Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 55 entries · page 2 of 3
August 18, 2023·Gaming & Casino

Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered

Caesars Entertainment · United States

Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.

Vendor / Supply Chain Impersonation
$15.0M ransom paidConfirmed2 sources
August 11, 2023·Manufacturing

Clorox attack traced to help desk agents resetting passwords without verification

The Clorox Company · United States

Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.

Help Desk Impersonation
$380.0M business impactConfirmed5 sources
March 29, 2023·Technology

3CX supply chain attack began with a trojanised X_TRADER installer on staff PC

3CX Ltd. · Cyprus

In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.

Vendor / Supply Chain Impersonation
Confirmed3 sources
January 11, 2023·Technology

Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers

Mailchimp (Intuit) · United States

Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.

Help Desk Impersonation
Confirmed7 sources
November 7, 2022·OtherCampaign

Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds

Multiple (New York law firm, a Maltese bank, a Qatari businessman, others) · United States

Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.

Business Email Compromise
Confirmed1 source
October 14, 2022·Technology

Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing

Dropbox · United States

Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.

Credential Phishing Portal
Confirmed3 sources
September 16, 2022·TechnologyCampaign

GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials

GitHub users and customer organisations (GitHub-reported campaign) · United States

GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.

Credential Phishing Portal
Confirmed2 sources
August 25, 2022·Transportation & Logistics

DoorDash customer data exposed through phished third-party vendor employees

DoorDash · United States

DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.

Vendor / Supply Chain Impersonation
Confirmed3 sources
May 4, 2022·Financial ServicesBenchmark

FBI: business email compromise exposed $43 billion in losses across 177 countries

Businesses, government entities and individuals worldwide (multi-victim campaign) · Global

On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.

Business Email Compromise
$43.3B multi-victim total241K affectedConfirmed1 source
April 3, 2022·Cryptocurrency

Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds

SatoshiLabs (Trezor), via email provider Mailchimp · Czech Republic

Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.

Vendor / Supply Chain Impersonation
Confirmed2 sources
March 30, 2022·OtherCampaign

Operation Eagle Sweep: 65 arrests in global BEC disruption

Multiple businesses and individuals (500+ U.S. victims) · United States

Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.

Business Email CompromiseAttempt blocked
Confirmed1 source
March 18, 2022·Technology

HubSpot employee account compromised, exposing customer data at crypto firms

HubSpot · United States

On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.

Credential Phishing Portal
Confirmed2 sources
January 21, 2022·Technology

Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling

Okta (via subprocessor Sitel/Sykes) · United States

A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.

Vendor / Supply Chain Impersonation
Confirmed2 sources
July 2021·Government

Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover

Town of Peterborough, New Hampshire · United States

The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.

Business Email Compromise
$2.3M funds lostConfirmed2 sources
2021·Nonprofit

One Treasure Island nonprofit loses $650,000 to hijacked email thread

One Treasure Island · United States

One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.

Business Email Compromise
$650K funds lostReported2 sources
November 24, 2020·Education

Baltimore County schools ransomware started with a contractor opening a phishing email

Baltimore County Public Schools · United States

Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.

Spear Phishing (Email)
$9.7M business impactConfirmed2 sources
April 23, 2020·HealthcareCampaign

WHO impersonation surge during COVID-19 targets donors and staff

World Health Organization and the general public (multi-victim campaign) · Global

On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.

Spear Phishing (Email)
450 affectedConfirmed2 sources
April 6, 2020·Healthcare

Magellan Health ransomware began with a phishing email impersonating a client

Magellan Health · United States

Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.

Spear Phishing (Email)
$1.4M business impact365K affectedConfirmed2 sources
January 17, 2020·Government

Puerto Rico government agency sends $2.6 million to fraudulent account

Puerto Rico Industrial Development Company (PRIDCO) · Puerto Rico

Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.

Business Email Compromise
$2.6M funds lostConfirmed1 source
September 10, 2019·OtherCampaign

Operation reWired: 281 arrested worldwide in BEC crackdown

Multiple businesses and individuals (global) · United States

Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.

Business Email CompromiseAttempt blocked
Confirmed3 sources
August 14, 2019·Manufacturing

Toyota Boshoku European unit loses $37 million to payment-instruction BEC

Toyota Boshoku Corporation (European subsidiary) · Japan

Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.

Business Email Compromise
$37.0M funds lostConfirmed3 sources
April 2019·Technology

Wipro employee accounts phished and used to attack the IT giant's own customers

Wipro Limited · India

In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.

Credential Phishing Portal
Confirmed2 sources
March 19, 2019·Manufacturing

Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer

Norsk Hydro ASA · Norway

Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.

Vendor / Supply Chain Impersonation
$71.0M business impactReported3 sources
December 2018·Professional Services

Tecnimont India loses $18.6 million to fake CEO conference calls

Tecnimont SpA (Indian subsidiary, Maire Tecnimont group) · India

The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.

Business Email Compromise
$18.6M funds lostReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vendor+%2F+Supply+Chain+Impersonation.