Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 3 of 12
November 20, 2025·TelecomCampaign

Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders

AT&T and T-Mobile customers, including four Manhattan residents · United States

Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.

Insider Recruitment
$435K multi-victim totalAlleged1 source
November 18, 2025·Education

Harvard alumni and donor data stolen in phone-based phishing attack

Harvard University · United States

Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.

Vishing (Voice Phishing)
Confirmed2 sources
November 3, 2025·Professional Services

US ransomware negotiators charged with running their own BlackCat attacks

US medical device company, pharmaceutical firm, drone maker and other victims · United States

US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.

Insider Recruitment
$1.3M ransom paidConfirmed2 sources
November 2025·Education

Princeton advancement database breached in targeted phishing attack

Princeton University · United States

Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.

Spear Phishing (Email)
Confirmed2 sources
November 2025·Technology

Five plead guilty to helping North Korean IT workers infiltrate 136 US companies

136 US companies (victims of the fake-worker scheme) · United States

The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.

Fake IT Worker Infiltration
$2.2M criminal proceedsConfirmed2 sources
November 2025·ConsumerCampaign

Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams

Consumers and card issuers worldwide (Google plaintiff) · United States

In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.

Smishing (SMS)
Confirmed2 sources
October 31, 2025·Education

University of Pennsylvania donor systems breached via social engineering

University of Pennsylvania · United States

The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.

Credential Phishing Portal
Confirmed2 sources
October 14, 2025·ConsumerCampaign

Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds

Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign) · Cambodia

On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.

Romance / Investment Scam
$15.0B assets seizedReported2 sources
September 18, 2025·Other

US and UK charge Scattered Spider pair tied to $115M in ransom payments

47 US organisations including healthcare, transport and technology firms · United States

On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.

Help Desk Impersonation
$115.0M multi-victim totalConfirmed2 sources
September 16, 2025·TechnologyCampaign

Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service

Microsoft 365 customers in 94 countries, including US healthcare organisations · United States

Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.

Credential Phishing PortalConfirmed AI-enabled
5.0K affectedConfirmed2 sources
September 8, 2025·ConsumerCampaign

US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud

US, European and Chinese scam victims (multi-victim campaign) · Myanmar and Cambodia

On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.

Fake Job Offer / Recruitment Lure
$10.0B multi-victim totalConfirmed2 sources
September 2025·Manufacturing

Stellantis confirms customer data stolen from Salesforce platform

Stellantis · Netherlands

Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.

Vishing (Voice Phishing)
Reported2 sources
September 2025·Retail

Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft

Kering (Gucci, Balenciaga, Alexander McQueen) · France

Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.

Vishing (Voice Phishing)
Reported2 sources
August 6, 2025·Technology

Workday discloses CRM breach after social engineering of employees

Workday · United States

Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.

Vishing (Voice Phishing)
Confirmed2 sources
August 2025·Technology

North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs

US Fortune 500 technology companies employing fraudulent remote workers · United States

In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.

Fake IT Worker InfiltrationConfirmed AI-enabled
Reported2 sources
August 2025·Other

Claude Code used to automate extortion of at least 17 organisations

At least 17 organisations across healthcare, emergency services, government and religious institutions · United States

Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.

Credential Phishing PortalConfirmed AI-enabled
Reported2 sources
August 2025·Transportation & Logistics

Air France and KLM disclose breach of third-party customer service platform

Air France-KLM · France

Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Retail

Chanel notifies US clients after third-party client-care database breach

Chanel · United States

Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Retail

Pandora warns customers after third-party platform breach

Pandora A/S · Denmark

Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Cryptocurrency

Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts

Cryptocurrency holders and companies targeted by the group · United States

A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.

SIM Swap
$13.0M funds lostConfirmed2 sources
August 2025·OtherCampaign

Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud

Approximately 88,000 victims across 18 African countries and the UK · Multiple

Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.

Business Email Compromise
$485.0M multi-victim totalConfirmed2 sources
July 28, 2025·Financial Services

TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs

TransUnion · United States

Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.

Vishing (Voice Phishing)
4.4M affectedReported2 sources
July 24, 2025·Technology

Cisco confirms vishing call gave attacker access to its third-party CRM instance

Cisco Systems · United States

Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.

Vishing (Voice Phishing)
Confirmed2 sources
July 24, 2025·Cryptocurrency

Crypto exchange WOO X loses $14 million after staff member phished

WOO X · Taiwan

Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.

Spear Phishing (Email)
$14.0M funds lostConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.