Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 20 of 44 entries · page 2 of 2
May 15, 2024·OtherCampaign

Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta

Multiple organisations (campaign) · Multiple

Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.

Vishing (Voice Phishing)
Confirmed3 sources
September 11, 2023·Gaming & Casino

MGM Resorts shut down for ten days after a help desk social engineering call

MGM Resorts International · United States

MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.

Help Desk Impersonation
$110.0M business impactReported4 sources
August 27, 2023·Technology

Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee

Retool · United States

Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.

Smishing (SMS)Confirmed AI-enabled
27 affectedConfirmed4 sources
August 19, 2023·Professional Services

SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data

Kroll · United States

Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.

SIM Swap
Confirmed2 sources
August 18, 2023·Gaming & Casino

Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered

Caesars Entertainment · United States

Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.

Vendor / Supply Chain Impersonation
$15.0M ransom paidConfirmed2 sources
August 11, 2023·Manufacturing

Clorox attack traced to help desk agents resetting passwords without verification

The Clorox Company · United States

Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.

Help Desk Impersonation
$380.0M business impactConfirmed5 sources
August 2023·TechnologyCampaign

Okta warns of a coordinated campaign against US customers' IT service desks

Multiple US-based Okta customer organizations · United States

Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.

Help Desk Impersonation
Confirmed2 sources
May 8, 2023·Technology

Dragos intrusion began with the hijacked personal email of an employee due to start work

Dragos · United States

Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.

Fake Job Offer / Recruitment LureAttempt blocked
Confirmed2 sources
May 2023·Cryptocurrency

Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked

Bart Stephens, co-founder of Blockchain Capital · United States

Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.

SIM SwapAttempt blocked
$6.3M funds lostReported1 source
February 5, 2023·Cryptocurrency

Coinbase employee phished by SMS then talked through by a fake IT caller

Coinbase · United States

In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.

Smishing (SMS)Attempt blocked
Confirmed3 sources
January 11, 2023·Technology

Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers

Mailchimp (Intuit) · United States

Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.

Help Desk Impersonation
Confirmed7 sources
January 2023·Gaming & Casino

Riot Games loses League of Legends source code to a social engineering attack

Riot Games · United States

Riot Games disclosed in January 2023 that attackers used social engineering to compromise its development environment and steal source code for League of Legends and Teamfight Tactics along with a legacy anti-cheat platform. The company received a ransom email demanding $10 million and publicly refused to pay. Riot said no player data or personal information was compromised, but the intrusion disrupted its build pipeline and delayed game patches.

Help Desk Impersonation
Confirmed2 sources
September 18, 2022·Gaming & Casino

Rockstar Games internal Slack breached and GTA 6 footage leaked

Rockstar Games · United States

An actor using the handle teapotuberhacker, the same persona behind the Uber intrusion days earlier, posted roughly 90 in-development Grand Theft Auto VI videos and claimed to hold GTA V and GTA VI source code, saying they had reached Rockstar's internal Slack and Confluence. Rockstar confirmed a network intrusion and unauthorised access to early development footage. A UK teenager, Arion Kurtaj, was later convicted and in December 2023 given an indefinite hospital order.

Help Desk Impersonation
Alleged2 sources
September 15, 2022·Transportation & Logistics

Uber breached after MFA push bombing and a WhatsApp message posing as IT

Uber Technologies · United States

In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.

MFA Fatigue / Push Bombing
Confirmed5 sources
November 3, 2021·Financial Services

Robinhood support employee socially engineered by phone; 7 million customers exposed

Robinhood Markets · United States

On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.

Vishing (Voice Phishing)
7.0M affectedConfirmed2 sources
June 2021·Gaming & Casino

Electronic Arts source code stolen via Slack cookie and IT help desk impersonation

Electronic Arts · United States

In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.

Help Desk Impersonation
Reported3 sources
November 13, 2020·Cryptocurrency

Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash

GoDaddy (registrar); Liquid.com and NiceHash · United States

Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.

Vishing (Voice Phishing)
Confirmed2 sources
July 15, 2020·Technology

Twitter's July 2020 account takeover started with phone spear phishing of employees

Twitter, Inc. · United States

On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.

Vishing (Voice Phishing)
$118K criminal proceeds130 affectedConfirmed6 sources
January 2018·Cryptocurrency

AT&T SIM swap drains $24M in crypto from investor Michael Terpin

Michael Terpin (individual investor; Transform Group) · United States

Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.

SIM Swap
$24.0M funds lostConfirmed2 sources
2018·Cryptocurrency

Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree

Approximately 40 individual cryptocurrency holders · United States

Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.

SIM Swap
$7.5M multi-victim totalConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Help+Desk+Impersonation.