Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 98 entries · page 3 of 5
April 1, 2024·Technology

Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs

Cisco Duo (via an unnamed telephony supplier) · United States

Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.

Credential Phishing Portal
Confirmed1 source
February 19, 2024·Government

Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected

Los Angeles County Department of Public Health · United States

The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.

Credential Phishing Portal
200K affectedConfirmed2 sources
January 2024·ConsumerCampaign

AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads

Multiple US consumers; brands Taylor Swift and Le Creuset impersonated · United States

In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources
2024·OtherBenchmark

FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)

Aggregate: U.S. and international BEC victims reporting to FBI IC3 · United States

The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.

Business Email Compromise
$2.8B multi-victim totalConfirmed2 sources
December 14, 2023·Cryptocurrency

Ledger Connect Kit poisoned after a former employee's npm account was phished

Ledger SAS · France

On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.

Spear Phishing (Email)
$600K funds lostConfirmed3 sources
August 27, 2023·Technology

Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee

Retool · United States

Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.

Smishing (SMS)Confirmed AI-enabled
27 affectedConfirmed4 sources
August 2023·Energy & UtilitiesCampaign

QR code phishing campaign targets a major US energy company's Microsoft logins

Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets) · United States

Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.

QR Code PhishingAttempt blocked
Confirmed3 sources
August 2023·TechnologyCampaign

EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts

More than 100 organisations worldwide (Proofpoint-tracked campaign) · Global

Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.

Credential Phishing Portal
Confirmed2 sources
May 8, 2023·Technology

Dragos intrusion began with the hijacked personal email of an employee due to start work

Dragos · United States

Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.

Fake Job Offer / Recruitment LureAttempt blocked
Confirmed2 sources
February 5, 2023·Technology

Reddit source code stolen via a phishing site cloning its intranet gateway

Reddit · United States

Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.

Credential Phishing Portal
Confirmed3 sources
January 11, 2023·Technology

Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers

Mailchimp (Intuit) · United States

Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.

Help Desk Impersonation
Confirmed7 sources
October 14, 2022·Technology

Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing

Dropbox · United States

Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.

Credential Phishing Portal
Confirmed3 sources
October 2022·Technology

Zendesk breach followed successful SMS phishing of employees

Zendesk · United States

Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.

Smishing (SMS)
Reported3 sources
October 2022·Retail

Bed Bath & Beyond discloses data breach to SEC after an employee was phished

Bed Bath & Beyond · United States

Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.

Credential Phishing Portal
Confirmed2 sources
October 2022·Cryptocurrency

3Commas users phished for API keys, leading to unauthorised trades on FTX accounts

3Commas users (with linked FTX and Binance accounts) · Estonia

In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.

Credential Phishing Portal
$6.0M multi-victim totalReported2 sources
September 16, 2022·TechnologyCampaign

GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials

GitHub users and customer organisations (GitHub-reported campaign) · United States

GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.

Credential Phishing Portal
Confirmed2 sources
August 25, 2022·Transportation & Logistics

DoorDash customer data exposed through phished third-party vendor employees

DoorDash · United States

DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.

Vendor / Supply Chain Impersonation
Confirmed3 sources
August 4, 2022·Technology

Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers

Twilio · United States

In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.

Smishing (SMS)
Confirmed4 sources
August 3, 2022·Technology

Klaviyo employee phished; attacker used internal tools to take crypto mailing lists

Klaviyo · United States

Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.

Credential Phishing Portal
Confirmed2 sources
August 2022·TechnologyCampaign

0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations

Over 130 organisations targeted (Group-IB tracked campaign) · United States

Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.

Smishing (SMS)
9.9K affectedConfirmed2 sources
July 20, 2022·Technology

Cloudflare blocks the same SMS phishing attack that breached Twilio

Cloudflare · United States

On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.

Smishing (SMS)Attempt blocked
Confirmed3 sources
July 12, 2022·TechnologyCampaign

Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations

More than 10,000 organisations targeted (Microsoft-tracked campaign) · Global

Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.

Credential Phishing Portal
Confirmed2 sources
July 2022·Transportation & Logistics

American Airlines discloses breach after phishing compromised employee mailboxes

American Airlines · United States

American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.

Credential Phishing Portal
1.7K affectedConfirmed2 sources
May 2022·Government

Ghostwriter credential phishing against Ukrainian government and military accounts

Ukrainian government and military personnel · Ukraine

Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.

Credential Phishing PortalAttempt blocked
Confirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Credential+Phishing+Portal.