{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:17:36.599Z","total":100,"returned":50,"limit":50,"offset":0,"next":"https://global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vishing+%28Voice+Phishing%29&offset=50&limit=50","note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ReliaQuest blocks ShinyHunters vishing attack with device-trust controls","date":"2026-08-24","date_precision":"day","victim_org":"ReliaQuest","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"ReliaQuest did not state whether synthetic voice was used on the calls.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; no customer data was accessed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.","how_it_worked":"The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.","lessons":"Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.","confidence":"Confirmed","sources":[{"title":"ReliaQuest confirms failed data-theft attack after ShinyHunters breach","url":"https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"},{"slug":"2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ","title":"Levi Strauss files 8-K after social engineering compromises three employee computers","date":"2026-08-07","date_precision":"day","year":2026,"victim_org":"Levi Strauss & Co.","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.","how_it_worked":"Levi Strauss disclosed only that the vector was social engineering against employees, without naming the technique. The linkage Reuters drew to a crew running a five-week, 200-company spree matches the voice-phishing-plus-lookalike-portal pattern dominant through 2026, in which callers impersonating IT support harvest credentials and session tokens from individual staff. Access reached three endpoints and corporate data was taken before the company contained it. Levi Strauss activated incident response and engaged third-party specialists; consumer systems were reported unaffected.","lessons":"Phishing-resistant MFA plus rapid session revocation limits a three-endpoint compromise to exactly that; the 8-K filing over three laptops shows how cheaply this vector reaches material-disclosure territory.","confidence":"Confirmed","sources":[{"title":"Levi Strauss discloses data breach after social engineering attack on employees","url":"https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/","publisher":"CyberInsider"},{"title":"Levi Strauss describes contained cyber incident, LEVI 8-K filing","url":"https://www.stocktitan.net/sec-filings/LEVI/8-k-levi-strauss-co-reports-material-event-0f6321560e78.html","publisher":"StockTitan (SEC filing)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ"},{"title":"Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks","date":"2026-08-06","date_precision":"day","victim_org":"Point72, Millennium Management, Two Sigma, Citadel and private-equity firms","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.","outcomes":["Attempt Blocked","Extortion","Credential Theft"],"loss_usd":10600000,"loss_note":"Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.","records_affected":null,"threat_actor":"UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon","summary":"BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.","how_it_worked":"Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.","lessons":"Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.","confidence":"Confirmed","sources":[{"title":"Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group","url":"https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at","year":2026,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"},{"slug":"2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee","title":"Brinks Home breached after Microsoft Entra vishing call to an employee","date":"2026-07-13","date_precision":"day","year":2026,"victim_org":"Brinks Home","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.","how_it_worked":"The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.","lessons":"Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.","confidence":"Confirmed","sources":[{"title":"ShinyHunters claims Brinks Home breach, threatens to leak stolen data","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/","publisher":"BleepingComputer"},{"title":"Salesforce Hacks 2026: Everything We Know So Far","url":"https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"},{"title":"Apollo Global Management breached by BlackFile callers posing as IT support","date":"2026-07-06","date_precision":"day","victim_org":"Apollo Global Management","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Researchers described a large pool of human callers recruited for small fees rather than synthetic voice.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"Apollo did not disclose a figure; researchers said BlackFile typically opens around $3 million and settles under $1 million.","records_affected":null,"threat_actor":"BlackFile (tracked by Google as UNC6671), part of The Com, operating the Redact, Pink, Helix and Falcon extortion brands","summary":"Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.","how_it_worked":"BlackFile industrialised the phone call. Researchers describe hundreds of callers, often low-level people recruited for a small fee or for standing within the group, dialling employees while impersonating internal IT support until one target complies. Volume replaces finesse: the crew averages about 1.5 new victims a day and has hit private equity firms, law firms, ratings agencies and medical technology companies. Once an identity is obtained the operators move into cloud platforms and collect data for extortion, escalating with threatening messages and swatting when victims resist.","lessons":"Phishing-resistant MFA plus a strict no-credentials-over-the-phone policy blunts high-volume calling, and cloud data stores need export alerting because these crews steal rather than encrypt.","confidence":"Confirmed","sources":[{"title":"Apollo discloses data breach from ongoing wave of attacks hitting financial sector","url":"https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/","publisher":"CyberScoop"},{"title":"Details emerge on BlackFile's recent attacks on financial companies","url":"https://cyberscoop.com/blackfile-cyberattacks-financial-sector/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"},{"slug":"2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai","title":"RingCentral data on 1.6M accounts leaked after social engineering campaign","date":"2026-07","date_precision":"month","year":2026,"victim_org":"RingCentral","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1600000,"threat_actor":"ShinyHunters","summary":"Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.","how_it_worked":"RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.","lessons":"Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.","confidence":"Confirmed","sources":[{"title":"RingCentral data breach exposed info of 1.6 million accounts","url":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","publisher":"BleepingComputer"},{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","url":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai"},{"slug":"2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe","title":"Abbott investigates ShinyHunters claim after mid-June vishing on employees","date":"2026-06","date_precision":"month","year":2026,"victim_org":"Abbott Laboratories (legacy Exact Sciences systems)","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.","how_it_worked":"Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.","lessons":"Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.","confidence":"Reported","sources":[{"title":"Abbott Investigating Cyberattack Claims From Two Threat Actors","url":"https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/","publisher":"HIPAA Journal"},{"title":"Abbott investigates after ShinyHunters claims massive data theft","url":"https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"},{"title":"Quantum Health network breached after social engineering call to a user","date":"2026-05-29","date_precision":"day","victim_org":"Quantum Health","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.","how_it_worked":"The intrusion started with a phone call rather than an email or an exploit. The caller persuaded a legitimate user to hand over the credentials needed to reach the network, and the attacker then held that access for roughly four days. Because the login was valid and used in a normal way, nothing surfaced until a network disruption on June 1 prompted investigation. HIPAA Journal noted that the tradecraft aligns with tactics commonly employed by the ShinyHunters threat group, though no ransomware operation claimed the incident.","lessons":"Phishing-resistant MFA prevents a disclosed password from being usable, and impossible-travel or new-device alerts would have flagged the four-day window of unfamiliar access.","confidence":"Reported","sources":[{"title":"Vishing Attack on Quantum Health Network Exposed Patient Data","url":"https://www.hipaajournal.com/quantum-health-precision-imaging-centers-heart-america-data-breaches/","publisher":"The HIPAA Journal"}],"entry_type":"incident","slug":"2026-quantum-health-network-breached-after-social-engineering-call-to-a-user","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-quantum-health-network-breached-after-social-engineering-call-to-a-user"},{"slug":"2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials","title":"MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices","date":"2026-05-06","date_precision":"day","year":2026,"victim_org":"Multiple organisations in the United States and MENA (unnamed)","sector":"Manufacturing","country":"United States and Middle East / North Africa","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"MuddyWater (Seedworm), assessed as linked to Iran's Ministry of Intelligence and Security, operating behind Chaos ransomware branding","summary":"Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.","how_it_worked":"The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.","lessons":"Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.","confidence":"Reported","sources":[{"title":"Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware","url":"https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/","publisher":"Rapid7 Labs"},{"title":"MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack","url":"https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"},{"slug":"2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft","title":"Cushman & Wakefield confirms vishing-triggered Salesforce data theft","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Cushman & Wakefield","sector":"Professional Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters; Qilin also claimed the victim","summary":"Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.","how_it_worked":"The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.","lessons":"Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.","confidence":"Confirmed","sources":[{"title":"Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim","url":"https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/","publisher":"Cybernews"},{"title":"Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped","url":"https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/","publisher":"Breached.Company"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"},{"slug":"2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat","title":"UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services","sector":"Other","country":"Global","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":10600000,"loss_kind":"criminal_proceeds","loss_note":"USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.","records_affected":null,"threat_actor":"UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)","summary":"Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.","how_it_worked":"Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.","lessons":"Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.","confidence":"Confirmed","sources":[{"title":"Vishing Extortion Group UNC6671 Rebrands After Making Millions","url":"https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/","publisher":"SecurityWeek"},{"title":"UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data","url":"https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"},{"slug":"2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca","title":"City of Aurora loses $1.1M after employee falls for bank impersonation call","date":"2026-04-29","date_precision":"day","year":2026,"victim_org":"City of Aurora, Illinois","sector":"Government","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":1100000,"loss_kind":"direct_loss","loss_note":"USD, approximately $1.1 million taken from municipal payroll accounts. Recovery efforts ongoing with law enforcement and the bank; the city carries insurance covering losses of this type.","records_affected":null,"threat_actor":null,"summary":"On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.","how_it_worked":"The pretext was routine banking business and the identity impersonated was the city's own financial institution, the party a finance employee expects to hear from about account matters. Officials described these schemes as exploiting trust and manufacturing urgency, and the deception worked purely by phone; nothing was hacked. The employee supplied account credentials or verification details during the call, which the fraudster immediately used to authorise transfers out of city payroll accounts. Discovery came shortly after the payments cleared.","lessons":"A hard rule that no banking detail or verification code is ever given on an inbound call, only on a callback to a number held on file, plus bank-side dual authorisation on outbound transfers.","confidence":"Confirmed","sources":[{"title":"Aurora lost nearly $1.1M from city bank accounts after employee fell for phone scam, officials say","url":"https://www.nbcchicago.com/news/local/aurora-lost-1-1m-from-city-bank-accounts-after-employee-fell-for-phone-scam-officials-say/3939104/","publisher":"NBC Chicago"},{"title":"'Social Engineering Fraud' Cost Aurora, Ill., Nearly $1.1M","url":"https://www.govtech.com/security/social-engineering-fraud-cost-aurora-ill-nearly-1-1m","publisher":"Government Technology"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca"},{"title":"ADT confirms breach after vishing attack on employee's Okta SSO account","date":"2026-04-20","date_precision":"day","victim_org":"ADT","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using AI voice agents in its vishing operations; AI use in the ADT call was not separately confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"ShinyHunters set an April 27, 2026 ransom deadline; no payment or loss figure was disclosed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.","how_it_worked":"An operator called an ADT employee posing as internal support and used a plausible authentication pretext to route them to a company-branded fake sign-in page. The page relayed the credentials and one-time code to the real Okta login in real time, giving the attacker a live SSO session. Because Salesforce sat behind that same single sign-on, the session opened the CRM directly, and the attackers exported customer and prospect records in bulk before ADT terminated the intrusion. Extortion followed, with a leak deadline set three days after public confirmation.","lessons":"Phishing-resistant passkeys bound to managed devices, plus export-volume alerting on the CRM, would have blocked both the credential relay and the bulk extraction.","confidence":"Confirmed","sources":[{"title":"ADT confirms data breach after ShinyHunters leak threat","url":"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/","publisher":"BleepingComputer"},{"title":"ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack","url":"https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack","publisher":"Rescana"}],"entry_type":"incident","slug":"2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account"},{"slug":"2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi","title":"Carnival confirms social engineering of an employee account exposed 6 million customers","date":"2026-04-14","date_precision":"day","year":2026,"victim_org":"Carnival Corporation","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5995277,"threat_actor":"ShinyHunters","summary":"Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.","how_it_worked":"Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.","lessons":"Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.","confidence":"Reported","sources":[{"title":"Carnival Cruise confirms data breach affecting nearly 6 million people","url":"https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/","publisher":"BleepingComputer"},{"title":"Carnival Data Breach Exposed 6 Million People","url":"https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/","publisher":"SecurityWeek"},{"title":"Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach","url":"https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach","publisher":"Office of the Texas Attorney General"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"},{"slug":"2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi","title":"Charter Communications breach of 4.9M accounts began with an Entra vishing call","date":"2026-04-01","date_precision":"day","year":2026,"victim_org":"Charter Communications (Spectrum)","sector":"Telecom","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4900000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.","how_it_worked":"The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.","lessons":"Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.","confidence":"Confirmed","sources":[{"title":"Charter Communications data breach affects 4.9 million accounts","url":"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/","publisher":"BleepingComputer"},{"title":"Charter confirms Spectrum data breach after ShinyHunters claims hack","url":"https://www.foxnews.com/tech/charter-breach-warning-customers-know","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi"},{"title":"Identity protection firm Aura breached in vishing attack; ~900,000 records taken","date":"2026-03","date_precision":"month","victim_org":"Aura","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call that compromised the employee account.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":900000,"threat_actor":"ShinyHunters","summary":"Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.","how_it_worked":"The attackers targeted a single employee account with a voice phishing call, the same pattern the group used against Okta and Microsoft Entra single sign-on accounts throughout early 2026: pose as internal IT, offer help with an authentication task, and capture credentials and a one-time code through a lookalike login page. The compromised account was live for only about an hour, but that was long enough to export a marketing database wholesale. The stolen combination of name, address, phone and email is itself high-quality raw material for follow-on phishing and vishing.","lessons":"Short-lived access still enables bulk export; rate-limiting and alerting on large database exports would have caught the theft inside the one-hour window.","confidence":"Reported","sources":[{"title":"Aura data breach","url":"https://en.wikipedia.org/wiki/Aura_data_breach","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records"},{"slug":"2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo","title":"Figure Technology loses ~967,000 customer records after employee falls for SSO vishing","date":"2026-02-19","date_precision":"day","year":2026,"victim_org":"Figure Technology Solutions","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":967000,"threat_actor":"ShinyHunters","summary":"Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.","how_it_worked":"The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.","lessons":"Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.","confidence":"Reported","sources":[{"title":"Nearly 1 Million User Records Compromised in Figure Data Breach","url":"https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/","publisher":"SecurityWeek"},{"title":"Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters","url":"https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/","publisher":"Cybernews"},{"title":"Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People","url":"https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"},{"slug":"2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod","title":"CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes","date":"2026-02-13","date_precision":"day","year":2026,"victim_org":"CarGurus","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.","how_it_worked":"Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.","lessons":"One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.","confidence":"Reported","sources":[{"title":"CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach","url":"https://news.dealershipguy.com/p/cargurus-probes-cyberattack-shinyhunters-theft-1-7-million-records-data-breach-2026-02-23","publisher":"Dealership Guy News"},{"title":"CarGurus Reported Data Breach","url":"https://complyauto.com/cargurus-reported-data-breach/","publisher":"ComplyAuto"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod"},{"title":"Optimizely confirms data breach after vishing attack on employees","date":"2026-02-11","date_precision":"day","victim_org":"Optimizely","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"Optimizely did not state whether synthetic voice was used on the calls.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed; the company said there was no disruption to business operations.","records_affected":null,"threat_actor":"Likely ShinyHunters-affiliated","summary":"Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.","how_it_worked":"Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.","lessons":"Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.","confidence":"Confirmed","sources":[{"title":"Ad tech firm Optimizely confirms data breach after vishing attack","url":"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees"},{"slug":"2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts","title":"Hims & Hers support tickets stolen through compromised Okta SSO accounts","date":"2026-02-04","date_precision":"day","year":2026,"victim_org":"Hims & Hers Health","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.","how_it_worked":"Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.","lessons":"Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.","confidence":"Confirmed","sources":[{"title":"Hims & Hers warns of data breach after Zendesk support ticket breach","url":"https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/","publisher":"BleepingComputer"},{"title":"Telehealth Giant Hims & Hers Announces Data Breach","url":"https://www.hipaajournal.com/him-hers-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts"},{"title":"BlackFile extortion gang runs vishing campaign against retail and hospitality","date":"2026-02","date_precision":"month","victim_org":"Multiple retail and hospitality organisations (unnamed)","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.","records_affected":null,"threat_actor":"BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)","summary":"BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.","how_it_worked":"Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.","lessons":"Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.","confidence":"Confirmed","sources":[{"title":"New BlackFile extortion gang targets retail and hospitality orgs","url":"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"},{"title":"STAC4749 Teams vishing campaign led to Chaos ransomware in North America","date":"2026-02","date_precision":"month","victim_org":"Dozens of North American organisations (unnamed)","sector":"Manufacturing","country":"Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No ransom or loss totals were disclosed.","records_affected":null,"threat_actor":"STAC4749, deploying Chaos ransomware","summary":"Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.","how_it_worked":"The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.","lessons":"Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.","confidence":"Confirmed","sources":[{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","url":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america"},{"slug":"2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli","title":"Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido (and subsidiary Ben)","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.","how_it_worked":"Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.","lessons":"Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.","confidence":"Reported","sources":[{"title":"Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling","url":"https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling","publisher":"NOS"},{"title":"Major hack of Dutch telco Odido was a classic case of social engineering","url":"https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/","publisher":"Techzine"},{"title":"Odido data breach exposes personal info of 6.2 million customers","url":"https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"},{"slug":"2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo","title":"Odido: IT impersonation calls and MFA approval requests expose 6.2M customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.","how_it_worked":"The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.","lessons":"Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.","confidence":"Confirmed","sources":[{"title":"Odido hackers pretended to be an IT employee to breach corporate system","url":"https://cybernews.com/security/odido-hackers-phishing-attack/","publisher":"Cybernews"},{"title":"Odido Salesforce Hack: Up to 6M Customers' Data at Risk","url":"https://www.salesforceben.com/odido-salesforce-hack-up-to-6m-customers-data-at-risk/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo"},{"slug":"2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill","title":"Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records","date":"2026-01-29","date_precision":"day","year":2026,"victim_org":"Match Group (Match, Hinge, OkCupid)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":10000000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.","how_it_worked":"The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.","lessons":"Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.","confidence":"Reported","sources":[{"title":"Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match","url":"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/","publisher":"BleepingComputer"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill"},{"slug":"2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering","title":"$282M in Bitcoin and Litecoin stolen from a holder via social engineering","date":"2026-01-10","date_precision":"day","year":2026,"victim_org":"Unnamed cryptocurrency holder","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Cryptocurrency Theft"],"loss_usd":282000000,"loss_kind":"direct_loss","loss_note":"USD value at time of theft of 1,459 BTC and 2.05 million LTC; no recovery reported.","records_affected":null,"threat_actor":null,"summary":"On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.","how_it_worked":"Reporting characterised the theft as a support-impersonation social engineering attack of the kind that has become the dominant loss driver in crypto: the attacker poses as an employee of a wallet or exchange provider, builds trust with the holder, and persuades them to hand over a seed phrase, sign a malicious transaction or surrender login details. The theft came days after hardware-wallet maker Ledger disclosed a breach exposing customer names and contact details, the kind of list that makes such calls credible. The victim has not been identified and the exact pretext was not published.","lessons":"No legitimate wallet or exchange support agent ever needs a seed phrase or a remote-access session; large holdings belong behind multi-signature approval with an out-of-band co-signer.","confidence":"Reported","sources":[{"title":"Hacker steals $282 million crypto from a victim in social-engineering attack","url":"https://www.coindesk.com/business/2026/01/16/hacker-steals-usd282-milion-in-hardware-wallet-social-engineering-attack","publisher":"CoinDesk"},{"title":"Crypto User Loses $282 Million in Bitcoin and Litecoin to Social Engineering Scam","url":"https://bravenewcoin.com/insights/crypto-user-loses-282-million-in-bitcoin-and-litecoin-to-social-engineering-scam","publisher":"Brave New Coin"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"},{"title":"Betterment named among victims of the January 2026 real-time vishing wave","date":"2026-01-09","date_precision":"day","victim_org":"Betterment","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"No synthetic voice was reported for this campaign; the calls were described as live operators.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.","how_it_worked":"The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.","lessons":"Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav"},{"title":"SoundCloud hit as real-time vishing kits drive browsers through SSO logins","date":"2026-01","date_precision":"month","victim_org":"SoundCloud","sector":"Media & Entertainment","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":36000000,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.","how_it_worked":"The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.","lessons":"Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"},{"title":"Okta SSO accounts targeted in vishing campaign against financial firms","date":"2026-01","date_precision":"month","victim_org":"Multiple fintech, wealth management and advisory firms (unnamed)","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_note":"Ransom demands were made by email; no aggregate figure was published for this wave.","records_affected":null,"threat_actor":"ShinyHunters (signed some extortion demands)","summary":"BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.","how_it_worked":"Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.","lessons":"Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.","confidence":"Confirmed","sources":[{"title":"Okta SSO accounts targeted in vishing-based data theft attacks","url":"https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"},{"slug":"2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec","title":"Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Crunchbase","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":2000000,"threat_actor":"ShinyHunters","summary":"Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.","how_it_worked":"The attackers called Crunchbase staff and posed as internal IT support, using a pretext about an account or access issue that required the employee to sign in while the caller stayed on the line. The employee entered Okta single sign-on credentials and read back the one-time code, which the caller replayed against the live Okta login within its validity window, producing an authenticated session under a legitimate staff identity. The trust signals abused were the routine familiarity of an IT support call and the employee's own genuine Okta prompt; the pressure was urgency framed as fixing a problem already affecting the employee's access.","lessons":"Phishing-resistant, origin-bound authenticators remove the readable one-time code these calls depend on, and a standing rule that IT never requests codes by phone gives staff a clean refusal script.","confidence":"Reported","sources":[{"title":"Crunchbase Confirms Data Breach After Hacking Claims","url":"https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/","publisher":"SecurityWeek"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"},{"title":"ShinyHunters claims 2 Million Crunchbase records; company confirms breach","url":"https://securityaffairs.com/187340/data-breach/shinyhunters-claims-2-million-crunchbase-records-company-confirms-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing","title":"ShinyHunters claim 14M Panera Bread records after Entra SSO vishing","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Panera Bread","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.","how_it_worked":"The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.","lessons":"Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.","confidence":"Alleged","sources":[{"title":"ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach","url":"https://www.techrepublic.com/article/news-panera-bread-data-breach/","publisher":"TechRepublic"},{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing"},{"slug":"2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack","title":"Harvard alumni and donor data stolen in phone-based phishing attack","date":"2025-11-18","date_precision":"day","year":2025,"victim_org":"Harvard University","sector":"Education","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.","how_it_worked":"The attacker telephoned someone with access to the advancement systems and, over the call, obtained what was needed to log in as that person. Harvard characterised the incident explicitly as a phone-based phishing attack on its Alumni Affairs and Development environment. Advancement offices are attractive because a small number of staff hold broad read access to donor records, and because fundraising work involves frequent legitimate calls from unfamiliar people, which normalises an unexpected voice asking for help. Once authenticated as the employee, the intruder queried and exported donor and alumni records before the university revoked the access and brought in outside responders.","lessons":"Phishing-resistant MFA on advancement systems and a standing rule that credentials or one-time codes are never handled over the phone would have blocked the login.","confidence":"Confirmed","sources":[{"title":"Harvard University discloses data breach affecting alumni, donors","url":"https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/","publisher":"BleepingComputer"},{"title":"Harvard University reports data breach following voice phishing incident","url":"https://www.paubox.com/blog/harvard-university-reports-data-breach-following-voice-phishing-incident","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack"},{"slug":"2025-princeton-advancement-database-breached-in-targeted-phishing-attack","title":"Princeton advancement database breached in targeted phishing attack","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Princeton University","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.","how_it_worked":"The intrusion started with a targeted phishing approach aimed at a single staff member with advancement-system access rather than a mass campaign. The message and follow-up were crafted around university fundraising work, an area where staff routinely receive unfamiliar outreach about events, gifts and alumni records, which made the approach unremarkable. The trust signal abused was the appearance of legitimate internal or alumni-related correspondence; the pressure was ordinary work urgency rather than threats. Once the employee's session or credentials were captured, the attacker authenticated as them and queried the advancement database directly, exporting constituent records before the university detected the activity and cut off access.","lessons":"Hardware-backed or passkey MFA for advancement staff, plus alerting on unusual bulk queries against constituent databases, would have contained the single compromised account.","confidence":"Confirmed","sources":[{"title":"Princeton Database Breached in Targeted Phishing Incident","url":"https://paw.princeton.edu/article/princeton-database-breached-targeted-phishing-incident","publisher":"Princeton Alumni Weekly"},{"title":"Cybersecurity incident information and FAQ","url":"https://oit.princeton.edu/cybersecurity-incident-information-and-faq","publisher":"Princeton University OIT"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-princeton-advancement-database-breached-in-targeted-phishing-attack"},{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},{"slug":"2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform","title":"Stellantis confirms customer data stolen from Salesforce platform","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Stellantis","sector":"Manufacturing","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered Lapsus$ Hunters (claimed)","summary":"Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.","how_it_worked":"The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.","lessons":"Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.","confidence":"Reported","sources":[{"title":"Automaker giant Stellantis confirms data breach after Salesforce hack","url":"https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/","publisher":"BleepingComputer"},{"title":"Stellantis confirms data breach involving customers' contact information","url":"https://www.engadget.com/big-tech/stellantis-confirms-data-breach-involving-customers-contact-information-194136744.html","publisher":"Engadget"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform"},{"slug":"2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the","title":"Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Kering (Gucci, Balenciaga, Alexander McQueen)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.","how_it_worked":"ShinyHunters told reporters the access came from the same telephone-based playbook it ran against dozens of consumer brands in 2025: a caller posing as internal IT or a SaaS vendor contacted staff with CRM access, cited a plausible support ticket, and guided them through granting a connected application permission in the customer-relationship platform. The identity impersonated was the victim's own IT function; the trust signal abused was a vendor-branded consent page that looked routine. No malware was deployed. Once approved by a human, the app was used to enumerate and export customer profiles, which were then used for private extortion demands.","lessons":"Retail and luxury CRM tenants should treat third-party app consent as a privileged administrative action requiring a second approver and out-of-band caller verification.","confidence":"Reported","sources":[{"title":"Company that owns Gucci, Balenciaga, other brands confirms hack","url":"https://techcrunch.com/2025/09/15/company-that-owns-gucci-balenciaga-other-brands-confirms-hack","publisher":"TechCrunch"},{"title":"Gucci, Balenciaga, McQueen confirm breach, ShinyHunters claim 7.4M customers' data stolen","url":"https://cybernews.com/news/gucci-balenciaga-kering-data-breach-7-million-customers-compromised-shiny-hunters/","publisher":"Cybernews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the"},{"title":"Workday discloses CRM breach after social engineering of employees","date":"2025-08-06","date_precision":"day","victim_org":"Workday","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Smishing (SMS)","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign","summary":"Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.","how_it_worked":"Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.","lessons":"Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.","confidence":"Confirmed","sources":[{"title":"Workday hit by social engineering data breach targeting its CRM platform","url":"https://therecord.media/workday-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Human resources firm Workday disclosed a data breach","url":"https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-workday-discloses-crm-breach-after-social-engineering-of-employees","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"},{"slug":"2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf","title":"Air France and KLM disclose breach of third-party customer service platform","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Air France-KLM","sector":"Transportation & Logistics","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.","how_it_worked":"Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.","lessons":"Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.","confidence":"Reported","sources":[{"title":"Air France and KLM disclose data breaches impacting customers","url":"https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/","publisher":"BleepingComputer"},{"title":"Air France, KLM Say Hackers Accessed Customer Data","url":"https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"},{"slug":"2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach","title":"Chanel notifies US clients after third-party client-care database breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Chanel","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.","how_it_worked":"Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.","lessons":"Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.","confidence":"Reported","sources":[{"title":"Chanel Alerts Client of Third-Party Breach","url":"https://www.darkreading.com/cyberattacks-data-breaches/chanel-alerts-third-party-breach","publisher":"Dark Reading"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach"},{"slug":"2025-pandora-warns-customers-after-third-party-platform-breach","title":"Pandora warns customers after third-party platform breach","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Pandora A/S","sector":"Retail","country":"Denmark","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters (reported)","summary":"Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.","how_it_worked":"Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.","lessons":"Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.","confidence":"Reported","sources":[{"title":"Pandora and Chanel Customer Data Leaked in Third-Party Breaches","url":"https://www.pymnts.com/cybersecurity/2025/pandora-and-chanel-customer-data-leaked-in-breach/","publisher":"PYMNTS"},{"title":"Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora","url":"https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-pandora-warns-customers-after-third-party-platform-breach"},{"slug":"2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing","title":"Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Cryptocurrency holders and companies targeted by the group","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft","Identity Theft"],"loss_usd":13000000,"loss_kind":"direct_loss","loss_note":"About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.","records_affected":null,"threat_actor":"Scattered Spider","summary":"A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.","how_it_worked":"The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.","lessons":"Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.","confidence":"Confirmed","sources":[{"title":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years","url":"https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/","publisher":"Krebs on Security"},{"title":"Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution","url":"https://therecord.media/scattered-spider-affiliate-sentenced-10-years","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"},{"slug":"2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ","title":"TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs","date":"2025-07-28","date_precision":"day","year":2025,"victim_org":"TransUnion","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Identity Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4400000,"threat_actor":"ShinyHunters","summary":"Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.","how_it_worked":"TransUnion has described the entry point only as a third-party application serving its consumer support operations and has not publicly confirmed a social engineering pretext. Reporting places the theft in the Salesforce campaign attributed to UNC6040 and ShinyHunters, in which callers impersonating internal IT support telephone employees, cite a routine integration or troubleshooting need, and talk the target through authorising an attacker-controlled connected application inside the genuine Salesforce authorisation screen. The abused trust signal is Salesforce's own real interface combined with a plausible internal support identity; the extraction that follows is automated and needs no further human involvement.","lessons":"Restricting connected-app authorisation to a small set of administrators and alerting on any newly bound application or unusual bulk export from the CRM would have contained this class of intrusion at the moment of consent.","confidence":"Reported","sources":[{"title":"TransUnion suffers data breach impacting over 4.4 million people","url":"https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/","publisher":"BleepingComputer"},{"title":"TransUnion becomes latest victim in major wave of Salesforce-linked cyberattacks, 4.4M Americans affected","url":"https://www.foxnews.com/tech/transunion-becomes-latest-victim-major-wave-salesforce-linked-cyberattacks-4-4m-americans-affected","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ"},{"slug":"2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm","title":"Cisco confirms vishing call gave attacker access to its third-party CRM instance","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (Salesforce vishing wave)","summary":"Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.","how_it_worked":"The attacker telephoned a Cisco representative and, using an internal-sounding pretext, persuaded them to authorise access to the company's instance of a third-party cloud CRM platform. This is the pattern Google's threat intelligence team documented as UNC6040: callers impersonate IT support and talk the target through granting a connected application or completing a sign-in that hands the caller an authenticated CRM session. The trust signals abused were a plausible internal support identity and the ordinariness of the request, and the abuse was quick and quiet enough that the export was complete before the account activity was identified.","lessons":"Restricting who can authorise connected applications in the CRM, and requiring a call-back through a verified internal directory number before any access-granting action, closes the path a single persuaded employee opens.","confidence":"Confirmed","sources":[{"title":"Vishing Attack Impacting Third-Party CRM System","url":"https://sec.cloudapps.cisco.com/security/center/resources/CRM-vishing","publisher":"Cisco (company advisory)"},{"title":"Cisco discloses data breach impacting Cisco.com user accounts","url":"https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"title":"Qantas contact centre platform breached after help desk tricked into adding MFA","date":"2025-07-01","date_precision":"day","victim_org":"Qantas Airways","sector":"Transportation & Logistics","country":"Australia","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.","records_affected":5700000,"threat_actor":"Scattered Spider / Muddled Libra (reported)","summary":"Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.","how_it_worked":"The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.","lessons":"Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.","confidence":"Confirmed","sources":[{"title":"Qantas data breach impacted 5.7 million individuals","url":"https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html","publisher":"Security Affairs"},{"title":"Qantas confirms customer data breach amid Scattered Spider attacks","url":"https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html","publisher":"Security Affairs"},{"title":"Update on Qantas cyber incident: Wednesday 9 July 2025","url":"https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025","publisher":"Qantas Newsroom"},{"title":"Tech support scam caused massive data breach at Australian airline Qantas","url":"https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267","publisher":"The Register"}],"entry_type":"incident","slug":"2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"},{"slug":"2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft","title":"LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave","date":"2025-07","date_precision":"month","year":2025,"victim_org":"LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040","summary":"Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.","how_it_worked":"The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.","lessons":"Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.","confidence":"Reported","sources":[{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"},{"title":"Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches","url":"https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"},{"slug":"2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d","title":"Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware","date":"2025-07","date_precision":"month","year":2025,"victim_org":"US retail, airline, transportation and insurance organisations","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC3944 / Scattered Spider","summary":"Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.","how_it_worked":"Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.","lessons":"Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.","confidence":"Confirmed","sources":[{"title":"Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure","url":"https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html","publisher":"The Hacker News"},{"title":"Scattered Spider targets VMware ESXi using social engineering","url":"https://securityaffairs.com/180466/cyber-crime/scattered-spider-targets-vmware-esxi-in-using-social-engineering/","publisher":"Security Affairs"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d"},{"slug":"2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password","title":"WestJet breach of 1.2 million passengers began with a help desk password reset","date":"2025-06-13","date_precision":"day","year":2025,"victim_org":"WestJet","sector":"Transportation & Logistics","country":"Canada","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1200000,"threat_actor":null,"summary":"Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.","how_it_worked":"The attackers used social engineering to have an employee's password reset, then signed in to the corporate network through Citrix. The pretext was that of a legitimate employee locked out of their account, and the identity impersonated was a staff member whose details had been researched beforehand. The trust signal abused was the help desk's willingness to restore access on the strength of knowledge-based answers, and the pressure applied was a worker unable to do their job. From that foothold the intruders moved into the Windows domain and Microsoft cloud tenant and exfiltrated passenger records over several days before detection.","lessons":"Identity-proofing at the service desk, using video verification or a manager-approved out-of-band challenge before any password or MFA reset, is the single control that would have stopped this.","confidence":"Confirmed","sources":[{"title":"WestJet data breach exposes travel details of 1.2 million customers","url":"https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/","publisher":"BleepingComputer"},{"title":"Data breach at Canadian airline WestJet affects 1.2M passengers","url":"https://techcrunch.com/2025/10/01/data-breach-at-canadian-airline-westjet-affects-1-2m-passengers/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password"},{"title":"Aflac breached in insurance-sector social engineering campaign; 22.6M affected","date":"2025-06-12","date_precision":"day","victim_org":"Aflac","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No public reporting attributes AI-generated voice to the Aflac intrusion.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed; Aflac offered 24 months of credit monitoring, identity theft and medical fraud protection.","records_affected":22650000,"threat_actor":"Not confirmed by Aflac; reporting points to Scattered Spider's 2025 insurance-sector campaign","summary":"Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.","how_it_worked":"Aflac has not published the intrusion mechanics beyond describing a sophisticated cybercrime group and an industry-wide campaign, so the vector here is characterised from the campaign rather than from Aflac's own disclosure. Google Threat Intelligence, warning insurers during the same weeks, told the sector to pay particular attention to social engineering attempts against help desks and call centres, the route the same crews had used against retail and hospitality: a phone call impersonating staff to obtain credential or MFA resets, then rapid data collection with no malware deployed.","lessons":"Identity verification standards for help desks and call centres, applied to both employee and customer channels, is the control the sector was explicitly warned to strengthen.","confidence":"Confirmed","sources":[{"title":"Aflac discloses breach amidst Scattered Spider insurance attacks","url":"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/","publisher":"BleepingComputer"},{"title":"22M Affected by Aflac Data Breach","url":"https://www.securityweek.com/22-million-affected-by-aflac-data-breach/","publisher":"SecurityWeek"},{"title":"Aflac confirms June data breach affecting over 22 million customers","url":"https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html","publisher":"Security Affairs"},{"title":"Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised","url":"https://www.hipaajournal.com/aflac-data-breach/","publisher":"The HIPAA Journal"},{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff"}]}