Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 10 of 12
September 10, 2019·OtherCampaign

Operation reWired: 281 arrested worldwide in BEC crackdown

Multiple businesses and individuals (global) · United States

Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.

Business Email CompromiseAttempt blocked
Confirmed3 sources
September 2019·Media & Entertainment

Nikkei America employee wires $29 million on fraudulent management instructions

Nikkei Inc. (Nikkei America) · United States

Japanese media group Nikkei disclosed in October 2019 that an employee at its US subsidiary, Nikkei America, had transferred about $29 million to a bank account controlled by fraudsters the previous month. The employee acted on instructions from someone impersonating a Nikkei management executive. Nikkei reported the matter to authorities in the United States and Hong Kong and said it was working to recover the funds.

Business Email Compromise
$29.0M funds lostConfirmed2 sources
August 14, 2019·Manufacturing

Toyota Boshoku European unit loses $37 million to payment-instruction BEC

Toyota Boshoku Corporation (European subsidiary) · Japan

Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.

Business Email Compromise
$37.0M funds lostConfirmed3 sources
July 2019·Education

Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow

Lancaster University · United Kingdom

Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.

Credential Phishing Portal
13K affectedConfirmed2 sources
May 29, 2019·Government

Riviera Beach pays $600,000 ransom after an employee clicked a malicious email link

City of Riviera Beach, Florida · United States

The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.

Spear Phishing (Email)
$600K ransom paidConfirmed2 sources
May 9, 2019·Healthcare

Presbyterian Healthcare Services phishing exposes data on 183,000 patients

Presbyterian Healthcare Services · United States

New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.

Credential Phishing Portal
183K affectedConfirmed2 sources
April 2019·Technology

Wipro employee accounts phished and used to attack the IT giant's own customers

Wipro Limited · India

In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.

Credential Phishing Portal
Confirmed2 sources
March 19, 2019·Manufacturing

Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer

Norsk Hydro ASA · Norway

Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.

Vendor / Supply Chain Impersonation
$71.0M business impactReported3 sources
March 2019·Energy & Utilities

UK energy firm CEO tricked by AI voice clone of German parent-company boss

Unnamed UK-based energy company (subsidiary of a German parent) · United Kingdom

In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.

Voice Clone / Audio DeepfakeSuspected AI-enabled
$243K funds lostReported2 sources
January 8, 2019·Government

Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients

Oregon Department of Human Services · United States

On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.

Credential Phishing Portal
645K affectedConfirmed2 sources
December 2018·Professional Services

Tecnimont India loses $18.6 million to fake CEO conference calls

Tecnimont SpA (Indian subsidiary, Maire Tecnimont group) · India

The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.

Business Email Compromise
$18.6M funds lostReported2 sources
November 2018·Government

Cabarrus County, NC diverts $2.5 million school payment to BEC actors

Cabarrus County, North Carolina · United States

Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.

Vendor / Supply Chain Impersonation
$2.5M funds lostConfirmed1 source
October 2018·Telecom

Mobile carrier employee took $500-a-day bribes to perform SIM swaps

Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers · United States

A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.

Insider Recruitment
19 affectedConfirmed1 source
October 2018·Education

San Diego Unified staff phished, exposing 500,000 students, parents and employees

San Diego Unified School District · United States

San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.

Credential Phishing Portal
500K affectedConfirmed2 sources
September 20, 2018·ConsumerCampaign

Virtual kidnapping ring extorts parents with staged ransom calls

Parents in Texas, California and Idaho (multi-victim campaign) · United States and Mexico

On 20 September 2018 Yanette Rodriguez Acosta of Houston was sentenced to 88 months in federal prison for conspiracy to commit wire fraud and money laundering in a virtual kidnapping extortion scheme. Co-conspirators in Mexico called victims in Texas, California and Idaho falsely claiming to have kidnapped their children and demanding ransom. The sentencing judge said the defendant showed gleeful disregard for victims while inflicting pain, fear and long-term effects for profit.

Vishing (Voice Phishing)
Confirmed1 source
July 20, 2018·ConsumerCampaign

India-based IRS and USCIS impersonation call centers: 24 defendants sentenced

US consumers, many of them elderly (multi-victim campaign) · United States and India

On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.

Vishing (Voice Phishing)
$9.0M multi-victim totalConfirmed1 source
July 2018·Government

City of Ottawa treasurer wires about US$98,000 to fake city manager

City of Ottawa · Canada

In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.

Business Email Compromise
$98K funds lostConfirmed1 source
April 2018·Manufacturing

Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud

Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom

Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.

Business Email Compromise
$11.0M funds lostConfirmed1 source
April 2018·Retail

FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards

Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor) · United States

In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.

Spear Phishing (Email)
5.0M affectedReported2 sources
March 2018·Media & Entertainment

Pathé Dutch branch wires €19 million in fake CEO acquisition scam

Pathé (Netherlands branch) · Netherlands

In March 2018 fraudsters impersonating the chief executive of French film company Pathé's parent persuaded the Dutch branch's leadership to make a series of payments totaling more than €19 million for a purported acquisition of a Dubai-based company. Branch director Dertje Meijer and CFO Edwin Slutter were both dismissed after the loss surfaced. An external investigation cleared them of involvement, and Slutter later won partial relief in a wrongful-termination suit.

Business Email Compromise
$21.5M funds lostConfirmed1 source
March 2018·Media & Entertainment

Cinema group Pathe loses EUR 19.2 million to CEO fraud; Dutch executives dismissed

Pathe (Pathe Nederland) · Netherlands

Between March and May 2018 the Dutch arm of the French cinema chain Pathe transferred about EUR 19.2 million in a series of payments to accounts in Dubai, acting on emails purporting to come from Pathe's French head office. The company dismissed the managing director and financial director of Pathe Nederland; a Dutch court ruling later published details of the case and upheld the dismissals.

Business Email Compromise
$21.5M funds lostConfirmed2 sources
March 2018·Healthcare

UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients

UnityPoint Health · United States

UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.

Business Email Compromise
$2.8M business impact1.4M affectedConfirmed2 sources
January 2018·Cryptocurrency

AT&T SIM swap drains $24M in crypto from investor Michael Terpin

Michael Terpin (individual investor; Transform Group) · United States

Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.

SIM Swap
$24.0M funds lostConfirmed2 sources
2018·Cryptocurrency

Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree

Approximately 40 individual cryptocurrency holders · United States

Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.

SIM Swap
$7.5M multi-victim totalConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.