Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Sony Pictures destructive hack preceded by fake Apple ID phishing emails
Sony Pictures Entertainment · United States
On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.
Celebrity iCloud photo theft: 600 victims phished with fake Apple and Google emails
Celebrities and private individuals with Apple iCloud and Google accounts · United States
The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.
Scoular Company wires $17.2 million after fake CEO and auditor emails
The Scoular Company · United States
In June 2014 the corporate controller of Omaha-based commodities trading firm The Scoular Company wired $17.2 million to a Chinese bank in three installments after receiving emails impersonating chief executive Chuck Elsea and the company's outside auditor at KPMG. The messages described a confidential international acquisition and demanded secrecy. The emails were sent from accounts associated with Germany, France and Israel using servers in Moscow.
Premera Blue Cross breach began with a spear-phishing email, 10.4 million affected
Premera Blue Cross · United States
Attackers compromised Premera Blue Cross in May 2014 and remained undetected for about nine months until January 2015. The intrusion exposed the protected health information of roughly 10.4 million individuals, including names, dates of birth, Social Security numbers, bank account details and clinical information. The HHS Office for Civil Rights, describing the incident, stated that the entry point was a spear-phishing email that installed malware.
Yahoo network breached via spear-phishing email, 500 million accounts stolen
Yahoo! Inc. · United States
In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.
Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical
Target Corporation · United States
Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.
AP Twitter account hijacked, fake White House bombing tweet jolts markets
The Associated Press · United States
On 23 April 2013 the Associated Press's main Twitter account posted a false report of two explosions at the White House injuring President Obama. The Dow Jones Industrial Average dropped roughly 143 points in minutes before recovering once AP disavowed the tweet. AP said the account takeover was preceded by phishing attempts against its corporate network; the Syrian Electronic Army claimed responsibility, a claim that was not independently corroborated at the time.
Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million
Google LLC and Facebook, Inc. · United States
From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.
Epsilon email marketing breach exposes address lists of banks and retailers
Epsilon Data Management and other email service providers · United States
In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.
RSA SecurID breach begins with '2011 Recruitment Plan' spear phishing email
RSA Security (EMC) · United States
In March 2011 attackers stole information related to RSA's SecurID two-factor authentication product after two small groups of RSA employees were sent spear phishing emails carrying a booby-trapped Excel attachment. RSA executive Uri Rivner publicly described the lure email as being titled '2011 Recruitment Plan.' The stolen SecurID data was subsequently used in attempted intrusions at US defense contractors, and RSA offered to replace tokens for customers.
Sarah Palin Yahoo email account taken over via password-reset questions
Sarah Palin (then Governor of Alaska and vice-presidential candidate) · United States
During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.
HP boardroom pretexting scandal: investigators impersonate directors to phone carriers
Hewlett-Packard directors, journalists and their family members · United States
California Attorney General Bill Lockyer filed criminal charges on 4 October 2006 against former HP chairwoman Patricia Dunn, former HP ethics chief Kevin Hunsaker and three outside investigators. To identify the source of boardroom leaks to the press, investigators obtained the private telephone billing records of 12 people by impersonating them to phone carriers. Personal identifying information for 13 board members, journalists and family members was obtained and used unlawfully. Each defendant faced four felony counts.
Kevin Mitnick's telecom pretexting campaign and 1995 arrest
Pacific Bell, Digital Equipment Corporation and other telecommunications and computer firms · United States
Kevin Mitnick was arrested by the FBI in Raleigh, North Carolina on 15 February 1995 and found with cloned cellular phones, more than 100 cloned cellular phone codes and multiple pieces of false identification. In 1999 he pleaded guilty to four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting wire communications, and admitted copying proprietary software from large cellular telephone and computer companies. He was sentenced to 46 months plus 22 months for violating supervised release. His case is the formative reference point for social engineering as a discipline.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.