{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:58.729Z","total":12,"returned":12,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman","title":"700+ education and tech sites hijacked to serve ClickFix paste-the-command lures","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Visitors to 700+ compromised university and technology company websites","sector":"Education","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.","how_it_worked":"The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.","lessons":"Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.","confidence":"Confirmed","sources":[{"title":"700+ education and tech websites hijacked in huge ClickFix malware campaign","url":"https://www.malwarebytes.com/blog/bugs/2026/05/700-education-and-tech-websites-hijacked-in-huge-clickfix-malware-campaign","publisher":"Malwarebytes"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"},{"slug":"2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands","title":"CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Users of malicious Chrome extension impersonating uBlock Origin Lite","sector":"Technology","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.","how_it_worked":"The lure inverted the usual ClickFix pattern. Rather than a fake CAPTCHA, the attackers manufactured a real, visible fault: the installed extension broke the victim's browser, then presented a repair prompt that looked like a security notice. Because the user had genuinely just experienced a crash, the instruction to paste a command into a terminal read as a fix rather than an attack. Operators showed selectivity, deploying extra backdoors only where the compromised host was domain-joined, indicating they were filtering for enterprise environments worth returning to.","lessons":"Blocking clipboard-to-shell execution patterns and restricting extension installation to an allowlist stops the paste step, which is the only point where the user's action is required.","confidence":"Confirmed","sources":[{"title":"New ClickFix variant 'CrashFix' deploying Python Remote Access Trojan","url":"https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands"},{"title":"Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access","date":"2025-07-22","date_precision":"day","victim_org":"Multiple businesses and critical infrastructure organisations (campaign)","sector":"Healthcare","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the advisory.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the advisory notes Interlock does not state an initial ransom amount in its notes.","records_affected":null,"threat_actor":"Interlock ransomware group","summary":"A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.","how_it_worked":"Visitors to compromised but otherwise legitimate websites were served a page claiming they needed to prove they were human or fix a display problem. The page silently copied a command to the clipboard and instructed the user to open the Windows Run dialog, paste and press Enter, which executed PowerShell that fetched a remote access trojan. Because the victim types the command themselves, no download prompt or macro warning appears and email gateways are entirely bypassed. Interlock operators then used the foothold for credential theft with infostealers and keyloggers, lateral movement over RDP, data exfiltration to cloud storage, and double-extortion encryption of Windows and Linux systems.","lessons":"Instrument and alert on PowerShell or mshta launched from explorer.exe via the Run dialog, and block clipboard-to-shell execution paths through application control; no legitimate CAPTCHA ever asks a user to run a command.","confidence":"Confirmed","sources":[{"title":"#StopRansomware: Interlock (AA25-203A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a","publisher":"CISA / FBI / HHS / MS-ISAC"},{"title":"#StopRansomware: Interlock (PDF)","url":"https://www.ic3.gov/CSA/2025/250722.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Feds Issue Interlock Ransomware Warning as Healthcare Attacks Spike","url":"https://www.hipaajournal.com/interlock-ransomware-alert-2025/","publisher":"HIPAA Journal"}],"entry_type":"campaign","slug":"2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce"},{"title":"ClickFix fake-CAPTCHA social engineering floods the threat landscape","date":"2025","date_precision":"year","victim_org":"Multiple organisations and consumers (technique)","sector":"Other","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam","Spear Phishing (Email)"],"ai_involvement":"Unknown","ai_notes":"Some ClickFix lure pages and follow-on infrastructure have been reported as AI-assisted in their construction, but Proofpoint's reporting does not confirm AI involvement in the technique itself.","outcomes":["Credential Theft","Ransomware Deployment","Data Breach"],"loss_usd":null,"loss_note":"No aggregate loss figure; this entry documents a technique adopted across many criminal and state-linked actors rather than a single victim.","records_affected":null,"threat_actor":"Multiple, including cybercriminal and state-aligned groups tracked by Proofpoint","summary":"Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.","how_it_worked":"The victim reaches a page, often through malvertising, a compromised site, a search result or an emailed link, that presents a plausible obstacle: 'verify you are human', 'this document failed to load, run the fix', or a fake Chrome update error. Instructions walk the user through pressing Windows+R, pressing Ctrl+V and pressing Enter. The clipboard has already been populated by JavaScript with a PowerShell or mshta command, frequently padded with whitespace so the malicious portion is scrolled out of view in the Run box. Executing it downloads and runs the payload under the user's own privileges, sidestepping email attachment scanning, macro blocking and download reputation checks entirely because the user is the delivery mechanism.","lessons":"Disable or monitor the Run dialog through policy, alert on clipboard-sourced script execution, and train staff on the single unambiguous rule that no legitimate website ever asks you to paste a command into your operating system.","confidence":"Confirmed","sources":[{"title":"Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape","url":"https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape","publisher":"Proofpoint"},{"title":"Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware","url":"https://securityonline.info/deceptive-captcha-clickfix-campaign-uses-clipboard-injection-to-deliver-malware/","publisher":"SecurityOnline"},{"title":"Inside ClickFix: How Fake Prompts Took Over the Web","url":"https://netlas.io/blog/fake_prompts/","publisher":"Netlas"}],"entry_type":"campaign","slug":"2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape"},{"title":"Deepfake Elon Musk videos drive crypto investment scams against US consumers","date":"2024-11","date_precision":"month","victim_org":"Multiple US consumers","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Romance / Investment Scam","Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Scammers generated AI video and voice of Elon Musk pitching cryptocurrency investment schemes and distributed them as ads and posts on Facebook and TikTok.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Individual victim Heidi Swan lost over US$10,000; Deloitte estimated generative AI contributed to more than US$12 billion in US fraud losses in 2023, projected to reach US$40 billion by 2027","records_affected":null,"threat_actor":null,"summary":"By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.","how_it_worked":"The lure ran on the credibility of a single very famous investor whose views on cryptocurrency are widely known, so a video of him endorsing a platform confirmed what many targets already half-believed. Distribution through paid social advertising delivered the content inside trusted feeds and let operators target older users with disposable savings. The synthetic Musk described a limited-time opportunity with outsized returns, and the follow-through moved victims onto a bogus exchange with a support representative who coached them through funding the account. Fabricated balance growth and, in some cases, small permitted withdrawals sustained belief and encouraged larger deposits until withdrawals were blocked.","lessons":"Celebrity endorsement is never a basis for investing; platforms must verify advertiser identity and screen for synthetic likeness of public figures before ads run.","confidence":"Reported","sources":[{"title":"Deepfakes of Elon Musk are contributing to billions of dollars in fraud losses in the U.S.","url":"https://www.cbsnews.com/texas/news/deepfakes-ai-fraud-elon-musk/","publisher":"CBS News"},{"title":"Deepfake Elon Musk Videos Have Reportedly Contributed to Billions in Fraud","url":"https://incidentdatabase.ai/cite/795/","publisher":"AI Incident Database"}],"entry_type":"campaign","slug":"2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu"},{"slug":"2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou","title":"Ascension ransomware attack began when an employee downloaded a malicious file","date":"2024-05-08","date_precision":"day","year":2024,"victim_org":"Ascension","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5600000,"threat_actor":"Black Basta (reported)","summary":"Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.","how_it_worked":"A staff member downloaded a file to a work computer in the belief that it was legitimate, which is the form of compromise that has largely replaced the classic attachment: the user is looking for something, a document, an update, a utility, and takes delivery of malware from what appears to be an ordinary source. That single endpoint gave the operators their foothold in a health system spanning 140 hospitals, where the pressure to keep clinical systems continuously available works against aggressive segmentation. The attackers reached and exfiltrated data from seven servers before deploying encryption, forcing weeks of downtime procedures across the network.","lessons":"Application allowlisting and blocking user-initiated downloads of executables on clinical endpoints, combined with segmentation, are what keep one mistaken download from stopping 140 hospitals.","confidence":"Confirmed","sources":[{"title":"Ascension hacked after employee downloaded malicious file","url":"https://www.bleepingcomputer.com/news/security/ascension-hacked-after-employee-downloaded-malicious-file/","publisher":"BleepingComputer"},{"title":"Ascension cyberattack exposes data from 5.6 million people","url":"https://www.healthcaredive.com/news/ascension-cyberattack-data-breach-5-6-million/736167/","publisher":"Healthcare Dive"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou"},{"title":"AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads","date":"2024-01","date_precision":"month","victim_org":"Multiple US consumers; brands Taylor Swift and Le Creuset impersonated","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Voice Clone / Audio Deepfake","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The ads paired authentic images of the singer with a synthesised clone of her voice; a Carnegie Mellon researcher confirmed the audio was fabricated while the photographs were genuine.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Individual victims reported paying small shipping fees and supplying card details; aggregate loss not published","records_affected":null,"threat_actor":null,"summary":"In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.","how_it_worked":"The scam borrowed two trusted identities at once, a celebrity with an unusually devoted fanbase and a premium cookware brand that plausibly runs promotions. Distribution came through paid social ads, so the content arrived inside a feed the target already trusted rather than in an unsolicited message. The cloned voice narrating a personal-sounding offer supplied the authenticity that still images alone would not, and the giveaway framing made urgency natural: a limited number of free sets meant acting immediately. The small shipping fee was the conversion step, low enough to feel harmless while capturing card data and personal details.","lessons":"Consumers should verify giveaways on the brand's own site, and ad platforms need celebrity-likeness and synthetic-voice detection in advertiser review rather than post-hoc takedown.","confidence":"Reported","sources":[{"title":"The Taylor Swift Le Creuset cookware giveaway is fake","url":"https://www.today.com/food/news/taylor-swift-le-creuset-cookware-giveaway-fake-rcna133325","publisher":"TODAY / NBC News"},{"title":"AI-generated ads using Taylor Swift's likeness dupe fans with fake Le Creuset giveaway","url":"https://cbsnews.com/news/taylor-swift-le-creuset-ai-generated-ads","publisher":"CBS News"}],"entry_type":"campaign","slug":"2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads"},{"title":"Ghostwriter credential phishing against Ukrainian government and military accounts","date":"2022-05","date_precision":"month","victim_org":"Ukrainian government and military personnel","sector":"Government","country":"Ukraine","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Credential Theft","Espionage","Attempt Blocked"],"loss_usd":null,"loss_note":"No monetary loss; Google reported no accounts were compromised in the Ghostwriter campaign it described.","records_affected":null,"threat_actor":"Ghostwriter / UNC1151 (Belarus-attributed), alongside APT28 and Turla activity","summary":"Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.","how_it_worked":"Ghostwriter sent messages containing links to legitimate but compromised third-party websites that hosted the first-stage phishing page, which lends the URL an innocuous reputation and defeats simple domain blocklists. Users who clicked were redirected to attacker-controlled infrastructure presenting a replica webmail sign-in page, where entered credentials were captured. The campaign leaned on wartime urgency and the volume of official correspondence flowing to government and military staff, conditions in which recipients process messages quickly and are primed to expect unfamiliar senders and new systems.","lessons":"Enrolling government and military accounts in advanced protection with hardware security keys, and treating links to unfamiliar third-party sites as untrusted regardless of domain reputation, blocks this class of harvesting.","confidence":"Confirmed","sources":[{"title":"Update on cyber activity in Eastern Europe","url":"https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar"},{"title":"Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed","date":"2020-07-23","date_precision":"day","victim_org":"Garmin Ltd.","sector":"Technology","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Extortion"],"loss_usd":null,"loss_note":"Garmin never confirmed a ransom payment or a loss figure; press reporting of a multimillion-dollar payment is unverified.","records_affected":null,"threat_actor":"Evil Corp (WastedLocker operators)","summary":"Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.","how_it_worked":"In the WastedLocker campaigns of 2020 as documented by researchers, users browsing legitimate but compromised news and business websites were served a fake browser or Flash update overlay. Accepting the prompt downloaded a JavaScript-based loader, after which operators escalated privileges, moved laterally with Cobalt Strike and PowerShell, disabled security tooling and deployed WastedLocker across servers. For Garmin, only the ransomware family and the operational impact were publicly established; the entry point was never disclosed by the company or by law enforcement, so the human-deception element in this specific case is inferred from the campaign pattern rather than confirmed.","lessons":"Blocking user-initiated software updates from browser prompts and enforcing application control on workstations removes the fake-update lure that this ransomware family relied on.","confidence":"Alleged","sources":[{"title":"Garmin outage caused by confirmed WastedLocker ransomware attack","url":"https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/","publisher":"BleepingComputer"},{"title":"WastedLocker explained: How this targeted ransomware extorts millions from victims","url":"https://www.csoonline.com/article/569859/wastedlocker-explained-how-this-targeted-ransomware-extorts-millions-from-victims.html","publisher":"CSO Online"},{"title":"LockerGoga and WastedLocker ransomware insight","url":"https://www.recordedfuture.com/blog/lockergoga-ransomware-insight","publisher":"Recorded Future"}],"entry_type":"incident","slug":"2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c"},{"title":"Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups","date":"2017-05-12","date_precision":"day","victim_org":"US consumers (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Tech Support Scam","secondary_vectors":["Callback Phishing (TOAD)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the era predates generative tooling in this scam type.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"The FTC stated consumers paid millions of dollars but published no single campaign total. Individual matters included a $27 million default judgment and $1.3 million in forfeited assets.","records_affected":null,"threat_actor":"Repair All PC LLC, Troth Solutions, Vylah Tec, Universal Network Solutions, Click4Support, BigDog Solutions, First Choice Tech Support and others","summary":"On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.","how_it_worked":"Consumers browsing the web were served pop-up advertisements built to mimic genuine security alerts from Microsoft, Apple and other technology companies, warning that the machine was infected or being hacked and instructing the user to call a toll-free number. Telemarketers answering those calls claimed to represent the impersonated vendor, talked the victim into installing remote access software, and ran theatrical fake diagnostic tests that displayed ordinary system logs as evidence of infection. Having manufactured alarm and demonstrated apparent expertise, they sold hundreds of dollars of unnecessary repairs, software and multi-year service plans.","lessons":"Browser and OS vendors blocking full-screen dialog abuse, plus the simple consumer rule that no legitimate vendor puts a support phone number in a security warning, removes the entry point.","confidence":"Confirmed","sources":[{"title":"FTC and Federal, State and International Partners Announce Major Crackdown on Tech Support Scams","url":"https://www.ftc.gov/news-events/news/press-releases/2017/05/ftc-federal-state-international-partners-announce-major-crackdown-tech-support-scams","publisher":"Federal Trade Commission"}],"entry_type":"campaign","slug":"2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support"},{"slug":"2017-russian-fsb-officers-spear-phished-wolf-creek-nuclear-plant-in-global-en","title":"Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign","date":"2017","date_precision":"year","year":2017,"victim_org":"Wolf Creek Nuclear Operating Corporation","sector":"Energy & Utilities","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Russian FSB Center 16 (Dragonfly / Energetic Bear); three officers indicted by the US DOJ in 2021, unsealed 2022","summary":"A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.","how_it_worked":"The operators mailed engineers and IT staff at energy companies with documents tailored to their work, including material presented as job applications and CVs and as industry technical content, so opening the attachment felt like part of the job. Recipients who opened the files installed malware or were funnelled to credential-harvesting pages. The campaign also compromised websites the same engineers routinely visited, so credentials could be captured without any email at all. At Wolf Creek the successful phishing gave access to the corporate business network, which the group then used to push deeper into the victim's systems.","lessons":"Role-targeted phishing against engineers demands hardware-backed MFA and strict separation between corporate email environments and any network adjacent to operational technology.","confidence":"Confirmed","sources":[{"title":"Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide","url":"https://www.justice.gov/archives/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical","publisher":"U.S. Department of Justice"},{"title":"Indictment related to Wolf Creek computer hack unsealed","url":"https://www.ans.org/news/article-3818/indictment-related-to-wolf-creek-computer-hack-unsealed/","publisher":"American Nuclear Society"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-russian-fsb-officers-spear-phished-wolf-creek-nuclear-plant-in-global-en"},{"title":"Epsilon email marketing breach exposes address lists of banks and retailers","date":"2011-04","date_precision":"month","victim_org":"Epsilon Data Management and other email service providers","sector":"Professional Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":2000000,"loss_note":"The indictment alleged the defendants generated over $2 million from spam campaigns promoting counterfeit software using the stolen lists; downstream costs to the affected brands were not quantified.","records_affected":1000000000,"threat_actor":"Viet Quoc Nguyen, Giang Hoang Vu and David-Manuel Santos Da Silva (indicted March 2015)","summary":"In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.","how_it_worked":"The lead defendant sent targeted phishing emails to employees of email service providers. The messages carried links to sites built to exploit browser vulnerabilities and silently install malware, giving backdoor access to employee workstations and, from there, harvested access credentials for the marketing platforms. With those credentials he bulk-downloaded subscriber lists to a server he controlled in the Netherlands. Because the stolen records paired real names with the specific brands each person banked or shopped with, they were unusually valuable for follow-on spear phishing against consumers.","lessons":"Marketing platforms holding client subscriber lists need bulk-export alerting and least-privilege segregation, so one phished employee workstation cannot pull the entire customer database.","confidence":"Confirmed","sources":[{"title":"Feds Indict Three in 2011 Epsilon Hack","url":"https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/","publisher":"Krebs on Security"}],"entry_type":"incident","slug":"2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail","year":2011,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail"}]}