Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 6 of 12
October 2024·Technology

Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport

Wiz · United States

Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
October 2024·ConsumerCampaign

Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring

Men across Asia targeted through dating apps · Hong Kong

Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.

Romance / Investment ScamConfirmed AI-enabled
$46.0M multi-victim totalConfirmed2 sources
October 2024·Cryptocurrency

DPRK actor posing as a former contractor took $50M from Radiant Capital

Radiant Capital · Unknown

Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.

Vendor / Supply Chain Impersonation
$50.0M funds lostReported2 sources
September 1, 2024·Transportation & Logistics

Transport for London hit by Scattered Spider teens in a £29m intrusion

Transport for London · United Kingdom

Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.

Help Desk Impersonation
$39.0M business impactReported2 sources
September 2024·Government

US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM

Office of US Senator Ben Cardin, Senate Foreign Relations Committee · United States

In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.

Deepfake Video CallSuspected AI-enabledAttempt blocked
Reported2 sources
August 19, 2024·Cryptocurrency

Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin

An individual Genesis creditor in Washington, D.C. · United States

On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.

Vishing (Voice Phishing)
$243.0M funds lostReported2 sources
August 14, 2024·Government

Iran's APT42 phishes Israeli and US officials with think-tank impersonation

Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States

On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.

Credential Phishing Portal
Confirmed1 source
August 10, 2024·Manufacturing

Orion S.A. discloses $60 million loss from fraudulently induced wire transfers

Orion S.A. · United States

Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.

Business Email Compromise
$60.0M funds lostConfirmed2 sources
July 30, 2024·Healthcare

Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients

Michigan Medicine (University of Michigan) · United States

Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.

MFA Fatigue / Push Bombing
58K affectedConfirmed2 sources
July 18, 2024·Cryptocurrency

WazirX signers approved a spoofed transaction and lost $235M

WazirX · India

Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.

Vendor / Supply Chain Impersonation
$234.9M funds lostReported2 sources
July 15, 2024·Technology

KnowBe4 hired a North Korean fake IT worker who loaded malware on day one

KnowBe4 · United States

Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed3 sources
July 2024·Manufacturing

Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question

Ferrari · Italy

In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Reported2 sources
May 15, 2024·OtherCampaign

Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta

Multiple organisations (campaign) · Multiple

Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.

Vishing (Voice Phishing)
Confirmed3 sources
May 8, 2024·Healthcare

Ascension ransomware attack began when an employee downloaded a malicious file

Ascension · United States

Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.

Spear Phishing (Email)
5.6M affectedConfirmed2 sources
May 2024·Media & Entertainment

WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read

WPP · United Kingdom

WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.

Deepfake Video CallConfirmed AI-enabledAttempt blocked
Confirmed2 sources
May 2024·Cryptocurrency

LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft

DMM Bitcoin, via wallet software vendor Ginco · Japan

Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.

Fake Job Offer / Recruitment Lure
$308.0M funds lostConfirmed2 sources
April 12, 2024·Transportation & LogisticsCampaign

Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks

US drivers and toll customers (multi-victim campaign) · United States

On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.

Smishing (SMS)
2.0K affectedConfirmed1 source
April 1, 2024·Technology

Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs

Cisco Duo (via an unnamed telephony supplier) · United States

Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.

Credential Phishing Portal
Confirmed1 source
April 2024·Technology

LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO

LastPass · United States

On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed3 sources
March 26, 2024·Cryptocurrency

Munchables loses $62.5M to a developer it hired who was linked to North Korea

Munchables (NFT game on Blast) · Unknown

Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.

Fake IT Worker Infiltration
$62.5M funds lostReported2 sources
February 19, 2024·Government

Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected

Los Angeles County Department of Public Health · United States

The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.

Credential Phishing Portal
200K affectedConfirmed2 sources
February 2024·Professional Services

Arup Hong Kong office loses about $25 million in deepfake video call scam

Arup Group (Hong Kong office) · Hong Kong

In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.

Deepfake Video CallConfirmed AI-enabled
$25.0M funds lostConfirmed5 sources
January 9, 2024·Government

SIM swap of the SEC's X account posted a fake Bitcoin ETF approval

U.S. Securities and Exchange Commission · United States

On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.

SIM Swap
Confirmed2 sources
January 2024·ConsumerCampaign

AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads

Multiple US consumers; brands Taylor Swift and Le Creuset impersonated · United States

In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.