Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta
Multiple organisations (campaign) · Multiple
Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.
LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO
LastPass · United States
On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.
AI-cloned Biden robocall told New Hampshire voters to skip the primary
New Hampshire primary voters · United States
On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.
FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings
US senior citizens (multi-victim campaign) · United States
On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.
MGM Resorts shut down for ten days after a help desk social engineering call
MGM Resorts International · United States
MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.
Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee
Retool · United States
Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.
Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered
Caesars Entertainment · United States
Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.
Clorox attack traced to help desk agents resetting passwords without verification
The Clorox Company · United States
Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.
Okta warns of a coordinated campaign against US customers' IT service desks
Multiple US-based Okta customer organizations · United States
Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.
AI voice clone of teenage daughter used in Arizona virtual kidnapping attempt
Jennifer DeStefano, a private individual in Scottsdale, Arizona · United States
Jennifer DeStefano of Scottsdale, Arizona received a call in which she heard what she believed was her 15-year-old daughter crying, followed by a man claiming to hold the girl and demanding a US$1 million ransom, later reduced to US$50,000 in cash. While she kept the caller talking, other parents reached her husband, who confirmed the daughter was safe at home. No money changed hands. DeStefano described the incident in written testimony to the US Senate Judiciary Committee in June 2023, and it became one of the most cited AI voice-cloning cases in US policy debate.
Coinbase employee phished by SMS then talked through by a fake IT caller
Coinbase · United States
In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.
FTC: business and government impersonation scams hit $1.1 billion in 2023
US consumers (multi-victim campaign) · United States
An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.
Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers
Twilio · United States
In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.
0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations
Over 130 organisations targeted (Group-IB tracked campaign) · United States
Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.
Cisco breached after vishing and MFA fatigue against an employee
Cisco Systems · United States
Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.
FTC data: $147.8M in gift card fraud driven by government and business impersonators
US consumers (multi-victim campaign) · United States
An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.
Robinhood support employee socially engineered by phone; 7 million customers exposed
Robinhood Markets · United States
On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.
Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash
GoDaddy (registrar); Liquid.com and NiceHash · United States
Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.
Twitter's July 2020 account takeover started with phone spear phishing of employees
Twitter, Inc. · United States
On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.
Cloned company director's voice used in US$35M bank transfer fraud
Unnamed company and its bank; investigated by UAE authorities · United Arab Emirates
In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.
UK energy firm CEO tricked by AI voice clone of German parent-company boss
Unnamed UK-based energy company (subsidiary of a German parent) · United Kingdom
In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.
Tecnimont India loses $18.6 million to fake CEO conference calls
Tecnimont SpA (Indian subsidiary, Maire Tecnimont group) · India
The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.
Virtual kidnapping ring extorts parents with staged ransom calls
Parents in Texas, California and Idaho (multi-victim campaign) · United States and Mexico
On 20 September 2018 Yanette Rodriguez Acosta of Houston was sentenced to 88 months in federal prison for conspiracy to commit wire fraud and money laundering in a virtual kidnapping extortion scheme. Co-conspirators in Mexico called victims in Texas, California and Idaho falsely claiming to have kidnapped their children and demanding ransom. The sentencing judge said the defendant showed gleeful disregard for victims while inflicting pain, fear and long-term effects for profit.
India-based IRS and USCIS impersonation call centers: 24 defendants sentenced
US consumers, many of them elderly (multi-victim campaign) · United States and India
On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vishing+%28Voice+Phishing%29.