Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Okta SSO accounts targeted in vishing campaign against financial firms
Multiple fintech, wealth management and advisory firms (unnamed) · United States
BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.
Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked
Crunchbase · United States
Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.
ShinyHunters SSO vishing campaign hits 100+ organizations
100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance · Global
Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.
ShinyHunters claim 14M Panera Bread records after Entra SSO vishing
Panera Bread · United States
ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.
Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams
Consumers and card issuers worldwide (Google plaintiff) · United States
In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.
University of Pennsylvania donor systems breached via social engineering
University of Pennsylvania · United States
The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.
US and UK charge Scattered Spider pair tied to $115M in ransom payments
47 US organisations including healthcare, transport and technology firms · United States
On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.
Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service
Microsoft 365 customers in 94 countries, including US healthcare organisations · United States
Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.
Claude Code used to automate extortion of at least 17 organisations
At least 17 organisations across healthcare, emergency services, government and religious institutions · United States
Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.
Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts
Cryptocurrency holders and companies targeted by the group · United States
A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.
LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave
LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.) · France
Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.
UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app
Approximately 20 Salesforce customer organisations, later including Google · Multiple
Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.
BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware
Employee of a cryptocurrency foundation (Web3 sector) · United States
In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.
Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers
US State Department; three foreign ministers, a US governor and a member of Congress · United States
In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.
Google's own Salesforce instance hit by UNC6040 IT-support vishing
Google · United States
Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.
UK 'safe account' bank and police impersonation drives £450.7M in APP fraud
UK banking customers (multi-victim campaign) · United Kingdom
UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.
FBI warns of AI voice-cloning campaign impersonating senior US officials
Current and former senior US federal and state officials and their contacts · United States
On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.
Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients
Arizona Arthritis and Rheumatology Associates · United States
Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.
Monongalia Health System email phishing breach affects 4,895 patients
Monongalia Health System (Mon Health) · United States
West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.
Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts
Multiple government, NGO, defence and energy organisations · Multiple
Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.
Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport
Wiz · United States
Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.
Iran's APT42 phishes Israeli and US officials with think-tank impersonation
Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States
On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.
Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients
Michigan Medicine (University of Michigan) · United States
Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.
Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks
US drivers and toll customers (multi-victim campaign) · United States
On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Credential+Phishing+Portal.