Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 5 of 12
May 8, 2025·Cryptocurrency

Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft

BitoPro · Taiwan

Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.

Spear Phishing (Email)
$11.5M funds lostReported2 sources
May 1, 2025·Retail

Harrods restricts internet access after intrusion attempts in UK retail wave

Harrods · United Kingdom

Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.

Help Desk Impersonation
Alleged2 sources
May 2025·Government

AI voice impersonation of White House chief of staff Susie Wiles targets Republicans

The White House; senators, governors and business executives contacted · United States

In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.

Voice Clone / Audio DeepfakeSuspected AI-enabledAttempt blocked
Reported2 sources
May 2025·Cryptocurrency

Kraken advanced a North Korean fake job applicant to unmask his tradecraft

Kraken (Payward, Inc.) · United States

Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.

Fake IT Worker InfiltrationAttempt blocked
Confirmed2 sources
May 2025·LegalCampaign

FBI warns Silent Ransom Group is callback-phishing US law firms

US law firms and legal services organisations (campaign) · United States

The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.

Callback Phishing (TOAD)
Confirmed3 sources
May 2025·Cryptocurrency

Binance and Kraken block bribery attempts aimed at support staff

Binance and Kraken · United States

In the weeks around the Coinbase insider breach, the same style of attack was attempted against Binance and Kraken. Bloomberg-sourced reporting said threat actors approached customer support staff at both exchanges over Telegram and offered bribes for system access and customer data. Both exchanges detected and blocked the approaches, and neither reported any user data exposure.

Insider RecruitmentAttempt blocked
Reported1 source
May 2025·Retail

Adidas customer data stolen through third-party customer service provider

Adidas · Germany

Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.

Vishing (Voice Phishing)
Reported2 sources
April 22, 2025·Retail

Marks & Spencer attack tied to social engineering of outsourced service desk

Marks & Spencer Group plc · United Kingdom

Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.

Help Desk Impersonation
Confirmed6 sources
April 2025·TechnologyCampaign

North Korean operatives adopt real-time deepfakes to pass remote job interviews

Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate · United States

In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed2 sources
April 2025·Retail

Co-op loses £206m of revenue and 6.5 million members' data to DragonForce

Co-operative Group · United Kingdom

The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.

Help Desk Impersonation
$275.0M business impact6.5M affectedConfirmed5 sources
March 17, 2025·Technology

Rippling sues Deel over a manager allegedly recruited as a corporate spy

Rippling · United States

On March 17, 2025 Rippling sued rival HR and payroll company Deel in the Northern District of California, alleging Deel cultivated a Rippling employee as a spy. The complaint says the employee searched Rippling systems for 'Deel' an average of 23 times a day over four months and accessed Slack channels more than 6,000 times without business justification, funnelling sales pipeline data, pricing, customer churn lists and employee contact details to Deel. Deel denies wrongdoing and the litigation continues.

Insider Recruitment
Alleged2 sources
March 5, 2025·ConsumerCampaign

25 Canadians charged over $21M grandparent scam targeting seniors in 40 states

Elderly US residents in more than 40 states (multi-victim campaign) · United States and Canada

On 5 March 2025 US authorities announced charges against 25 Canadian nationals over a grandparent scam run from call centers in and around Montreal that defrauded elderly people in more than 40 states of over $21 million. Twenty-three defendants were arrested on 4 March and two remained at large. Money was moved to Canada after cash pickups, sometimes through cryptocurrency, to obscure its source.

Vishing (Voice Phishing)
$21.0M multi-victim totalReported1 source
March 3, 2025·Healthcare

Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients

Arizona Arthritis and Rheumatology Associates · United States

Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.

Credential Phishing Portal
5.5K affectedConfirmed1 source
March 3, 2025·Healthcare

Monongalia Health System email phishing breach affects 4,895 patients

Monongalia Health System (Mon Health) · United States

West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.

Credential Phishing Portal
4.9K affectedConfirmed1 source
March 2025·Other

Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO

Unnamed multinational firm, Singapore office · Singapore

On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.

Deepfake Video CallConfirmed AI-enabled
$499K funds lostConfirmed1 source
March 2025·CryptocurrencyCampaign

'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders

Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully · Multiple

From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.

Vishing (Voice Phishing)
Reported2 sources
February 21, 2025·Cryptocurrency

Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI

Bybit · United Arab Emirates

On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.

Vendor / Supply Chain Impersonation
$1.5B funds lostConfirmed5 sources
February 13, 2025·GovernmentCampaign

Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts

Multiple government, NGO, defence and energy organisations · Multiple

Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.

Spear Phishing (Email)
Confirmed2 sources
February 2025·Consumer

AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman

Massimo Moratti and other Italian business leaders · Italy

In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
$1.0M funds lostReported3 sources
January 2025·ConsumerCampaign

Hong Kong arrests 31 in second deepfake romance fraud ring targeting Southeast Asia

Victims in Taiwan, Singapore and Malaysia · Hong Kong

Hong Kong police arrested 31 people on 2 and 3 January 2025 over a deepfake-enabled romance and investment fraud syndicate that operated from two premises in Kowloon Bay and took more than HK$34 million (about US$4.37 million) from victims in Taiwan, Singapore and Malaysia. Members were trained to approach targets on dating apps using online photographs of attractive people combined with deepfake technology. It was the second major deepfake fraud bust by Hong Kong authorities in three months.

Romance / Investment ScamConfirmed AI-enabled
$4.4M multi-victim totalConfirmed1 source
January 2025·Financial Services

VC firm Insight Partners breached through social engineering attack

Insight Partners · United States

New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.

Spear Phishing (Email)
Confirmed2 sources
2025·OtherCampaign

ClickFix fake-CAPTCHA social engineering floods the threat landscape

Multiple organisations and consumers (technique) · Multiple

Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.

Watering Hole / Malvertising
Confirmed3 sources
December 3, 2024·ConsumerBenchmark

FBI warns criminals are using generative AI to scale voice-clone and identity fraud

US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign) · United States

On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed1 source
November 2024·ConsumerCampaign

Deepfake Elon Musk videos drive crypto investment scams against US consumers

Multiple US consumers · United States

By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.