Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 100 entries · page 2 of 5
January 29, 2026·Technology

Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records

Match Group (Match, Hinge, OkCupid) · United States

ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.

Credential Phishing Portal
10.0M affectedReported2 sources
January 10, 2026·Cryptocurrency

$282M in Bitcoin and Litecoin stolen from a holder via social engineering

Unnamed cryptocurrency holder · Unknown

On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.

Tech Support Scam
$282.0M funds lostReported2 sources
January 9, 2026·Financial Services

Betterment named among victims of the January 2026 real-time vishing wave

Betterment · United States

Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.

Vishing (Voice Phishing)
Reported1 source
January 2026·Media & Entertainment

SoundCloud hit as real-time vishing kits drive browsers through SSO logins

SoundCloud · Germany

A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.

Vishing (Voice Phishing)
36.0M affectedReported1 source
January 2026·Financial ServicesCampaign

Okta SSO accounts targeted in vishing campaign against financial firms

Multiple fintech, wealth management and advisory firms (unnamed) · United States

BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed1 source
January 2026·Technology

Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked

Crunchbase · United States

Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.

Vishing (Voice Phishing)
2.0M affectedReported3 sources
January 2026·OtherCampaign

ShinyHunters SSO vishing campaign hits 100+ organizations

100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance · Global

Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.

Vishing (Voice Phishing)
Confirmed2 sources
January 2026·Hospitality

ShinyHunters claim 14M Panera Bread records after Entra SSO vishing

Panera Bread · United States

ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.

Vishing (Voice Phishing)
Alleged2 sources
November 18, 2025·Education

Harvard alumni and donor data stolen in phone-based phishing attack

Harvard University · United States

Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.

Vishing (Voice Phishing)
Confirmed2 sources
November 2025·Education

Princeton advancement database breached in targeted phishing attack

Princeton University · United States

Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.

Spear Phishing (Email)
Confirmed2 sources
September 18, 2025·Other

US and UK charge Scattered Spider pair tied to $115M in ransom payments

47 US organisations including healthcare, transport and technology firms · United States

On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.

Help Desk Impersonation
$115.0M multi-victim totalConfirmed2 sources
September 2025·Manufacturing

Stellantis confirms customer data stolen from Salesforce platform

Stellantis · Netherlands

Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.

Vishing (Voice Phishing)
Reported2 sources
September 2025·Retail

Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft

Kering (Gucci, Balenciaga, Alexander McQueen) · France

Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.

Vishing (Voice Phishing)
Reported2 sources
August 6, 2025·Technology

Workday discloses CRM breach after social engineering of employees

Workday · United States

Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.

Vishing (Voice Phishing)
Confirmed2 sources
August 2025·Transportation & Logistics

Air France and KLM disclose breach of third-party customer service platform

Air France-KLM · France

Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Retail

Chanel notifies US clients after third-party client-care database breach

Chanel · United States

Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Retail

Pandora warns customers after third-party platform breach

Pandora A/S · Denmark

Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Cryptocurrency

Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts

Cryptocurrency holders and companies targeted by the group · United States

A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.

SIM Swap
$13.0M funds lostConfirmed2 sources
July 28, 2025·Financial Services

TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs

TransUnion · United States

Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.

Vishing (Voice Phishing)
4.4M affectedReported2 sources
July 24, 2025·Technology

Cisco confirms vishing call gave attacker access to its third-party CRM instance

Cisco Systems · United States

Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.

Vishing (Voice Phishing)
Confirmed2 sources
July 16, 2025·Financial Services

Allianz Life's Salesforce CRM emptied after social engineering

Allianz Life Insurance Company of North America · United States

Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.

Vishing (Voice Phishing)Suspected AI-enabled
1.1M affectedConfirmed4 sources
July 1, 2025·Transportation & Logistics

Qantas contact centre platform breached after help desk tricked into adding MFA

Qantas Airways · Australia

Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.

Help Desk Impersonation
5.7M affectedConfirmed4 sources
July 2025·Retail

LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave

LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.) · France

Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.

Vishing (Voice Phishing)
Reported2 sources
July 2025·OtherCampaign

Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware

US retail, airline, transportation and insurance organisations · United States

Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.

Help Desk Impersonation
Confirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vishing+%28Voice+Phishing%29.