Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 98 entries · page 4 of 5
April 3, 2022·Cryptocurrency

Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds

SatoshiLabs (Trezor), via email provider Mailchimp · Czech Republic

Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.

Vendor / Supply Chain Impersonation
Confirmed2 sources
March 18, 2022·Technology

HubSpot employee account compromised, exposing customer data at crypto firms

HubSpot · United States

On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.

Credential Phishing Portal
Confirmed2 sources
March 2022·Telecom

LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code

T-Mobile US · United States

Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.

SIM Swap
Confirmed2 sources
July 15, 2020·Technology

Twitter's July 2020 account takeover started with phone spear phishing of employees

Twitter, Inc. · United States

On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.

Vishing (Voice Phishing)
$118K criminal proceeds130 affectedConfirmed6 sources
May 2020·Government

Scattered Canary floods Washington's pandemic unemployment system with fake claims

Washington State Employment Security Department · United States

In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.

Credential Phishing Portal
Reported1 source
April 23, 2020·HealthcareCampaign

WHO impersonation surge during COVID-19 targets donors and staff

World Health Organization and the general public (multi-victim campaign) · Global

On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.

Spear Phishing (Email)
450 affectedConfirmed2 sources
April 6, 2020·Healthcare

Magellan Health ransomware began with a phishing email impersonating a client

Magellan Health · United States

Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.

Spear Phishing (Email)
$1.4M business impact365K affectedConfirmed2 sources
September 10, 2019·OtherCampaign

Operation reWired: 281 arrested worldwide in BEC crackdown

Multiple businesses and individuals (global) · United States

Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.

Business Email CompromiseAttempt blocked
Confirmed3 sources
July 2019·Education

Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow

Lancaster University · United Kingdom

Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.

Credential Phishing Portal
13K affectedConfirmed2 sources
May 9, 2019·Healthcare

Presbyterian Healthcare Services phishing exposes data on 183,000 patients

Presbyterian Healthcare Services · United States

New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.

Credential Phishing Portal
183K affectedConfirmed2 sources
April 2019·Technology

Wipro employee accounts phished and used to attack the IT giant's own customers

Wipro Limited · India

In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.

Credential Phishing Portal
Confirmed2 sources
January 8, 2019·Government

Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients

Oregon Department of Human Services · United States

On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.

Credential Phishing Portal
645K affectedConfirmed2 sources
October 2018·Education

San Diego Unified staff phished, exposing 500,000 students, parents and employees

San Diego Unified School District · United States

San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.

Credential Phishing Portal
500K affectedConfirmed2 sources
April 2018·Manufacturing

Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud

Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom

Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.

Business Email Compromise
$11.0M funds lostConfirmed1 source
March 2018·Healthcare

UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients

UnityPoint Health · United States

UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.

Business Email Compromise
$2.8M business impact1.4M affectedConfirmed2 sources
May 2017·Nonprofit

Save the Children Federation loses nearly $1 million in charity BEC fraud

Save the Children Federation, Inc. · United States

In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.

Business Email Compromise
$1.0M funds lostConfirmed1 source
2017·Energy & Utilities

Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign

Wolf Creek Nuclear Operating Corporation · United States

A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.

Spear Phishing (Email)
Confirmed2 sources
November 2016·GovernmentCampaign

GRU spear-phished election vendor VR Systems, then 122 local election officials

VR Systems and US local election administrators · United States

A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.

Credential Phishing Portal
Reported2 sources
March 19, 2016·Government

John Podesta and DNC staff phished by fake Google security alerts in 2016

Hillary for America campaign and the Democratic National Committee · United States

On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.

Credential Phishing Portal
Confirmed3 sources
2016·Government

GRU spearphishing of the Clinton campaign, DNC and DCCC

Hillary Clinton presidential campaign, Democratic National Committee and Democratic Congressional Campaign Committee · United States

A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.

Spear Phishing (Email)
Confirmed1 source
August 17, 2015·GovernmentCampaign

IRS 'Get Transcript' abused to pull 334,000 taxpayer transcripts

US taxpayers via the Internal Revenue Service (multi-victim campaign) · United States

In August 2015 the IRS disclosed that criminals had successfully retrieved prior-year tax transcripts for roughly 334,000 taxpayers through its online Get Transcript service, having attempted access against about 610,000 taxpayers. The Treasury Inspector General later put the potentially compromised total higher. Attackers defeated the service's knowledge-based authentication rather than breaching IRS systems.

Credential Phishing Portal
334K affectedConfirmed1 source
November 24, 2014·Media & Entertainment

Sony Pictures destructive hack preceded by fake Apple ID phishing emails

Sony Pictures Entertainment · United States

On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.

Credential Phishing Portal
Reported3 sources
September 2014·Consumer

Celebrity iCloud photo theft: 600 victims phished with fake Apple and Google emails

Celebrities and private individuals with Apple iCloud and Google accounts · United States

The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.

Credential Phishing Portal
600 affectedConfirmed1 source
2014·Technology

Yahoo network breached via spear-phishing email, 500 million accounts stolen

Yahoo! Inc. · United States

In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.

Spear Phishing (Email)
500.0M affectedReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Credential+Phishing+Portal.