Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 98 entries · page 2 of 5
January 2026·Financial ServicesCampaign

Okta SSO accounts targeted in vishing campaign against financial firms

Multiple fintech, wealth management and advisory firms (unnamed) · United States

BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed1 source
January 2026·Technology

Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked

Crunchbase · United States

Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.

Vishing (Voice Phishing)
2.0M affectedReported3 sources
January 2026·OtherCampaign

ShinyHunters SSO vishing campaign hits 100+ organizations

100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance · Global

Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.

Vishing (Voice Phishing)
Confirmed2 sources
January 2026·Hospitality

ShinyHunters claim 14M Panera Bread records after Entra SSO vishing

Panera Bread · United States

ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.

Vishing (Voice Phishing)
Alleged2 sources
November 2025·ConsumerCampaign

Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams

Consumers and card issuers worldwide (Google plaintiff) · United States

In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.

Smishing (SMS)
Confirmed2 sources
October 31, 2025·Education

University of Pennsylvania donor systems breached via social engineering

University of Pennsylvania · United States

The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.

Credential Phishing Portal
Confirmed2 sources
September 18, 2025·Other

US and UK charge Scattered Spider pair tied to $115M in ransom payments

47 US organisations including healthcare, transport and technology firms · United States

On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.

Help Desk Impersonation
$115.0M multi-victim totalConfirmed2 sources
September 16, 2025·TechnologyCampaign

Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service

Microsoft 365 customers in 94 countries, including US healthcare organisations · United States

Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.

Credential Phishing PortalConfirmed AI-enabled
5.0K affectedConfirmed2 sources
August 2025·Other

Claude Code used to automate extortion of at least 17 organisations

At least 17 organisations across healthcare, emergency services, government and religious institutions · United States

Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.

Credential Phishing PortalConfirmed AI-enabled
Reported2 sources
August 2025·Cryptocurrency

Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts

Cryptocurrency holders and companies targeted by the group · United States

A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.

SIM Swap
$13.0M funds lostConfirmed2 sources
July 2025·Retail

LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave

LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.) · France

Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.

Vishing (Voice Phishing)
Reported2 sources
June 4, 2025·Other

UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app

Approximately 20 Salesforce customer organisations, later including Google · Multiple

Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.

Vishing (Voice Phishing)
Confirmed1 source
June 2025·Cryptocurrency

BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware

Employee of a cryptocurrency foundation (Web3 sector) · United States

In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
June 2025·Government

Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers

US State Department; three foreign ministers, a US governor and a member of Congress · United States

In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
June 2025·Technology

Google's own Salesforce instance hit by UNC6040 IT-support vishing

Google · United States

Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed5 sources
May 19, 2025·Financial ServicesCampaign

UK 'safe account' bank and police impersonation drives £450.7M in APP fraud

UK banking customers (multi-victim campaign) · United Kingdom

UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.

Vishing (Voice Phishing)
186K affectedConfirmed2 sources
May 15, 2025·GovernmentCampaign

FBI warns of AI voice-cloning campaign impersonating senior US officials

Current and former senior US federal and state officials and their contacts · United States

On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
March 3, 2025·Healthcare

Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients

Arizona Arthritis and Rheumatology Associates · United States

Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.

Credential Phishing Portal
5.5K affectedConfirmed1 source
March 3, 2025·Healthcare

Monongalia Health System email phishing breach affects 4,895 patients

Monongalia Health System (Mon Health) · United States

West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.

Credential Phishing Portal
4.9K affectedConfirmed1 source
February 13, 2025·GovernmentCampaign

Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts

Multiple government, NGO, defence and energy organisations · Multiple

Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.

Spear Phishing (Email)
Confirmed2 sources
October 2024·Technology

Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport

Wiz · United States

Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
August 14, 2024·Government

Iran's APT42 phishes Israeli and US officials with think-tank impersonation

Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States

On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.

Credential Phishing Portal
Confirmed1 source
July 30, 2024·Healthcare

Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients

Michigan Medicine (University of Michigan) · United States

Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.

MFA Fatigue / Push Bombing
58K affectedConfirmed2 sources
April 12, 2024·Transportation & LogisticsCampaign

Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks

US drivers and toll customers (multi-victim campaign) · United States

On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.

Smishing (SMS)
2.0K affectedConfirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Credential+Phishing+Portal.