Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 7 of 55 entries · page 3 of 3
November 2018·Government

Cabarrus County, NC diverts $2.5 million school payment to BEC actors

Cabarrus County, North Carolina · United States

Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.

Vendor / Supply Chain Impersonation
$2.5M funds lostConfirmed1 source
2017·Other

Dublin Zoo defrauded of about €500,000 in invoice redirection scam

Dublin Zoo · Ireland

Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.

Vendor / Supply Chain Impersonation
Reported1 source
November 2016·GovernmentCampaign

GRU spear-phished election vendor VR Systems, then 122 local election officials

VR Systems and US local election administrators · United States

A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.

Credential Phishing Portal
Reported2 sources
June 5, 2015·Technology

Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise

Ubiquiti Networks · United States

In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.

Business Email Compromise
$46.7M funds lostConfirmed4 sources
June 2014·Other

Scoular Company wires $17.2 million after fake CEO and auditor emails

The Scoular Company · United States

In June 2014 the corporate controller of Omaha-based commodities trading firm The Scoular Company wired $17.2 million to a Chinese bank in three installments after receiving emails impersonating chief executive Chuck Elsea and the company's outside auditor at KPMG. The messages described a confidential international acquisition and demanded secrecy. The emails were sent from accounts associated with Germany, France and Israel using servers in Moscow.

Business Email Compromise
$17.2M funds lostConfirmed1 source
December 2013·Retail

Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical

Target Corporation · United States

Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.

Vendor / Supply Chain Impersonation
110.0M affectedReported3 sources
2013·Technology

Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million

Google LLC and Facebook, Inc. · United States

From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.

Vendor / Supply Chain Impersonation
$120.0M funds lostConfirmed6 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vendor+%2F+Supply+Chain+Impersonation.