Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 80 entries · page 3 of 4
April 6, 2020·Healthcare

Magellan Health ransomware began with a phishing email impersonating a client

Magellan Health · United States

Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.

Spear Phishing (Email)
$1.4M business impact365K affectedConfirmed2 sources
July 2019·Education

Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow

Lancaster University · United Kingdom

Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.

Credential Phishing Portal
13K affectedConfirmed2 sources
May 29, 2019·Government

Riviera Beach pays $600,000 ransom after an employee clicked a malicious email link

City of Riviera Beach, Florida · United States

The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.

Spear Phishing (Email)
$600K ransom paidConfirmed2 sources
May 9, 2019·Healthcare

Presbyterian Healthcare Services phishing exposes data on 183,000 patients

Presbyterian Healthcare Services · United States

New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.

Credential Phishing Portal
183K affectedConfirmed2 sources
March 19, 2019·Manufacturing

Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer

Norsk Hydro ASA · Norway

Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.

Vendor / Supply Chain Impersonation
$71.0M business impactReported3 sources
January 8, 2019·Government

Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients

Oregon Department of Human Services · United States

On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.

Credential Phishing Portal
645K affectedConfirmed2 sources
October 2018·Education

San Diego Unified staff phished, exposing 500,000 students, parents and employees

San Diego Unified School District · United States

San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.

Credential Phishing Portal
500K affectedConfirmed2 sources
April 2018·Manufacturing

Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud

Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom

Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.

Business Email Compromise
$11.0M funds lostConfirmed1 source
April 2018·Retail

FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards

Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor) · United States

In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.

Spear Phishing (Email)
5.0M affectedReported2 sources
April 2017·Hospitality

Chipotle payment card breach traced to FIN7 phishing emails backed by phone calls

Chipotle Mexican Grill · United States

Chipotle disclosed in May 2017 that point-of-sale malware had captured payment card track data at restaurants between 24 March and 18 April 2017, including cardholder name, card number, expiry date and verification code. The FBI attributed the intrusion to FIN7, naming Chipotle among the group's publicly disclosed US victims. FIN7 entered victim networks through phishing emails that employees opened, reinforced by follow-up phone calls.

Spear Phishing (Email)
Confirmed2 sources
February 2, 2017·EducationCampaign

IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits

US school districts, tribal organizations, nonprofits and employers (multi-victim campaign) · United States

In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.

Business Email Compromise
Confirmed1 source
2017·Energy & Utilities

Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign

Wolf Creek Nuclear Operating Corporation · United States

A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.

Spear Phishing (Email)
Confirmed2 sources
November 2016·GovernmentCampaign

GRU spear-phished election vendor VR Systems, then 122 local election officials

VR Systems and US local election administrators · United States

A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.

Credential Phishing Portal
Reported2 sources
August 2016·Manufacturing

Leoni AG Romanian subsidiary wires €40 million to fraudsters

Leoni AG (Bistrița, Romania subsidiary) · Romania

German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.

Business Email Compromise
$44.0M funds lostConfirmed2 sources
March 19, 2016·Government

John Podesta and DNC staff phished by fake Google security alerts in 2016

Hillary for America campaign and the Democratic National Committee · United States

On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.

Credential Phishing Portal
Confirmed3 sources
March 1, 2016·Technology

Seagate CEO-impersonation phish exposes every US employee's W-2

Seagate Technology · United States

On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.

Business Email Compromise
Confirmed2 sources
February 28, 2016·Technology

Snapchat payroll staff phished by fake CEO request for employee W-2s

Snapchat, Inc. · United States

On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.

Business Email Compromise
Confirmed1 source
February 2016·Financial Services

Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails

Bangladesh Bank (central bank of Bangladesh) · Bangladesh

In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.

Spear Phishing (Email)
$81.0M funds lostReported3 sources
January 2016·Manufacturing

Austrian aerospace supplier FACC loses about €50 million to CEO fraud

FACC AG · Austria

FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.

Business Email Compromise
$54.0M funds lostConfirmed3 sources
2016·Government

GRU spearphishing of the Clinton campaign, DNC and DCCC

Hillary Clinton presidential campaign, Democratic National Committee and Democratic Congressional Campaign Committee · United States

A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.

Spear Phishing (Email)
Confirmed1 source
December 23, 2015·Energy & Utilities

Ukraine power grid blackout of 2015 began with BlackEnergy spear phishing

Kyivoblenergo, Prykarpattyaoblenergo and Chernivtsioblenergo · Ukraine

On 23 December 2015 three Ukrainian regional electricity distribution companies were hit by a coordinated cyberattack that opened breakers at roughly 30 substations and left about 225,000 customers without power. The joint E-ISAC/SANS analysis found the intrusion began months earlier with spear phishing emails carrying malicious Office documents that installed BlackEnergy 3, which was used to harvest credentials for the operators' VPN and SCADA environments.

Spear Phishing (Email)
Confirmed3 sources
June 5, 2015·Technology

Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise

Ubiquiti Networks · United States

In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.

Business Email Compromise
$46.7M funds lostConfirmed4 sources
February 4, 2015·Healthcare

Anthem breach of 78.8 million records started with a spear phishing email

Anthem Inc. · United States

Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.

Spear Phishing (Email)
$115.0M business impact78.8M affectedConfirmed3 sources
November 24, 2014·Media & Entertainment

Sony Pictures destructive hack preceded by fake Apple ID phishing emails

Sony Pictures Entertainment · United States

On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.

Credential Phishing Portal
Reported3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Spear+Phishing+%28Email%29.