Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport
Wiz · United States
Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.
Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring
Men across Asia targeted through dating apps · Hong Kong
Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.
DPRK actor posing as a former contractor took $50M from Radiant Capital
Radiant Capital · Unknown
Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.
Transport for London hit by Scattered Spider teens in a £29m intrusion
Transport for London · United Kingdom
Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.
US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM
Office of US Senator Ben Cardin, Senate Foreign Relations Committee · United States
In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.
Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin
An individual Genesis creditor in Washington, D.C. · United States
On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.
Iran's APT42 phishes Israeli and US officials with think-tank impersonation
Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States
On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.
Orion S.A. discloses $60 million loss from fraudulently induced wire transfers
Orion S.A. · United States
Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.
Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients
Michigan Medicine (University of Michigan) · United States
Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.
WazirX signers approved a spoofed transaction and lost $235M
WazirX · India
Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.
KnowBe4 hired a North Korean fake IT worker who loaded malware on day one
KnowBe4 · United States
Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.
Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question
Ferrari · Italy
In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.
Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta
Multiple organisations (campaign) · Multiple
Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.
Ascension ransomware attack began when an employee downloaded a malicious file
Ascension · United States
Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.
WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read
WPP · United Kingdom
WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.
LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft
DMM Bitcoin, via wallet software vendor Ginco · Japan
Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.
Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks
US drivers and toll customers (multi-victim campaign) · United States
On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.
Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs
Cisco Duo (via an unnamed telephony supplier) · United States
Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.
LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO
LastPass · United States
On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.
Munchables loses $62.5M to a developer it hired who was linked to North Korea
Munchables (NFT game on Blast) · Unknown
Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.
Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected
Los Angeles County Department of Public Health · United States
The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.
Arup Hong Kong office loses about $25 million in deepfake video call scam
Arup Group (Hong Kong office) · Hong Kong
In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.
SIM swap of the SEC's X account posted a fake Bitcoin ETF approval
U.S. Securities and Exchange Commission · United States
On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.
AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads
Multiple US consumers; brands Taylor Swift and Le Creuset impersonated · United States
In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.