Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries
August 24, 2026·Technology

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · United States

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
August 7, 2026·Retail

Levi Strauss files 8-K after social engineering compromises three employee computers

Levi Strauss & Co. · United States

Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.

Vishing (Voice Phishing)
Confirmed2 sources
August 6, 2026·Financial Services

Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks

Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States

BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.

Vishing (Voice Phishing)Attempt blocked
$10.6M criminal proceedsConfirmed1 source
July 13, 2026·Consumer

Brinks Home breached after Microsoft Entra vishing call to an employee

Brinks Home · United States

Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.

Vishing (Voice Phishing)
Confirmed2 sources
July 6, 2026·Financial Services

Apollo Global Management breached by BlackFile callers posing as IT support

Apollo Global Management · United States

Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.

Vishing (Voice Phishing)
Confirmed2 sources
July 2026·Technology

RingCentral data on 1.6M accounts leaked after social engineering campaign

RingCentral · United States

Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.

Vishing (Voice Phishing)
1.6M affectedConfirmed2 sources
July 2026·OtherCampaign

Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts

Corporate Microsoft 365 users across a dozen countries · Global

French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.

Credential Phishing Portal
Confirmed1 source
July 2026·GovernmentCampaign

Armored Likho spear phishing targets government and power sector in three countries

Government agencies and electric power organisations in Russia, Brazil and Kazakhstan · Russia

Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.

Spear Phishing (Email)
Confirmed1 source
July 2026·Government

FBI identifies North Korean remote IT worker employed by a US federal agency

Unnamed US federal agency · United States

FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.

Fake IT Worker Infiltration
Confirmed2 sources
July 2026·DefenseCampaign

Lazarus pairs fake recruiter approaches with a Windows zero-day

Defence and aerospace organisations in Western Europe, India and South America · Global

Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.

Fake Job Offer / Recruitment Lure
Confirmed1 source
June 2026·Healthcare

Abbott investigates ShinyHunters claim after mid-June vishing on employees

Abbott Laboratories (legacy Exact Sciences systems) · United States

ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.

Vishing (Voice Phishing)
Reported2 sources
May 29, 2026·Healthcare

Quantum Health network breached after social engineering call to a user

Quantum Health · United States

A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.

Vishing (Voice Phishing)
Reported1 source
May 6, 2026·ManufacturingCampaign

MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices

Multiple organisations in the United States and MENA (unnamed) · United States and Middle East / North Africa

Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.

Help Desk Impersonation
Reported2 sources
May 2026·Professional Services

Cushman & Wakefield confirms vishing-triggered Salesforce data theft

Cushman & Wakefield · United States

Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.

Vishing (Voice Phishing)
Confirmed2 sources
May 2026·EducationCampaign

700+ education and tech sites hijacked to serve ClickFix paste-the-command lures

Visitors to 700+ compromised university and technology company websites · Global

Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.

Watering Hole / Malvertising
Confirmed1 source
May 2026·OtherCampaign

UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls

Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services · Global

Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.

Help Desk Impersonation
$10.6M criminal proceedsConfirmed2 sources
April 29, 2026·Government

City of Aurora loses $1.1M after employee falls for bank impersonation call

City of Aurora, Illinois · United States

On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.

Vishing (Voice Phishing)
$1.1M funds lostConfirmed2 sources
April 20, 2026·Consumer

ADT confirms breach after vishing attack on employee's Okta SSO account

ADT · United States

ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed2 sources
April 14, 2026·Hospitality

Carnival confirms social engineering of an employee account exposed 6 million customers

Carnival Corporation · United States

Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.

Vishing (Voice Phishing)
6.0M affectedReported3 sources
April 13, 2026·Cryptocurrency

Kraken refuses extortion after two support insiders accessed client data

Kraken · United States

CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.

Insider RecruitmentAttempt blocked
2.0K affectedConfirmed1 source
April 1, 2026·Cryptocurrency

Six-month DPRK social engineering operation preceded $285M Drift Protocol theft

Drift Protocol · Unknown

Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.

Vendor / Supply Chain Impersonation
$285.0M funds lostReported2 sources
April 1, 2026·Telecom

Charter Communications breach of 4.9M accounts began with an Entra vishing call

Charter Communications (Spectrum) · United States

ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.

Vishing (Voice Phishing)
4.9M affectedConfirmed2 sources
March 12, 2026·Media & Entertainment

Crunchyroll support tickets stolen via compromised BPO agent SSO account

Crunchyroll · United States

On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.

Credential Phishing Portal
Reported2 sources
March 2026·Technology

Identity protection firm Aura breached in vishing attack; ~900,000 records taken

Aura · United States

Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.

Vishing (Voice Phishing)
900K affectedReported1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.