Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 80 entries · page 2 of 4
December 3, 2024·ConsumerBenchmark

FBI warns criminals are using generative AI to scale voice-clone and identity fraud

US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign) · United States

On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed1 source
September 2024·Government

US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM

Office of US Senator Ben Cardin, Senate Foreign Relations Committee · United States

In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.

Deepfake Video CallSuspected AI-enabledAttempt blocked
Reported2 sources
August 14, 2024·Government

Iran's APT42 phishes Israeli and US officials with think-tank impersonation

Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States

On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.

Credential Phishing Portal
Confirmed1 source
May 8, 2024·Healthcare

Ascension ransomware attack began when an employee downloaded a malicious file

Ascension · United States

Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.

Spear Phishing (Email)
5.6M affectedConfirmed2 sources
May 2024·Media & Entertainment

WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read

WPP · United Kingdom

WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.

Deepfake Video CallConfirmed AI-enabledAttempt blocked
Confirmed2 sources
February 19, 2024·Government

Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected

Los Angeles County Department of Public Health · United States

The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.

Credential Phishing Portal
200K affectedConfirmed2 sources
February 2024·Professional Services

Arup Hong Kong office loses about $25 million in deepfake video call scam

Arup Group (Hong Kong office) · Hong Kong

In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.

Deepfake Video CallConfirmed AI-enabled
$25.0M funds lostConfirmed5 sources
December 14, 2023·Cryptocurrency

Ledger Connect Kit poisoned after a former employee's npm account was phished

Ledger SAS · France

On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.

Spear Phishing (Email)
$600K funds lostConfirmed3 sources
August 2023·Energy & UtilitiesCampaign

QR code phishing campaign targets a major US energy company's Microsoft logins

Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets) · United States

Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.

QR Code PhishingAttempt blocked
Confirmed3 sources
August 2023·TechnologyCampaign

EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts

More than 100 organisations worldwide (Proofpoint-tracked campaign) · Global

Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.

Credential Phishing Portal
Confirmed2 sources
February 5, 2023·Technology

Reddit source code stolen via a phishing site cloning its intranet gateway

Reddit · United States

Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.

Credential Phishing Portal
Confirmed3 sources
October 14, 2022·Technology

Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing

Dropbox · United States

Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.

Credential Phishing Portal
Confirmed3 sources
October 2022·Retail

Bed Bath & Beyond discloses data breach to SEC after an employee was phished

Bed Bath & Beyond · United States

Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.

Credential Phishing Portal
Confirmed2 sources
July 12, 2022·TechnologyCampaign

Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations

More than 10,000 organisations targeted (Microsoft-tracked campaign) · Global

Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.

Credential Phishing Portal
Confirmed2 sources
July 2022·Transportation & Logistics

American Airlines discloses breach after phishing compromised employee mailboxes

American Airlines · United States

American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.

Credential Phishing Portal
1.7K affectedConfirmed2 sources
June 23, 2022·Cryptocurrency

Phishing of a Harmony developer preceded the $100M Horizon Bridge theft

Harmony (Horizon Bridge) · United States

Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.

Spear Phishing (Email)
$100.0M funds lostConfirmed2 sources
May 4, 2022·Financial ServicesBenchmark

FBI: business email compromise exposed $43 billion in losses across 177 countries

Businesses, government entities and individuals worldwide (multi-victim campaign) · Global

On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.

Business Email Compromise
$43.3B multi-victim total241K affectedConfirmed1 source
May 2022·Government

Ghostwriter credential phishing against Ukrainian government and military accounts

Ukrainian government and military personnel · Ukraine

Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.

Credential Phishing PortalAttempt blocked
Confirmed1 source
April 3, 2022·Cryptocurrency

Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds

SatoshiLabs (Trezor), via email provider Mailchimp · Czech Republic

Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.

Vendor / Supply Chain Impersonation
Confirmed2 sources
March 23, 2022·Cryptocurrency

Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF

Sky Mavis (Ronin Network / Axie Infinity) · Vietnam

On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.

Fake Job Offer / Recruitment Lure
$620.0M funds lostConfirmed4 sources
2022·Defense

Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge

Unnamed aerospace company in Spain · Spain

ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.

Fake Job Offer / Recruitment Lure
Confirmed3 sources
February 2021·Financial Services

Sequoia Capital investor data exposed after employee falls for phishing email

Sequoia Capital · United States

Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.

Spear Phishing (Email)
Reported3 sources
November 24, 2020·Education

Baltimore County schools ransomware started with a contractor opening a phishing email

Baltimore County Public Schools · United States

Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.

Spear Phishing (Email)
$9.7M business impactConfirmed2 sources
April 23, 2020·HealthcareCampaign

WHO impersonation surge during COVID-19 targets donors and staff

World Health Organization and the general public (multi-victim campaign) · Global

On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.

Spear Phishing (Email)
450 affectedConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Spear+Phishing+%28Email%29.