Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Operation reWired: 281 arrested worldwide in BEC crackdown
Multiple businesses and individuals (global) · United States
Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.
Nikkei America employee wires $29 million on fraudulent management instructions
Nikkei Inc. (Nikkei America) · United States
Japanese media group Nikkei disclosed in October 2019 that an employee at its US subsidiary, Nikkei America, had transferred about $29 million to a bank account controlled by fraudsters the previous month. The employee acted on instructions from someone impersonating a Nikkei management executive. Nikkei reported the matter to authorities in the United States and Hong Kong and said it was working to recover the funds.
Toyota Boshoku European unit loses $37 million to payment-instruction BEC
Toyota Boshoku Corporation (European subsidiary) · Japan
Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.
Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow
Lancaster University · United Kingdom
Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.
Riviera Beach pays $600,000 ransom after an employee clicked a malicious email link
City of Riviera Beach, Florida · United States
The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.
Presbyterian Healthcare Services phishing exposes data on 183,000 patients
Presbyterian Healthcare Services · United States
New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.
Wipro employee accounts phished and used to attack the IT giant's own customers
Wipro Limited · India
In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.
Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer
Norsk Hydro ASA · Norway
Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.
UK energy firm CEO tricked by AI voice clone of German parent-company boss
Unnamed UK-based energy company (subsidiary of a German parent) · United Kingdom
In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.
Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients
Oregon Department of Human Services · United States
On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.
Tecnimont India loses $18.6 million to fake CEO conference calls
Tecnimont SpA (Indian subsidiary, Maire Tecnimont group) · India
The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.
Cabarrus County, NC diverts $2.5 million school payment to BEC actors
Cabarrus County, North Carolina · United States
Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.
Mobile carrier employee took $500-a-day bribes to perform SIM swaps
Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers · United States
A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.
San Diego Unified staff phished, exposing 500,000 students, parents and employees
San Diego Unified School District · United States
San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.
Virtual kidnapping ring extorts parents with staged ransom calls
Parents in Texas, California and Idaho (multi-victim campaign) · United States and Mexico
On 20 September 2018 Yanette Rodriguez Acosta of Houston was sentenced to 88 months in federal prison for conspiracy to commit wire fraud and money laundering in a virtual kidnapping extortion scheme. Co-conspirators in Mexico called victims in Texas, California and Idaho falsely claiming to have kidnapped their children and demanding ransom. The sentencing judge said the defendant showed gleeful disregard for victims while inflicting pain, fear and long-term effects for profit.
India-based IRS and USCIS impersonation call centers: 24 defendants sentenced
US consumers, many of them elderly (multi-victim campaign) · United States and India
On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.
City of Ottawa treasurer wires about US$98,000 to fake city manager
City of Ottawa · Canada
In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.
Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud
Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom
Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.
FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards
Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor) · United States
In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.
Pathé Dutch branch wires €19 million in fake CEO acquisition scam
Pathé (Netherlands branch) · Netherlands
In March 2018 fraudsters impersonating the chief executive of French film company Pathé's parent persuaded the Dutch branch's leadership to make a series of payments totaling more than €19 million for a purported acquisition of a Dubai-based company. Branch director Dertje Meijer and CFO Edwin Slutter were both dismissed after the loss surfaced. An external investigation cleared them of involvement, and Slutter later won partial relief in a wrongful-termination suit.
Cinema group Pathe loses EUR 19.2 million to CEO fraud; Dutch executives dismissed
Pathe (Pathe Nederland) · Netherlands
Between March and May 2018 the Dutch arm of the French cinema chain Pathe transferred about EUR 19.2 million in a series of payments to accounts in Dubai, acting on emails purporting to come from Pathe's French head office. The company dismissed the managing director and financial director of Pathe Nederland; a Dutch court ruling later published details of the case and upheld the dismissals.
UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients
UnityPoint Health · United States
UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.
AT&T SIM swap drains $24M in crypto from investor Michael Terpin
Michael Terpin (individual investor; Transform Group) · United States
Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.
Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree
Approximately 40 individual cryptocurrency holders · United States
Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.