Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 8 of 80 entries · page 4 of 4
September 2014·Consumer

Celebrity iCloud photo theft: 600 victims phished with fake Apple and Google emails

Celebrities and private individuals with Apple iCloud and Google accounts · United States

The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.

Credential Phishing Portal
600 affectedConfirmed1 source
May 2014·Healthcare

Premera Blue Cross breach began with a spear-phishing email, 10.4 million affected

Premera Blue Cross · United States

Attackers compromised Premera Blue Cross in May 2014 and remained undetected for about nine months until January 2015. The intrusion exposed the protected health information of roughly 10.4 million individuals, including names, dates of birth, Social Security numbers, bank account details and clinical information. The HHS Office for Civil Rights, describing the incident, stated that the entry point was a spear-phishing email that installed malware.

Spear Phishing (Email)
$6.8M business impact10.4M affectedConfirmed2 sources
2014·Technology

Yahoo network breached via spear-phishing email, 500 million accounts stolen

Yahoo! Inc. · United States

In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.

Spear Phishing (Email)
500.0M affectedReported2 sources
December 2013·Retail

Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical

Target Corporation · United States

Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.

Vendor / Supply Chain Impersonation
110.0M affectedReported3 sources
April 23, 2013·Media & Entertainment

AP Twitter account hijacked, fake White House bombing tweet jolts markets

The Associated Press · United States

On 23 April 2013 the Associated Press's main Twitter account posted a false report of two explosions at the White House injuring President Obama. The Dow Jones Industrial Average dropped roughly 143 points in minutes before recovering once AP disavowed the tweet. AP said the account takeover was preceded by phishing attempts against its corporate network; the Syrian Electronic Army claimed responsibility, a claim that was not independently corroborated at the time.

Spear Phishing (Email)
Reported2 sources
2013·Technology

Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million

Google LLC and Facebook, Inc. · United States

From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.

Vendor / Supply Chain Impersonation
$120.0M funds lostConfirmed6 sources
April 2011·Professional Services

Epsilon email marketing breach exposes address lists of banks and retailers

Epsilon Data Management and other email service providers · United States

In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.

Spear Phishing (Email)
$2.0M criminal proceeds1.0B affectedConfirmed1 source
March 2011·Technology

RSA SecurID breach begins with '2011 Recruitment Plan' spear phishing email

RSA Security (EMC) · United States

In March 2011 attackers stole information related to RSA's SecurID two-factor authentication product after two small groups of RSA employees were sent spear phishing emails carrying a booby-trapped Excel attachment. RSA executive Uri Rivner publicly described the lure email as being titled '2011 Recruitment Plan.' The stolen SecurID data was subsequently used in attempted intrusions at US defense contractors, and RSA offered to replace tokens for customers.

Spear Phishing (Email)
$66.0M business impactConfirmed3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Spear+Phishing+%28Email%29.