Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 4 of 12
July 24, 2025·Technology

Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm

More than 300 US companies (victims of the fake-worker scheme) · United States

A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.

Fake IT Worker Infiltration
$17.0M criminal proceedsConfirmed2 sources
July 22, 2025·HealthcareCampaign

Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access

Multiple businesses and critical infrastructure organisations (campaign) · Multiple

A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.

Watering Hole / Malvertising
Confirmed3 sources
July 16, 2025·Financial Services

Allianz Life's Salesforce CRM emptied after social engineering

Allianz Life Insurance Company of North America · United States

Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.

Vishing (Voice Phishing)Suspected AI-enabled
1.1M affectedConfirmed4 sources
July 1, 2025·Transportation & Logistics

Qantas contact centre platform breached after help desk tricked into adding MFA

Qantas Airways · Australia

Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.

Help Desk Impersonation
5.7M affectedConfirmed4 sources
July 2025·Financial Services

Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility

HPS Investment Partners (BlackRock) · United States

HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.

Vendor / Supply Chain Impersonation
$400.0M funds lostReported3 sources
July 2025·Retail

LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave

LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.) · France

Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.

Vishing (Voice Phishing)
Reported2 sources
July 2025·OtherCampaign

Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware

US retail, airline, transportation and insurance organisations · United States

Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.

Help Desk Impersonation
Confirmed2 sources
June 30, 2025·TechnologyCampaign

US sweep seizes 200 computers from North Korean IT worker laptop farms

More than 100 US companies, including many Fortune 500 firms · United States

On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.

Fake IT Worker Infiltration
Confirmed2 sources
June 26, 2025·Transportation & Logistics

Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector

Hawaiian Airlines · United States

Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.

Help Desk Impersonation
Reported1 source
June 18, 2025·ConsumerCampaign

DOJ moves to forfeit $225M in crypto traced to pig butchering victims

US consumers (multi-victim campaign) · United States

On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.

Romance / Investment Scam
$19.4M multi-victim total434 affectedConfirmed3 sources
June 13, 2025·Transportation & Logistics

WestJet breach of 1.2 million passengers began with a help desk password reset

WestJet · Canada

Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.

Help Desk Impersonation
1.2M affectedConfirmed2 sources
June 12, 2025·Financial Services

Aflac breached in insurance-sector social engineering campaign; 22.6M affected

Aflac · United States

Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.

Vishing (Voice Phishing)
22.6M affectedConfirmed5 sources
June 4, 2025·Other

UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app

Approximately 20 Salesforce customer organisations, later including Google · Multiple

Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.

Vishing (Voice Phishing)
Confirmed1 source
June 2025·Cryptocurrency

BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware

Employee of a cryptocurrency foundation (Web3 sector) · United States

In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
June 2025·Government

Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers

US State Department; three foreign ministers, a US governor and a member of Congress · United States

In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
June 2025·Technology

Google's own Salesforce instance hit by UNC6040 IT-support vishing

Google · United States

Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed5 sources
June 2025·Financial Services

Erie Insurance hit in Scattered Spider help desk campaign against insurers

Erie Insurance · United States

Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.

Help Desk Impersonation
Reported1 source
June 2025·Financial Services

Philadelphia Insurance Companies disclosed breach in insurer-focused campaign

Philadelphia Insurance Companies · United States

Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.

Help Desk Impersonation
Reported1 source
June 2025·NonprofitCampaign

Russian state-linked actors phish app-specific passwords from academics and critics

Academics, journalists and Russia critics (individuals not named) · Multiple

Google Threat Intelligence and Citizen Lab jointly documented a campaign in June 2025 in which a Russian government-linked cluster tracked as UNC6293 persuaded targets to create Google application-specific passwords and hand them over. Victims included prominent academics and critics of Russia. The technique bypassed multi-factor authentication entirely and gave the attackers durable mailbox access.

Spear Phishing (Email)
Confirmed2 sources
May 29, 2025·Financial Services

Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers

Farmers Insurance · United States

Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.

Vishing (Voice Phishing)
1.1M affectedReported2 sources
May 21, 2025·Other

3AM ransomware affiliate used email bombing plus spoofed IT support calls

Unnamed Sophos client · Unknown

Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
May 19, 2025·Financial ServicesCampaign

UK 'safe account' bank and police impersonation drives £450.7M in APP fraud

UK banking customers (multi-victim campaign) · United Kingdom

UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.

Vishing (Voice Phishing)
186K affectedConfirmed2 sources
May 15, 2025·GovernmentCampaign

FBI warns of AI voice-cloning campaign impersonating senior US officials

Current and former senior US federal and state officials and their contacts · United States

On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
May 15, 2025·Cryptocurrency

Bribed overseas support agents leaked Coinbase data; $20M extortion refused

Coinbase · United States

Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.

Insider Recruitment
69K affectedConfirmed3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.