Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 25 entries
February 2026·Cryptocurrency

Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware

An unnamed cryptocurrency company executive · Unknown

Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
September 16, 2025·TechnologyCampaign

Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service

Microsoft 365 customers in 94 countries, including US healthcare organisations · United States

Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.

Credential Phishing PortalConfirmed AI-enabled
5.0K affectedConfirmed2 sources
August 2025·Technology

North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs

US Fortune 500 technology companies employing fraudulent remote workers · United States

In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.

Fake IT Worker InfiltrationConfirmed AI-enabled
Reported2 sources
August 2025·Other

Claude Code used to automate extortion of at least 17 organisations

At least 17 organisations across healthcare, emergency services, government and religious institutions · United States

Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.

Credential Phishing PortalConfirmed AI-enabled
Reported2 sources
June 2025·Cryptocurrency

BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware

Employee of a cryptocurrency foundation (Web3 sector) · United States

In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
June 2025·Government

Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers

US State Department; three foreign ministers, a US governor and a member of Congress · United States

In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
May 15, 2025·GovernmentCampaign

FBI warns of AI voice-cloning campaign impersonating senior US officials

Current and former senior US federal and state officials and their contacts · United States

On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
April 2025·TechnologyCampaign

North Korean operatives adopt real-time deepfakes to pass remote job interviews

Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate · United States

In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed2 sources
March 2025·Other

Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO

Unnamed multinational firm, Singapore office · Singapore

On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.

Deepfake Video CallConfirmed AI-enabled
$499K funds lostConfirmed1 source
February 2025·Consumer

AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman

Massimo Moratti and other Italian business leaders · Italy

In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
$1.0M funds lostReported3 sources
January 2025·ConsumerCampaign

Hong Kong arrests 31 in second deepfake romance fraud ring targeting Southeast Asia

Victims in Taiwan, Singapore and Malaysia · Hong Kong

Hong Kong police arrested 31 people on 2 and 3 January 2025 over a deepfake-enabled romance and investment fraud syndicate that operated from two premises in Kowloon Bay and took more than HK$34 million (about US$4.37 million) from victims in Taiwan, Singapore and Malaysia. Members were trained to approach targets on dating apps using online photographs of attractive people combined with deepfake technology. It was the second major deepfake fraud bust by Hong Kong authorities in three months.

Romance / Investment ScamConfirmed AI-enabled
$4.4M multi-victim totalConfirmed1 source
December 3, 2024·ConsumerBenchmark

FBI warns criminals are using generative AI to scale voice-clone and identity fraud

US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign) · United States

On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed1 source
November 2024·ConsumerCampaign

Deepfake Elon Musk videos drive crypto investment scams against US consumers

Multiple US consumers · United States

By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources
October 2024·Technology

Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport

Wiz · United States

Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
October 2024·ConsumerCampaign

Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring

Men across Asia targeted through dating apps · Hong Kong

Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.

Romance / Investment ScamConfirmed AI-enabled
$46.0M multi-victim totalConfirmed2 sources
July 15, 2024·Technology

KnowBe4 hired a North Korean fake IT worker who loaded malware on day one

KnowBe4 · United States

Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed3 sources
July 2024·Manufacturing

Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question

Ferrari · Italy

In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Reported2 sources
May 2024·Media & Entertainment

WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read

WPP · United Kingdom

WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.

Deepfake Video CallConfirmed AI-enabledAttempt blocked
Confirmed2 sources
April 2024·Technology

LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO

LastPass · United States

On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed3 sources
February 2024·Professional Services

Arup Hong Kong office loses about $25 million in deepfake video call scam

Arup Group (Hong Kong office) · Hong Kong

In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.

Deepfake Video CallConfirmed AI-enabled
$25.0M funds lostConfirmed5 sources
January 2024·ConsumerCampaign

AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads

Multiple US consumers; brands Taylor Swift and Le Creuset impersonated · United States

In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources
January 2024·Government

AI-cloned Biden robocall told New Hampshire voters to skip the primary

New Hampshire primary voters · United States

On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
August 27, 2023·Technology

Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee

Retool · United States

Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.

Smishing (SMS)Confirmed AI-enabled
27 affectedConfirmed4 sources
February 2023·Consumer

French woman loses EUR 830,000 to an AI-image 'Brad Pitt' romance scam

Private individual in France (identified only as 'Anne') · France

Beginning in February 2023, a 53-year-old French woman known publicly as Anne was drawn into an online relationship with someone posing as actor Brad Pitt. Over about 18 months she sent EUR 830,000, largely after being told he needed money for kidney cancer treatment and that his accounts were frozen by divorce proceedings. AI-generated images of the actor in hospital and a forged passport reinforced the deception. She realised she had been defrauded on seeing genuine photographs of Pitt with his partner, and filed a police complaint; the case became public in January 2025 when French broadcaster TF1 aired and then withdrew her interview.

Romance / Investment ScamConfirmed AI-enabled
$858K funds lostReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?ai=Confirmed+AI-enabled.