Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 52 entries · page 2 of 3
August 27, 2023·Technology

Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee

Retool · United States

Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.

Smishing (SMS)Confirmed AI-enabled
27 affectedConfirmed4 sources
August 2023·TechnologyCampaign

Okta warns of a coordinated campaign against US customers' IT service desks

Multiple US-based Okta customer organizations · United States

Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.

Help Desk Impersonation
Confirmed2 sources
August 2023·TechnologyCampaign

EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts

More than 100 organisations worldwide (Proofpoint-tracked campaign) · Global

Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.

Credential Phishing Portal
Confirmed2 sources
May 8, 2023·Technology

Dragos intrusion began with the hijacked personal email of an employee due to start work

Dragos · United States

Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.

Fake Job Offer / Recruitment LureAttempt blocked
Confirmed2 sources
March 29, 2023·Technology

3CX supply chain attack began with a trojanised X_TRADER installer on staff PC

3CX Ltd. · Cyprus

In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.

Vendor / Supply Chain Impersonation
Confirmed3 sources
February 5, 2023·Technology

Reddit source code stolen via a phishing site cloning its intranet gateway

Reddit · United States

Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.

Credential Phishing Portal
Confirmed3 sources
January 11, 2023·Technology

Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers

Mailchimp (Intuit) · United States

Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.

Help Desk Impersonation
Confirmed7 sources
October 14, 2022·Technology

Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing

Dropbox · United States

Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.

Credential Phishing Portal
Confirmed3 sources
October 2022·Technology

Zendesk breach followed successful SMS phishing of employees

Zendesk · United States

Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.

Smishing (SMS)
Reported3 sources
September 16, 2022·TechnologyCampaign

GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials

GitHub users and customer organisations (GitHub-reported campaign) · United States

GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.

Credential Phishing Portal
Confirmed2 sources
August 4, 2022·Technology

Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers

Twilio · United States

In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.

Smishing (SMS)
Confirmed4 sources
August 3, 2022·Technology

Klaviyo employee phished; attacker used internal tools to take crypto mailing lists

Klaviyo · United States

Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.

Credential Phishing Portal
Confirmed2 sources
August 2022·TechnologyCampaign

0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations

Over 130 organisations targeted (Group-IB tracked campaign) · United States

Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.

Smishing (SMS)
9.9K affectedConfirmed2 sources
July 20, 2022·Technology

Cloudflare blocks the same SMS phishing attack that breached Twilio

Cloudflare · United States

On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.

Smishing (SMS)Attempt blocked
Confirmed3 sources
July 12, 2022·TechnologyCampaign

Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations

More than 10,000 organisations targeted (Microsoft-tracked campaign) · Global

Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.

Credential Phishing Portal
Confirmed2 sources
May 24, 2022·Technology

Cisco breached after vishing and MFA fatigue against an employee

Cisco Systems · United States

Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.

MFA Fatigue / Push Bombing
Confirmed3 sources
March 18, 2022·Technology

HubSpot employee account compromised, exposing customer data at crypto firms

HubSpot · United States

On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.

Credential Phishing Portal
Confirmed2 sources
January 21, 2022·Technology

Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling

Okta (via subprocessor Sitel/Sykes) · United States

A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.

Vendor / Supply Chain Impersonation
Confirmed2 sources
July 23, 2020·Technology

Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed

Garmin Ltd. · United States

Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.

Watering Hole / Malvertising
Alleged3 sources
July 15, 2020·Technology

Twitter's July 2020 account takeover started with phone spear phishing of employees

Twitter, Inc. · United States

On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.

Vishing (Voice Phishing)
$118K criminal proceeds130 affectedConfirmed6 sources
April 2019·Technology

Wipro employee accounts phished and used to attack the IT giant's own customers

Wipro Limited · India

In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.

Credential Phishing Portal
Confirmed2 sources
March 1, 2016·Technology

Seagate CEO-impersonation phish exposes every US employee's W-2

Seagate Technology · United States

On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.

Business Email Compromise
Confirmed2 sources
February 28, 2016·Technology

Snapchat payroll staff phished by fake CEO request for employee W-2s

Snapchat, Inc. · United States

On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.

Business Email Compromise
Confirmed1 source
June 5, 2015·Technology

Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise

Ubiquiti Networks · United States

In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.

Business Email Compromise
$46.7M funds lostConfirmed4 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Technology.