Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 100 entries · page 3 of 5
June 13, 2025·Transportation & Logistics

WestJet breach of 1.2 million passengers began with a help desk password reset

WestJet · Canada

Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.

Help Desk Impersonation
1.2M affectedConfirmed2 sources
June 12, 2025·Financial Services

Aflac breached in insurance-sector social engineering campaign; 22.6M affected

Aflac · United States

Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.

Vishing (Voice Phishing)
22.6M affectedConfirmed5 sources
June 4, 2025·Other

UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app

Approximately 20 Salesforce customer organisations, later including Google · Multiple

Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.

Vishing (Voice Phishing)
Confirmed1 source
June 2025·Technology

Google's own Salesforce instance hit by UNC6040 IT-support vishing

Google · United States

Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed5 sources
June 2025·Financial Services

Erie Insurance hit in Scattered Spider help desk campaign against insurers

Erie Insurance · United States

Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.

Help Desk Impersonation
Reported1 source
June 2025·Financial Services

Philadelphia Insurance Companies disclosed breach in insurer-focused campaign

Philadelphia Insurance Companies · United States

Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.

Help Desk Impersonation
Reported1 source
May 29, 2025·Financial Services

Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers

Farmers Insurance · United States

Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.

Vishing (Voice Phishing)
1.1M affectedReported2 sources
May 21, 2025·Other

3AM ransomware affiliate used email bombing plus spoofed IT support calls

Unnamed Sophos client · Unknown

Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
May 19, 2025·Financial ServicesCampaign

UK 'safe account' bank and police impersonation drives £450.7M in APP fraud

UK banking customers (multi-victim campaign) · United Kingdom

UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.

Vishing (Voice Phishing)
186K affectedConfirmed2 sources
May 15, 2025·GovernmentCampaign

FBI warns of AI voice-cloning campaign impersonating senior US officials

Current and former senior US federal and state officials and their contacts · United States

On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
May 15, 2025·Cryptocurrency

Bribed overseas support agents leaked Coinbase data; $20M extortion refused

Coinbase · United States

Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.

Insider Recruitment
69K affectedConfirmed3 sources
May 1, 2025·Retail

Harrods restricts internet access after intrusion attempts in UK retail wave

Harrods · United Kingdom

Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.

Help Desk Impersonation
Alleged2 sources
May 2025·Government

AI voice impersonation of White House chief of staff Susie Wiles targets Republicans

The White House; senators, governors and business executives contacted · United States

In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.

Voice Clone / Audio DeepfakeSuspected AI-enabledAttempt blocked
Reported2 sources
May 2025·LegalCampaign

FBI warns Silent Ransom Group is callback-phishing US law firms

US law firms and legal services organisations (campaign) · United States

The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.

Callback Phishing (TOAD)
Confirmed3 sources
May 2025·Retail

Adidas customer data stolen through third-party customer service provider

Adidas · Germany

Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.

Vishing (Voice Phishing)
Reported2 sources
April 22, 2025·Retail

Marks & Spencer attack tied to social engineering of outsourced service desk

Marks & Spencer Group plc · United Kingdom

Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.

Help Desk Impersonation
Confirmed6 sources
April 2025·Retail

Co-op loses £206m of revenue and 6.5 million members' data to DragonForce

Co-operative Group · United Kingdom

The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.

Help Desk Impersonation
$275.0M business impact6.5M affectedConfirmed5 sources
March 5, 2025·ConsumerCampaign

25 Canadians charged over $21M grandparent scam targeting seniors in 40 states

Elderly US residents in more than 40 states (multi-victim campaign) · United States and Canada

On 5 March 2025 US authorities announced charges against 25 Canadian nationals over a grandparent scam run from call centers in and around Montreal that defrauded elderly people in more than 40 states of over $21 million. Twenty-three defendants were arrested on 4 March and two remained at large. Money was moved to Canada after cash pickups, sometimes through cryptocurrency, to obscure its source.

Vishing (Voice Phishing)
$21.0M multi-victim totalReported1 source
March 2025·CryptocurrencyCampaign

'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders

Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully · Multiple

From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.

Vishing (Voice Phishing)
Reported2 sources
February 2025·Consumer

AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman

Massimo Moratti and other Italian business leaders · Italy

In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
$1.0M funds lostReported3 sources
October 2024·Technology

Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport

Wiz · United States

Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
September 1, 2024·Transportation & Logistics

Transport for London hit by Scattered Spider teens in a £29m intrusion

Transport for London · United Kingdom

Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.

Help Desk Impersonation
$39.0M business impactReported2 sources
August 19, 2024·Cryptocurrency

Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin

An individual Genesis creditor in Washington, D.C. · United States

On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.

Vishing (Voice Phishing)
$243.0M funds lostReported2 sources
July 2024·Manufacturing

Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question

Ferrari · Italy

In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Reported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vishing+%28Voice+Phishing%29.