{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:34.758Z","total":16,"returned":16,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers","date":"2025-06","date_precision":"month","victim_org":"US State Department; three foreign ministers, a US governor and a member of Congress","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"A State Department cable described an impostor using AI-generated voice and text to mimic Secretary of State Marco Rubio, leaving Signal voicemails for at least two targets.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.","how_it_worked":"The impostor exploited the fact that senior diplomats routinely use Signal for informal contact, so a message from an account labelled with the Secretary's official email address fit the expected pattern. Rather than opening with a request, the actor left short voicemails in a cloned voice and sent texts inviting the target to continue the conversation on Signal, which builds familiarity before anything is asked. The trust signal was the combination of a recognisable voice and a display name resembling a state.gov address, neither of which is authenticated by the platform. Targets who engaged would then have been positioned for requests for information or for account access.","lessons":"Display names and voices are not identity: diplomatic contact should be initiated or confirmed through embassy and ministry channels, and platforms used for official business need verified organisational identity.","confidence":"Confirmed","sources":[{"title":"Imposter used AI to pose as Marco Rubio and contact foreign ministers","url":"https://feeds.bbci.co.uk/news/articles/crrqkyyjewno","publisher":"BBC News"},{"title":"A Marco Rubio impostor is using AI voice to call high-level officials","url":"https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/","publisher":"The Washington Post"}],"entry_type":"incident","slug":"2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore"},{"title":"FBI warns of AI voice-cloning campaign impersonating senior US officials","date":"2025-05-15","date_precision":"day","victim_org":"Current and former senior US federal and state officials and their contacts","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The FBI stated that malicious actors were sending AI-generated voice messages, alongside text messages, that purported to come from senior US officials.","outcomes":["Credential Theft","Identity Theft","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.","how_it_worked":"The campaign traded on the recipient's relationship with a named senior official rather than on any technical exploit. An initial text or voicemail in a cloned voice established that the official was reaching out personally, which for a colleague or former colleague is unremarkable. Once a reply came, targets were invited to continue on a separate messaging platform, a request that reads as security-conscious in government circles, and the link supplied there led to a credential-harvesting page or a device-linking flow. Each successful compromise fed the next round, since messages arriving from a genuinely compromised official account carry far more weight than any spoof.","lessons":"Officials and their contacts should verify unexpected outreach through a separately known number or channel, and adopt phishing-resistant authentication on personal accounts, which are typically the weak point rather than official systems.","confidence":"Confirmed","sources":[{"title":"Senior US Officials Impersonated in Malicious Messaging Campaign (PSA250515)","url":"https://www.ic3.gov/PSA/2025/PSA250515","publisher":"FBI Internet Crime Complaint Center"},{"title":"FBI warns senior US officials are being impersonated using texts, AI-based voice cloning","url":"https://www.cybersecuritydive.com/news/fbi-us-officials-impersonated-text-ai-voice/748334/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","slug":"2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials"},{"title":"AI voice impersonation of White House chief of staff Susie Wiles targets Republicans","date":"2025-05","date_precision":"month","victim_org":"The White House; senators, governors and business executives contacted","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Officials cited by news reports believed the impersonator used AI to replicate Susie Wiles's voice on phone calls; the contact list appears to have come from her compromised personal phone.","outcomes":["Identity Theft","Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.","how_it_worked":"The attack started from a compromised personal phone, which supplied both the target list and the context needed to make each approach specific. Messages and calls appeared to come from someone recipients genuinely deal with, and the requests, a pardon shortlist or a favour involving money, are the kind of sensitive, informal business that plausibly happens by phone rather than through official channels precisely because it is delicate. The cloned voice removed the last check most recipients would apply. Suspicion emerged from content rather than technology: some recipients noticed the requests did not match how Wiles operates, and the messages came from an unfamiliar number.","lessons":"Senior staff should keep official business off personal devices and pre-agree verification practices with frequent contacts, so that an unexpected request from a new number is confirmed before anyone acts.","confidence":"Reported","sources":[{"title":"White House responds to attempts to impersonate Trump advisor Susie Wiles","url":"https://www.newsweek.com/white-house-susie-wiles-trump-impersonate-fbi-2078802","publisher":"Newsweek"},{"title":"Trump officials keep getting targeted by 'vishing'","url":"https://time.com/7301176/impersonation-ai-voice-vishing-scam-rubio-wiles-trump-fbi-advice/","publisher":"TIME"}],"entry_type":"incident","slug":"2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets"},{"title":"AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman","date":"2025-02","date_precision":"month","victim_org":"Massimo Moratti and other Italian business leaders","sector":"Consumer","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Fraudsters used an AI-generated clone of Defence Minister Guido Crosetto's voice on phone calls, alongside accomplices posing as ministry staff.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":1000000,"loss_note":"Approx EUR 1 million paid by Massimo Moratti in two transfers; funds were traced to a Dutch bank account and frozen","records_affected":null,"threat_actor":null,"summary":"In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.","how_it_worked":"The pretext was engineered for the target audience: a matter of national interest, secret by nature, in which wealthy patriots were being asked to advance funds the state would repay. Calls came first from someone presenting as a ministry official, which set the frame, and then from the minister himself in a recognisable synthetic voice, an escalation that made the request feel personally sanctioned at the highest level. The promise of Bank of Italy reimbursement reduced the perceived risk to a short-term loan. Secrecy and the lives of hostages supplied both urgency and a reason not to consult advisers, and payment was directed to a foreign account presented as an operational necessity.","lessons":"Government officials do not solicit private funds by phone; any such request should be verified with the ministry's published switchboard before any transfer, and banks should challenge large first-time international transfers from personal accounts.","confidence":"Reported","sources":[{"title":"Police recover EUR 1M sent to deepfake scammers impersonating Italy's Defense Minister","url":"https://cybernews.com/cybercrime/deepfake-scammers-dupe-italian-buinessman-1-million-police-recover-funds/","publisher":"Cybernews"},{"title":"Fraudsters Allegedly Use AI-Generated Voice of Italian Defense Minister Guido Crosetto to Scam Business Leaders","url":"https://incidentdatabase.ai/cite/927/","publisher":"AI Incident Database"},{"title":"Guido Crosetto","url":"https://en.wikipedia.org/wiki/Guido_Crosetto","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a"},{"title":"FBI warns criminals are using generative AI to scale voice-clone and identity fraud","date":"2024-12-03","date_precision":"day","victim_org":"US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Deepfake Video Call","Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The entire advisory concerns criminal use of generative AI: AI text for phishing and fake profiles, AI images for fake IDs and personas, voice cloning to impersonate relatives and account holders, and real-time video synthesis to impersonate executives and authorities.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Extortion","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"The advisory does not publish an aggregate loss figure for AI-enabled fraud.","records_affected":null,"threat_actor":null,"summary":"On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.","how_it_worked":"Voice cloning is the pivotal technique for consumer harm. A short sample of a person's speech, readily available from social media video, is enough to synthesise a distressed relative calling to say they have been in an accident or arrested and need money immediately. The lever is the recognisable voice of a loved one under duress, which suppresses verification instincts far more effectively than any script. The same technology is used to satisfy bank voice authentication as an account holder, and real-time video synthesis extends it to live calls impersonating executives or providing proof of legitimacy to a romance or investment target. AI translation also strips the grammatical errors that once exposed foreign operators.","lessons":"The FBI's own recommendation is the practical control: agree a family or organisational verification code word in advance, and independently call back on a known number before acting on any urgent request.","confidence":"Confirmed","sources":[{"title":"Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud","url":"https://www.ic3.gov/PSA/2024/PSA241203","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide"},{"title":"Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport","date":"2024-10","date_precision":"month","victim_org":"Wiz","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers built a voice clone of chief executive Assaf Rappaport from audio of a conference talk and sent synthetic voice messages to dozens of employees seeking their credentials.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.","how_it_worked":"The attackers scaled a single cloned sample across dozens of recipients, betting that at least one employee would act on what sounded like a direct request from the chief executive. Voice messages rather than live calls removed the risk of interactive questions and let the same recording be reused, while the boss's authority supplied the pressure to comply quickly with a credential request. The flaw was in the source material: the only clean public audio was a conference keynote, so the clone inherited a projected, presentational tone that colleagues who hear Rappaport daily immediately found off. Employees compared notes and reported the messages rather than responding.","lessons":"Credential requests should never be actionable from a voice message, and mass-distribution patterns across many employees should trigger automated correlation and alerting.","confidence":"Confirmed","sources":[{"title":"Wiz CEO says company was targeted with deepfake attack that used his voice","url":"https://techcrunch.com/2024/10/28/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice/","publisher":"TechCrunch"},{"title":"Hackers Sent a Deepfake of Wiz CEO to Dozens of Employees","url":"https://www.entrepreneur.com/business-news/hackers-sent-a-deepfake-of-wiz-ceo-to-dozens-of-employees/482027","publisher":"Entrepreneur"}],"entry_type":"incident","slug":"2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa"},{"title":"Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question","date":"2024-07","date_precision":"month","victim_org":"Ferrari","sector":"Manufacturing","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The caller used a synthetic voice that reproduced chief executive Benedetto Vigna's southern Italian accent; the target noticed slightly mechanical intonation.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.","how_it_worked":"The approach started on WhatsApp from an unfamiliar number, with the mismatch explained away by the claim that the deal was so sensitive it required a separate line, a pretext that turns a red flag into evidence of importance. The escalation to a voice call added the strongest trust signal available, the chief executive's distinctive accent and manner discussing an unannounced acquisition. Confidentiality supplied the reason not to consult anyone, and a currency hedge gave a technical, plausible-sounding financial action. The executive interrupted the frame by asking a shared-knowledge question with no public answer, which the synthetic caller could not handle.","lessons":"A pre-agreed challenge based on shared private knowledge, or a codeword for executive payment requests, reliably breaks a voice clone that cannot improvise.","confidence":"Reported","sources":[{"title":"Ferrari narrowly dodges deepfake scam simulating deal-hungry CEO","url":"https://www.spokesman.com/stories/2024/jul/26/ferrari-narrowly-dodges-deepfake-scam-simulating-d/","publisher":"Bloomberg via The Spokesman-Review"},{"title":"Ferrari CEO Deepfake Shows Growing Threat of AI Scams Impersonating Executives","url":"https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo","publisher":"Bloomberg"}],"entry_type":"incident","slug":"2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu"},{"title":"WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read","date":"2024-05","date_precision":"month","victim_org":"WPP","sector":"Media & Entertainment","country":"United Kingdom","primary_vector":"Deepfake Video Call","secondary_vectors":["Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers set up a WhatsApp account using a publicly available image of chief executive Mark Read, then ran a Microsoft Teams meeting using YouTube footage of him alongside an AI voice clone.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.","how_it_worked":"The pretext was a new business opportunity that a chief executive might plausibly want to explore quietly with one trusted agency leader, which explained both the confidentiality and the unusual approach. The attackers assembled several weak trust signals into a convincing whole: a WhatsApp profile with Read's real photo, a Teams invite from an apparently senior source, video that showed his face and a synthetic voice on the line, and chat messages written in his persona. The technical staging papered over the gaps, with camera and audio problems used to explain why the video looked like recorded footage. The target was asked to move on money and personal information without touching normal corporate process.","lessons":"Verifying meeting invitations through the corporate directory rather than a messaging-app contact, and refusing to progress financial arrangements outside standard process, are what stopped this.","confidence":"Confirmed","sources":[{"title":"CEO of world's biggest ad firm targeted by deepfake scam","url":"https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam","publisher":"The Guardian"},{"title":"Scammers Reportedly Used AI Voice Clone and YouTube Footage to Impersonate WPP CEO","url":"https://incidentdatabase.ai/cite/983/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark"},{"title":"LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO","date":"2024-04","date_precision":"month","victim_org":"LastPass","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.","how_it_worked":"The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.","lessons":"A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.","confidence":"Confirmed","sources":[{"title":"Attempted Audio Deepfake Call Targets LastPass Employee","url":"https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee","publisher":"LastPass"},{"title":"LastPass: Hackers targeted employee in failed deepfake CEO call","url":"https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/","publisher":"BleepingComputer"},{"title":"LastPass employee targeted via an audio deepfake call","url":"https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"},{"title":"Arup Hong Kong office loses about $25 million in deepfake video call scam","date":"2024-02","date_precision":"month","victim_org":"Arup Group (Hong Kong office)","sector":"Professional Services","country":"Hong Kong","primary_vector":"Deepfake Video Call","secondary_vectors":["Business Email Compromise","Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":25000000,"loss_note":"HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.","records_affected":null,"threat_actor":null,"summary":"In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.","how_it_worked":"The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.","lessons":"High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.","confidence":"Confirmed","sources":[{"title":"Deepfaked video conference call makes employee send $25 million to scammers","url":"https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/","publisher":"Help Net Security"},{"title":"Arup Group (fraud incident section)","url":"https://en.wikipedia.org/wiki/Arup_Group","publisher":"Wikipedia"},{"title":"Business Email Compromise: Virtual Meeting Platforms","url":"https://www.ic3.gov/PSA/2022/PSA220216","publisher":"FBI IC3"},{"title":"Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee","url":"https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk","publisher":"CNN"},{"title":"'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage","publisher":"South China Morning Post"}],"entry_type":"incident","slug":"2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"},{"title":"AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads","date":"2024-01","date_precision":"month","victim_org":"Multiple US consumers; brands Taylor Swift and Le Creuset impersonated","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Voice Clone / Audio Deepfake","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The ads paired authentic images of the singer with a synthesised clone of her voice; a Carnegie Mellon researcher confirmed the audio was fabricated while the photographs were genuine.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Individual victims reported paying small shipping fees and supplying card details; aggregate loss not published","records_affected":null,"threat_actor":null,"summary":"In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.","how_it_worked":"The scam borrowed two trusted identities at once, a celebrity with an unusually devoted fanbase and a premium cookware brand that plausibly runs promotions. Distribution came through paid social ads, so the content arrived inside a feed the target already trusted rather than in an unsolicited message. The cloned voice narrating a personal-sounding offer supplied the authenticity that still images alone would not, and the giveaway framing made urgency natural: a limited number of free sets meant acting immediately. The small shipping fee was the conversion step, low enough to feel harmless while capturing card data and personal details.","lessons":"Consumers should verify giveaways on the brand's own site, and ad platforms need celebrity-likeness and synthetic-voice detection in advertiser review rather than post-hoc takedown.","confidence":"Reported","sources":[{"title":"The Taylor Swift Le Creuset cookware giveaway is fake","url":"https://www.today.com/food/news/taylor-swift-le-creuset-cookware-giveaway-fake-rcna133325","publisher":"TODAY / NBC News"},{"title":"AI-generated ads using Taylor Swift's likeness dupe fans with fake Le Creuset giveaway","url":"https://cbsnews.com/news/taylor-swift-le-creuset-ai-generated-ads","publisher":"CBS News"}],"entry_type":"campaign","slug":"2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads"},{"title":"AI-cloned Biden robocall told New Hampshire voters to skip the primary","date":"2024-01","date_precision":"month","victim_org":"New Hampshire primary voters","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Political consultant Steve Kramer admitted commissioning an AI-cloned voice of President Biden for the robocall; the FCC's enforcement action describes the recording as AI-generated.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"FCC proposed a US$6 million forfeiture against Kramer; carrier Lingo Telecom settled for US$1 million","records_affected":null,"threat_actor":"Steven Kramer (political consultant)","summary":"On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.","how_it_worked":"The channel was an ordinary automated phone call with spoofed caller ID, arriving in the last hours before an election when voters have little time to check anything. The trust signal was the president's recognisable voice delivering a message in his own idiom, addressed to Democratic voters as if from the campaign itself. The persuasion was framed not as suppression but as helpful strategy, telling recipients their vote mattered more in November, which gave the instruction an internally consistent rationale. Because the medium is one-way and the timing left no room for correction, targets had no natural opportunity to verify before the primary took place.","lessons":"Carriers enforcing STIR/SHAKEN caller-ID attestation on upstream customers, plus rapid election-authority rebuttal channels, are the practical controls; voters should treat any voting instruction by phone as unverified.","confidence":"Confirmed","sources":[{"title":"FCC Proposes $6 Million Fine For Illegal Robocalls That Used Deepfake AI Voice","url":"https://docs.fcc.gov/public/attachments/DOC-402762A1.pdf","publisher":"US Federal Communications Commission"},{"title":"Criminal charges and FCC fines issued for deepfake Biden robocalls","url":"https://www.npr.org/2024/05/23/nx-s1-4977582/fcc-ai-deepfake-robocall-biden-new-hampshire-political-operative","publisher":"NPR"}],"entry_type":"incident","slug":"2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary"},{"title":"Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee","date":"2023-08-27","date_precision":"day","victim_org":"Retool","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Voice Clone / Audio Deepfake","Vishing (Voice Phishing)","Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Retool stated the caller used a deepfaked voice imitating a specific member of its IT team, whom the target employee knew. This is one of the earliest well-documented uses of voice cloning in a corporate intrusion.","outcomes":["Data Breach","Cryptocurrency Theft","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Retool reported no loss of its own; downstream, cryptocurrency customer Fortress Trust separately reported a theft of roughly $15 million tied to the compromise, a figure attributed to Fortress Trust rather than confirmed by Retool.","records_affected":27,"threat_actor":null,"summary":"Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.","how_it_worked":"The employee received a text claiming to be from Retool IT about a payroll and healthcare enrolment issue, with a link to a page cloning the company's internal identity portal. After the employee submitted credentials and an MFA code, the attacker phoned them; the voice was a deepfake of a specific IT team member the employee recognised, and the caller was familiar with office layout, colleagues and internal processes. During the call the employee provided an additional MFA code, which let the attacker add their own device to the employee's Okta account. From there they reached the employee's Google account, where Authenticator's cloud sync had backed up OTP seeds, and used those to pivot into internal admin systems and alter customer accounts.","lessons":"Voice is no longer an identity proof; hardware security keys plus a policy that MFA codes are never read aloud, and disabling authenticator cloud sync on enterprise accounts, close both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Retool blames breach on Google Authenticator MFA cloud sync feature","url":"https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/","publisher":"BleepingComputer"},{"title":"Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients","url":"https://thehackernews.com/2023/09/retool-falls-victim-to-sms-based.html","publisher":"The Hacker News"},{"title":"Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks","url":"https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/","publisher":"SecurityWeek"},{"title":"When MFA isn't actually MFA","url":"https://retool.com/blog/mfa-isnt-mfa","publisher":"Retool"}],"entry_type":"incident","slug":"2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp"},{"title":"AI voice clone of teenage daughter used in Arizona virtual kidnapping attempt","date":"2023-04","date_precision":"month","victim_org":"Jennifer DeStefano, a private individual in Scottsdale, Arizona","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"The mother testified that the caller played back what sounded exactly like her 15-year-old daughter's voice, sobs and inflection included; investigators and researchers attributed this to AI voice cloning, though the sample source was never identified.","outcomes":["Attempt Blocked","Extortion"],"loss_usd":null,"loss_note":"No money was transferred","records_affected":null,"threat_actor":null,"summary":"Jennifer DeStefano of Scottsdale, Arizona received a call in which she heard what she believed was her 15-year-old daughter crying, followed by a man claiming to hold the girl and demanding a US$1 million ransom, later reduced to US$50,000 in cash. While she kept the caller talking, other parents reached her husband, who confirmed the daughter was safe at home. No money changed hands. DeStefano described the incident in written testimony to the US Senate Judiciary Committee in June 2023, and it became one of the most cited AI voice-cloning cases in US policy debate.","how_it_worked":"The pretext was the most emotionally overwhelming one available, a child in immediate physical danger, delivered by phone at a moment when the mother was away from her daughter and could not instantly verify. The cloned crying voice was the trust signal; it matched not just the timbre but the way the girl cries. The caller then applied escalating threats and refused to let her hang up or make another call, closing off exactly the verification path that would have ended the scam. Pressure was tuned by dropping the demand from US$1 million to US$50,000 cash, making compliance feel achievable, and by insisting on an in-person handover rather than a traceable wire.","lessons":"Families need a pre-agreed verbal code word and a habit of hanging up and calling the relative back on a known number before acting on any ransom or emergency call.","confidence":"Reported","sources":[{"title":"Written Statement of Jennifer DeStefano, US Senate Committee on the Judiciary","url":"https://www.judiciary.senate.gov/imo/media/doc/2023-06-13%20PM%20-%20Testimony%20-%20DeStefano.pdf","publisher":"US Senate Committee on the Judiciary"},{"title":"AI kidnapping scam targets Arizona mother","url":"https://www.fox10phoenix.com/news/ai-kidnapping-scam-targets-arizona-mother-youll-never-see-your-daughter-again","publisher":"FOX 10 Phoenix"}],"entry_type":"incident","slug":"2023-ai-voice-clone-of-teenage-daughter-used-in-arizona-virtual-kidnapping-at","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ai-voice-clone-of-teenage-daughter-used-in-arizona-virtual-kidnapping-at"},{"title":"Cloned company director's voice used in US$35M bank transfer fraud","date":"2020","date_precision":"year","victim_org":"Unnamed company and its bank; investigated by UAE authorities","sector":"Financial Services","country":"United Arab Emirates","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Business Email Compromise","Vishing (Voice Phishing)"],"ai_involvement":"Suspected AI-enabled","ai_notes":"UAE investigators stated in court filings that the fraudsters used 'deep voice' technology to clone a company director's speech for the phone call. The specific tooling was not established publicly.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":35000000,"loss_note":"Up to US$35 million per UAE court documents; US$400,000 traced to two US accounts at Centennial Bank","records_affected":null,"threat_actor":null,"summary":"In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.","how_it_worked":"The pretext was a confidential corporate acquisition that required the branch to release large sums quickly. The channel was a phone call from a person whose voice the manager had heard before, reinforced by a parallel email thread from the same director and from an outside lawyer retained to coordinate the deal, which is a familiar and legitimising pattern in M&A work. Secrecy was built into the story, so the manager had a reason not to ask colleagues. The layered corroboration between a recognised voice and matching documentation removed his doubt, and the transfers were executed before anyone verified through an independent channel.","lessons":"Any acquisition-related payment instruction should require verification through a pre-established channel with a named counterparty, not the contact details supplied inside the request itself.","confidence":"Reported","sources":[{"title":"Fraudsters Cloned Company Director's Voice In $35 Million Bank Heist, Police Find","url":"https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/","publisher":"Forbes"},{"title":"Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme","url":"https://incidentdatabase.ai/cite/147/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud","year":2020,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud"},{"title":"UK energy firm CEO tricked by AI voice clone of German parent-company boss","date":"2019-03","date_precision":"month","victim_org":"Unnamed UK-based energy company (subsidiary of a German parent)","sector":"Energy & Utilities","country":"United Kingdom","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Business Email Compromise"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Fraud investigators at insurer Euler Hermes attributed the call to commercial voice-synthesis software that reproduced the German executive's accent and speech melody. The AI attribution rests on the insurer's assessment, not on forensic recovery of the tool.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":243000,"loss_note":"EUR 220,000, approx US$243,000","records_affected":null,"threat_actor":null,"summary":"In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.","how_it_worked":"The attacker phoned the UK CEO directly and presented as the group chief executive, a person the target reported to and whose voice he knew. The cloned audio carried the familiar German accent and cadence, which served as the trust signal that displaced any need for written confirmation. The pretext was an urgent payment to a Hungarian supplier that had to clear within the hour, and the caller promised the subsidiary would be reimbursed immediately. After the first transfer succeeded the fraudster called back twice more, once claiming reimbursement had been sent and once asking for a further payment. The CEO only balked when the promised refund failed to appear and a later call arrived from an Austrian number.","lessons":"Out-of-band callback to a known-good number and a dual-authorisation rule for first-time beneficiary payments would have broken the single-channel voice trust the attack depended on.","confidence":"Reported","sources":[{"title":"A Voice Deepfake Was Used To Scam A CEO Out Of $243,000","url":"https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/","publisher":"Forbes"},{"title":"Scammers deepfake CEO's voice to talk underling into $243,000 transfer","url":"https://www.sophos.com/en-us/blog/scammers-deepfake-ceos-voice-to-talk-underling-into-243000-transfer","publisher":"Sophos Naked Security"}],"entry_type":"incident","slug":"2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo","year":2019,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo"}]}