Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 7 of 12
January 2024·Government

AI-cloned Biden robocall told New Hampshire voters to skip the primary

New Hampshire primary voters · United States

On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
2024·OtherBenchmark

FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)

Aggregate: U.S. and international BEC victims reporting to FBI IC3 · United States

The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.

Business Email Compromise
$2.8B multi-victim totalConfirmed2 sources
December 14, 2023·Cryptocurrency

Ledger Connect Kit poisoned after a former employee's npm account was phished

Ledger SAS · France

On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.

Spear Phishing (Email)
$600K funds lostConfirmed3 sources
October 2023·Technology

Arizona laptop farm placed North Korean IT workers at 309 US companies

309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer · United States

From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.

Fake IT Worker Infiltration
$17.0M criminal proceeds68 affectedConfirmed2 sources
September 29, 2023·ConsumerCampaign

FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings

US senior citizens (multi-victim campaign) · United States

On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.

Tech Support Scam
$542.0M multi-victim total19K affectedConfirmed1 source
September 11, 2023·Gaming & Casino

MGM Resorts shut down for ten days after a help desk social engineering call

MGM Resorts International · United States

MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.

Help Desk Impersonation
$110.0M business impactReported4 sources
August 27, 2023·Technology

Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee

Retool · United States

Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.

Smishing (SMS)Confirmed AI-enabled
27 affectedConfirmed4 sources
August 19, 2023·Professional Services

SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data

Kroll · United States

Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.

SIM Swap
Confirmed2 sources
August 18, 2023·Gaming & Casino

Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered

Caesars Entertainment · United States

Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.

Vendor / Supply Chain Impersonation
$15.0M ransom paidConfirmed2 sources
August 11, 2023·Manufacturing

Clorox attack traced to help desk agents resetting passwords without verification

The Clorox Company · United States

Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.

Help Desk Impersonation
$380.0M business impactConfirmed5 sources
August 2023·TechnologyCampaign

Okta warns of a coordinated campaign against US customers' IT service desks

Multiple US-based Okta customer organizations · United States

Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.

Help Desk Impersonation
Confirmed2 sources
August 2023·Energy & UtilitiesCampaign

QR code phishing campaign targets a major US energy company's Microsoft logins

Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets) · United States

Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.

QR Code PhishingAttempt blocked
Confirmed3 sources
August 2023·TechnologyCampaign

EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts

More than 100 organisations worldwide (Proofpoint-tracked campaign) · Global

Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.

Credential Phishing Portal
Confirmed2 sources
July 22, 2023·Cryptocurrency

Fake recruiter's coding test cost payment processor CoinsPaid $37M

CoinsPaid · Estonia

Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.

Fake Job Offer / Recruitment Lure
$37.0M funds lostReported2 sources
May 8, 2023·Technology

Dragos intrusion began with the hijacked personal email of an employee due to start work

Dragos · United States

Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.

Fake Job Offer / Recruitment LureAttempt blocked
Confirmed2 sources
May 2023·Cryptocurrency

Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked

Bart Stephens, co-founder of Blockchain Capital · United States

Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.

SIM SwapAttempt blocked
$6.3M funds lostReported1 source
April 2023·Consumer

AI voice clone of teenage daughter used in Arizona virtual kidnapping attempt

Jennifer DeStefano, a private individual in Scottsdale, Arizona · United States

Jennifer DeStefano of Scottsdale, Arizona received a call in which she heard what she believed was her 15-year-old daughter crying, followed by a man claiming to hold the girl and demanding a US$1 million ransom, later reduced to US$50,000 in cash. While she kept the caller talking, other parents reached her husband, who confirmed the daughter was safe at home. No money changed hands. DeStefano described the incident in written testimony to the US Senate Judiciary Committee in June 2023, and it became one of the most cited AI voice-cloning cases in US policy debate.

Voice Clone / Audio DeepfakeSuspected AI-enabledAttempt blocked
Reported2 sources
March 29, 2023·Technology

3CX supply chain attack began with a trojanised X_TRADER installer on staff PC

3CX Ltd. · Cyprus

In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.

Vendor / Supply Chain Impersonation
Confirmed3 sources
February 5, 2023·Cryptocurrency

Coinbase employee phished by SMS then talked through by a fake IT caller

Coinbase · United States

In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.

Smishing (SMS)Attempt blocked
Confirmed3 sources
February 5, 2023·Technology

Reddit source code stolen via a phishing site cloning its intranet gateway

Reddit · United States

Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.

Credential Phishing Portal
Confirmed3 sources
February 2023·Consumer

French woman loses EUR 830,000 to an AI-image 'Brad Pitt' romance scam

Private individual in France (identified only as 'Anne') · France

Beginning in February 2023, a 53-year-old French woman known publicly as Anne was drawn into an online relationship with someone posing as actor Brad Pitt. Over about 18 months she sent EUR 830,000, largely after being told he needed money for kidney cancer treatment and that his accounts were frozen by divorce proceedings. AI-generated images of the actor in hospital and a forged passport reinforced the deception. She realised she had been defrauded on seeing genuine photographs of Pitt with his partner, and filed a police complaint; the case became public in January 2025 when French broadcaster TF1 aired and then withdrew her interview.

Romance / Investment ScamConfirmed AI-enabled
$858K funds lostReported2 sources
February 2023·Consumer

Nature's Sunshine loses $4.8 million in BEC against Synergy Japan unit

Nature's Sunshine Products, Inc. (Synergy Japan) · Japan

Nature's Sunshine Products disclosed in a Form 8-K filed February 24, 2023 that a criminal scheme involving employee impersonation and fraudulent requests targeting its Synergy Japan operations produced a series of fraudulently induced wire transfers totaling $4.8 million between February 1 and February 17, 2023. The company discovered the fraud on February 17, 2023, contacted its bank and law enforcement to attempt recovery, and said it had identified no additional fraudulent activity.

Business Email Compromise
$4.8M funds lostConfirmed1 source
January 11, 2023·Technology

Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers

Mailchimp (Intuit) · United States

Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.

Help Desk Impersonation
Confirmed7 sources
January 2023·Gaming & Casino

Riot Games loses League of Legends source code to a social engineering attack

Riot Games · United States

Riot Games disclosed in January 2023 that attackers used social engineering to compromise its development environment and steal source code for League of Legends and Teamfight Tactics along with a legacy anti-cheat platform. The company received a ransom email demanding $10 million and publicly refused to pay. Riot said no player data or personal information was compromised, but the intrusion disrupted its build pipeline and delayed game patches.

Help Desk Impersonation
Confirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.