Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups
US consumers (multi-victim campaign) · United States
On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.
Save the Children Federation loses nearly $1 million in charity BEC fraud
Save the Children Federation, Inc. · United States
In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.
Chipotle payment card breach traced to FIN7 phishing emails backed by phone calls
Chipotle Mexican Grill · United States
Chipotle disclosed in May 2017 that point-of-sale malware had captured payment card track data at restaurants between 24 March and 18 April 2017, including cardholder name, card number, expiry date and verification code. The FBI attributed the intrusion to FIN7, naming Chipotle among the group's publicly disclosed US victims. FIN7 entered victim networks through phishing emails that employees opened, reinforced by follow-up phone calls.
IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits
US school districts, tribal organizations, nonprofits and employers (multi-victim campaign) · United States
In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.
Dublin Zoo defrauded of about €500,000 in invoice redirection scam
Dublin Zoo · Ireland
Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.
Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign
Wolf Creek Nuclear Operating Corporation · United States
A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.
GRU spear-phished election vendor VR Systems, then 122 local election officials
VR Systems and US local election administrators · United States
A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.
Leoni AG Romanian subsidiary wires €40 million to fraudsters
Leoni AG (Bistrița, Romania subsidiary) · Romania
German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.
Milwaukee Bucks employee sends players' and staff W-2s to an impersonator
Milwaukee Bucks (NBA) · United States
The NBA's Milwaukee Bucks disclosed in May 2016 that an employee had emailed 2015 W-2 tax documents for players and staff to an unknown party in response to a message impersonating the team's president. The documents included names, addresses, Social Security numbers and compensation figures. The team offered three years of credit monitoring to those affected.
John Podesta and DNC staff phished by fake Google security alerts in 2016
Hillary for America campaign and the Democratic National Committee · United States
On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.
Seagate CEO-impersonation phish exposes every US employee's W-2
Seagate Technology · United States
On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.
Sprouts Farmers Market payroll employee emails 21,000 staff W-2s to a scammer
Sprouts Farmers Market · United States
In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.
Snapchat payroll staff phished by fake CEO request for employee W-2s
Snapchat, Inc. · United States
On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.
Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails
Bangladesh Bank (central bank of Bangladesh) · Bangladesh
In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.
Austrian aerospace supplier FACC loses about €50 million to CEO fraud
FACC AG · Austria
FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.
Belgian bank Crelan loses €70 million to CEO-fraud payment orders
Crelan NV/SA · Belgium
Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.
GRU spearphishing of the Clinton campaign, DNC and DCCC
Hillary Clinton presidential campaign, Democratic National Committee and Democratic Congressional Campaign Committee · United States
A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.
Ukraine power grid blackout of 2015 began with BlackEnergy spear phishing
Kyivoblenergo, Prykarpattyaoblenergo and Chernivtsioblenergo · Ukraine
On 23 December 2015 three Ukrainian regional electricity distribution companies were hit by a coordinated cyberattack that opened breakers at roughly 30 substations and left about 225,000 customers without power. The joint E-ISAC/SANS analysis found the intrusion began months earlier with spear phishing emails carrying malicious Office documents that installed BlackEnergy 3, which was used to harvest credentials for the operators' VPN and SCADA environments.
IRS 'Get Transcript' abused to pull 334,000 taxpayer transcripts
US taxpayers via the Internal Revenue Service (multi-victim campaign) · United States
In August 2015 the IRS disclosed that criminals had successfully retrieved prior-year tax transcripts for roughly 334,000 taxpayers through its online Get Transcript service, having attempted access against about 610,000 taxpayers. The Treasury Inspector General later put the potentially compromised total higher. Attackers defeated the service's knowledge-based authentication rather than breaching IRS systems.
Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise
Ubiquiti Networks · United States
In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.
Mattel wires $3 million to Chinese account in CEO impersonation scam, recovers it
Mattel, Inc. · United States
On April 30, 2015 a Mattel finance executive wired $3 million to a bank in Wenzhou, China after receiving an email purporting to come from newly appointed chief executive Christopher Sinclair. The fraud was recognized the same day. Because May 1 was a banking holiday in China, Mattel was able to work with U.S. and Chinese law enforcement and the receiving bank to freeze the account, and the funds were returned within days.
Ryanair loses nearly $5 million from fuel account via fraudulent transfer
Ryanair Holdings plc · Ireland
In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.
Anthem breach of 78.8 million records started with a spear phishing email
Anthem Inc. · United States
Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.
Xoom Corporation loses $30.8 million to employee impersonation fraud
Xoom Corporation · United States
Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.