned from email alone, plus periodic reconciliation with recipients to catch a diversion within days rather than weeks.","confidence":"Confirmed","sources":[{"title":"Official says Puerto Rico government lost $2.6M in phishing scam","url":"https://www.pbs.org/newshour/nation/official-says-puerto-rico-government-lost-2-6m-in-phishing-scam","publisher":"PBS NewsHour / Associated Press"}],"entry_type":"incident","slug":"2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account","year":2020,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account"},{"title":"Operation reWired: 281 arrested worldwide in BEC crackdown","date":"2019-09-10","date_precision":"day","victim_org":"Multiple businesses and individuals (global)","sector":"Other","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal","Romance / Investment Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss","Attempt Blocked","Identity Theft"],"loss_usd":null,"loss_note":"Not a single-victim loss. The four-month operation produced 281 arrests, seized about $3.7 million and disrupted roughly $118 million in fraudulent wire transfers. IC3 reported nearly $1.3 billion in BEC/EAC losses for 2018 alone.","records_affected":null,"threat_actor":"Multiple BEC networks, predominantly Nigeria-based, plus actors in Turkey and Ghana","summary":"Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.","how_it_worked":"Operators compromised business and personal email accounts through phishing and credential theft, then monitored correspondence to time an intervention around a real pending payment. When a legitimate invoice, payroll run or closing disbursement was in flight, they injected altered banking instructions that appeared to come from the known counterparty. Victims spanned companies, schools, energy firms, seniors and real estate purchasers. Proceeds were funneled through networks of money mules and fictitious identities before being sent overseas. Thirty-nine FBI field offices and partners in nine countries coordinated arrests, seizures and mule warning letters simultaneously to disrupt both the fraud and its laundering infrastructure.","lessons":"Because criminal proceeds move through domestic mule accounts within hours, rapid reporting to the FBI's IC3 Recovery Asset Team is the single most effective control after a diverted payment is discovered.","confidence":"Confirmed","sources":[{"title":"281 Arrested Worldwide in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes","url":"https://www.justice.gov/archives/opa/pr/281-arrested-worldwide-coordinated-international-enforcement-operation-targeting-hundreds","publisher":"U.S. Department of Justice"},{"title":"Operation reWired","url":"https://www.fbi.gov/news/stories/operation-rewired-bec-takedown-091019","publisher":"Federal Bureau of Investigation"},{"title":"74 Arrested in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes","url":"https://www.justice.gov/archives/opa/pr/74-arrested-coordinated-international-enforcement-operation-targeting-hundreds-individuals","publisher":"U.S. Department of Justice"}],"entry_type":"campaign","slug":"2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown","year":2019,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown"},{"title":"Toyota Boshoku European unit loses $37 million to payment-instruction BEC","date":"2019-08-14","date_precision":"day","victim_org":"Toyota Boshoku Corporation (European subsidiary)","sector":"Manufacturing","country":"Japan","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":37000000,"loss_note":"Approximately ¥4 billion, reported as about $37 million; the company said it was pursuing recovery of the funds.","records_affected":null,"threat_actor":null,"summary":"Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.","how_it_worked":"Attackers sent messages that impersonated a trading partner or an internal authority and instructed the subsidiary's finance function to redirect a large trade payment to a different bank account. Because the amount and the counterparty were consistent with the subsidiary's normal automotive supply-chain payments, the request did not stand out, and the transfer was executed on the strength of the emailed instruction alone. The loss was discovered after the fact, and Toyota Boshoku disclosed it to the market alongside a downward revision of expected results while pursuing legal recovery.","lessons":"Any instruction that changes payee bank details, even mid-transaction with a known partner, should require independent verification through an established contact and a second approver outside the requesting chain.","confidence":"Confirmed","sources":[{"title":"Over $37 Million Lost by Toyota Boshoku Subsidiary in BEC Scam","url":"https://www.bleepingcomputer.com/news/security/over-37-million-lost-by-toyota-boshoku-subsidiary-in-bec-scam/","publisher":"BleepingComputer"},{"title":"Toyota Parts Supplier Loses $37 Million in Email Scam","url":"https://www.tripwire.com/state-of-security/toyota-parts-supplier-loses-37-million-email-scam","publisher":"Tripwire State of Security"},{"title":"Toyota Boshoku Corporation lost over $37 Million following BEC attack","url":"https://securityaffairs.com/90955/cyber-crime/toyota-boshoku-corporation-bec.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec","year":2019,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec"},{"slug":"2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu","title":"Wipro employee accounts phished and used to attack the IT giant's own customers","date":"2019-04","date_precision":"month","year":2019,"victim_org":"Wipro Limited","sector":"Technology","country":"India","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Supply Chain Compromise","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.","how_it_worked":"Attackers ran a phishing campaign against Wipro staff and captured credentials for a number of corporate accounts. The value of those accounts was not Wipro's own data but Wipro's position as a trusted outsourcing provider with standing access into client environments. Emails sent from genuine Wipro addresses to client contacts carry an authority that no spoofed domain can match, so the compromised mailboxes became the delivery mechanism for attacks on downstream customers. The follow-on activity was financially motivated, centring on gift-card and payment fraud at the affected clients rather than espionage.","lessons":"Managed service providers need phishing-resistant MFA on all staff accounts and customer-side monitoring of provider access, because a phished MSP mailbox is a trusted channel into every client.","confidence":"Confirmed","sources":[{"title":"Wipro admits to potential breach to employee accounts by phishing attack","url":"https://www.computerweekly.com/news/252461760/Wipro-admits-to-potential-breach-to-employee-accounts-by-phishing-attack","publisher":"Computer Weekly"},{"title":"How Not to Acknowledge a Data Breach","url":"https://krebsonsecurity.com/2019/04/how-not-to-acknowledge-a-data-breach/comment-page-1/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu"},{"title":"Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer","date":"2019-03-19","date_precision":"day","victim_org":"Norsk Hydro ASA","sector":"Manufacturing","country":"Norway","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption"],"loss_usd":71000000,"loss_note":"Microsoft's account of the incident states the financial impact would eventually approach $71 million; Hydro's own quarterly disclosures gave figures in a similar range and the company was partly insured.","records_affected":null,"threat_actor":"LockerGoga operators","summary":"Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.","how_it_worked":"The attackers first compromised a customer's mailbox, then used that genuine business relationship to send a document attachment to a Hydro employee. Because the sender was a real, expected correspondent, the attachment was opened and installed a trojan. Over the following months the intruders escalated into Active Directory, obtained domain-level control and then pushed LockerGoga across the estate, which encrypted files and, in some variants, changed local account passwords and logged users out. Hydro's 35,000 employees across 40 countries lost access to IT systems; some smelters ran on paper procedures for weeks.","lessons":"Attachments from known senders still need detonation and macro controls, and tiered Active Directory administration prevents a single infected desktop from becoming domain-wide ransomware deployment.","confidence":"Reported","sources":[{"title":"Hackers hit Norsk Hydro with ransomware. The company responded with transparency","url":"https://news.microsoft.com/source/features/digital-transformation/hackers-hit-norsk-hydro-ransomware-company-responded-transparency/","publisher":"Microsoft Source"},{"title":"Norsk Hydro responds to ransomware attack with transparency","url":"https://www.microsoft.com/en-us/security/blog/2019/12/17/norsk-hydro-ransomware-attack-transparency/","publisher":"Microsoft Security Blog"},{"title":"Hydro Hit by LockerGoga Ransomware via Active Directory","url":"https://www.bankinfosecurity.com/hydro-hit-by-lockergoga-ransomware-via-active-directory-a-12207","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted","year":2019,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted"},{"title":"Tecnimont India loses $18.6 million to fake CEO conference calls","date":"2018-12","date_precision":"month","victim_org":"Tecnimont SpA (Indian subsidiary, Maire Tecnimont group)","sector":"Professional Services","country":"India","primary_vector":"Business Email Compromise","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"Impersonation on the conference calls was performed by live human actors; no synthetic voice was reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":18600000,"loss_note":"About 1.3 billion rupees, reported as roughly $18.5-18.6 million, sent in three installments to banks in Hong Kong.","records_affected":null,"threat_actor":"Group reported by the company to be operating from China","summary":"The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.","how_it_worked":"This scheme layered voice over email to defeat skepticism. Messages arrived from a domain closely resembling the group CEO's, describing a secret acquisition in China that had to be funded from India because regulatory constraints supposedly blocked transfers from Italy. To answer the obvious objection, the fraudsters convened conference calls in which multiple actors played the CEO, group executives and an external Swiss attorney, giving the transaction the texture of a real deal team. Secrecy was justified as regulatory sensitivity, which kept the India head from calling headquarters. Three tranches were wired to Hong Kong before the parent company discovered the deception.","lessons":"Verification must go through a channel the attacker does not control: a callback to headquarters' known switchboard would have collapsed the entire fake deal team.","confidence":"Reported","sources":[{"title":"Chinese group swindles $18.5 million from Indian arm of Italian company","url":"https://in.marketscreener.com/quote/stock/MAIRE-S-P-A-13369769/news/Maire-Tecnimont-Chinese-group-swindles-18-5-million-from-Indian-arm-of-Italian-company-Economic-27846733/","publisher":"The Economic Times via MarketScreener"},{"title":"BEC Scam Leads to Theft of $18.6 Million","url":"https://www.bankinfosecurity.com/bec-scam-leads-to-theft-186-million-fraud-a-11930","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls"},{"title":"Cabarrus County, NC diverts $2.5 million school payment to BEC actors","date":"2018-11","date_precision":"month","victim_org":"Cabarrus County, North Carolina","sector":"Government","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":2504601,"loss_note":"$2,504,601 paid to fraudsters; $776,518.40 recovered, leaving about $1.7 million unrecovered.","records_affected":null,"threat_actor":null,"summary":"Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.","how_it_worked":"The attackers targeted the vendor master-data process rather than a single invoice. Posing as the school construction contractor, they submitted a bank-account change request accompanied by forms and signatures that matched what the county's finance staff expected to see for a legitimate update. Once the fraudulent account details were accepted into the vendor record, the next scheduled construction draw, more than $2.5 million, flowed to the criminals automatically through the county's normal payment run, with no anomaly to catch. The money was then layered through multiple downstream accounts, and only a fraction was traced and clawed back after the county recognized the diversion weeks later.","lessons":"Vendor bank-detail changes should be treated as a privileged change: verified by outbound call to a number from the original contract, confirmed by a second staffer, and followed by a small test payment before the next large draw.","confidence":"Confirmed","sources":[{"title":"Scammers Grab $2.5 Million From North Carolina County in BEC Scam","url":"https://www.securityweek.com/scammers-grab-25-million-north-carolina-county-bec-scam/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors","year":2018,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors"},{"title":"Dublin Zoo defrauded of about €500,000 in invoice redirection scam","date":"2017","date_precision":"year","victim_org":"Dublin Zoo","sector":"Other","country":"Ireland","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Approximately €500,000 was diverted; Gardaí recovered most of the funds, with reporting indicating roughly €130,000 outstanding. No official USD figure was published.","records_affected":null,"threat_actor":null,"summary":"Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.","how_it_worked":"The scheme substituted the destination account on invoices the zoo already expected to pay, so nothing about the amount, the supplier name or the timing looked unusual. Criminals obtained or replicated genuine invoices and presented altered bank details as a routine change of the supplier's account, communicated by email or phone. Finance staff updated the payment details and released the payments in the ordinary run. Gardaí publicly warned after the case that no business should change a supplier's bank account number on the basis of a call or email without verifying the change with a known contact at the supplier, which is precisely the control gap the fraud exploited.","lessons":"Treat supplier bank-detail changes as a security event requiring verification with a known contact using previously held numbers, and reconcile with suppliers promptly so a diversion is caught while funds are still recoverable.","confidence":"Reported","sources":[{"title":"Dublin Zoo lost €500k after falling victim to cyber scam","url":"https://www.irishexaminer.com/ireland/dublin-zoo-lost-500k-after-falling-victim-to-cyber-scam-464818.html","publisher":"Irish Examiner"}],"entry_type":"incident","slug":"2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam"}]}