Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 8 of 12
2023·ConsumerBenchmark

FTC: business and government impersonation scams hit $1.1 billion in 2023

US consumers (multi-victim campaign) · United States

An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.

Tech Support Scam
$1.1B multi-victim total490K affectedConfirmed1 source
December 4, 2022·Gaming & Casino

Activision breached after an HR employee falls for an SMS phishing message

Activision Blizzard · United States

Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.

Smishing (SMS)
19K affectedReported4 sources
November 11, 2022·Cryptocurrency

SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night

FTX (referred to as 'Victim 1' in the indictment) · United States

On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.

SIM Swap
$400.0M funds lostReported1 source
November 7, 2022·OtherCampaign

Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds

Multiple (New York law firm, a Maltese bank, a Qatari businessman, others) · United States

Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.

Business Email Compromise
Confirmed1 source
October 14, 2022·Technology

Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing

Dropbox · United States

Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.

Credential Phishing Portal
Confirmed3 sources
October 2022·Technology

Zendesk breach followed successful SMS phishing of employees

Zendesk · United States

Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.

Smishing (SMS)
Reported3 sources
October 2022·Retail

Bed Bath & Beyond discloses data breach to SEC after an employee was phished

Bed Bath & Beyond · United States

Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.

Credential Phishing Portal
Confirmed2 sources
October 2022·Cryptocurrency

3Commas users phished for API keys, leading to unauthorised trades on FTX accounts

3Commas users (with linked FTX and Binance accounts) · Estonia

In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.

Credential Phishing Portal
$6.0M multi-victim totalReported2 sources
September 18, 2022·Gaming & Casino

Rockstar Games internal Slack breached and GTA 6 footage leaked

Rockstar Games · United States

An actor using the handle teapotuberhacker, the same persona behind the Uber intrusion days earlier, posted roughly 90 in-development Grand Theft Auto VI videos and claimed to hold GTA V and GTA VI source code, saying they had reached Rockstar's internal Slack and Confluence. Rockstar confirmed a network intrusion and unauthorised access to early development footage. A UK teenager, Arion Kurtaj, was later convicted and in December 2023 given an indefinite hospital order.

Help Desk Impersonation
Alleged2 sources
September 16, 2022·TechnologyCampaign

GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials

GitHub users and customer organisations (GitHub-reported campaign) · United States

GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.

Credential Phishing Portal
Confirmed2 sources
September 15, 2022·Transportation & Logistics

Uber breached after MFA push bombing and a WhatsApp message posing as IT

Uber Technologies · United States

In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.

MFA Fatigue / Push Bombing
Confirmed5 sources
August 25, 2022·Transportation & Logistics

DoorDash customer data exposed through phished third-party vendor employees

DoorDash · United States

DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.

Vendor / Supply Chain Impersonation
Confirmed3 sources
August 4, 2022·Technology

Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers

Twilio · United States

In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.

Smishing (SMS)
Confirmed4 sources
August 3, 2022·Technology

Klaviyo employee phished; attacker used internal tools to take crypto mailing lists

Klaviyo · United States

Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.

Credential Phishing Portal
Confirmed2 sources
August 2022·CryptocurrencyCampaign

Deepfake of Binance communications chief used to scam crypto projects on video calls

Multiple cryptocurrency projects seeking Binance listings · Multiple countries

In August 2022 Binance disclosed that a 'sophisticated hacking team' had produced a deepfake video likeness of chief communications officer Patrick Hillmann and used it on Zoom calls with representatives of cryptocurrency projects. The impersonator offered help getting tokens listed on Binance and solicited payments and information. Hillmann said several project managers were convinced before the fraud was discovered, and that the clone was built from his publicly available interview footage.

Deepfake Video CallConfirmed AI-enabled
Reported2 sources
August 2022·TechnologyCampaign

0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations

Over 130 organisations targeted (Group-IB tracked campaign) · United States

Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.

Smishing (SMS)
9.9K affectedConfirmed2 sources
July 20, 2022·Technology

Cloudflare blocks the same SMS phishing attack that breached Twilio

Cloudflare · United States

On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.

Smishing (SMS)Attempt blocked
Confirmed3 sources
July 12, 2022·TechnologyCampaign

Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations

More than 10,000 organisations targeted (Microsoft-tracked campaign) · Global

Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.

Credential Phishing Portal
Confirmed2 sources
July 2022·Transportation & Logistics

American Airlines discloses breach after phishing compromised employee mailboxes

American Airlines · United States

American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.

Credential Phishing Portal
1.7K affectedConfirmed2 sources
June 23, 2022·Cryptocurrency

Phishing of a Harmony developer preceded the $100M Horizon Bridge theft

Harmony (Horizon Bridge) · United States

Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.

Spear Phishing (Email)
$100.0M funds lostConfirmed2 sources
June 2022·Government

European mayors duped by deepfake video calls posing as Kyiv mayor Klitschko

City governments of Berlin, Madrid and Vienna · Germany

In June 2022 the mayors of Berlin (Franziska Giffey), Madrid (Jose Luis Martinez-Almeida) and Vienna (Michael Ludwig) each held video calls with someone presenting as Kyiv mayor Vitali Klitschko. Giffey's office said the call was cut short when the topics and framing became implausible, and concluded a deepfake had been used. Klitschko linked the calls to Russian efforts to drive a wedge between Ukraine and its European partners. Attribution was never publicly established.

Deepfake Video CallSuspected AI-enabled
Reported2 sources
May 24, 2022·Technology

Cisco breached after vishing and MFA fatigue against an employee

Cisco Systems · United States

Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.

MFA Fatigue / Push Bombing
Confirmed3 sources
May 4, 2022·Financial ServicesBenchmark

FBI: business email compromise exposed $43 billion in losses across 177 countries

Businesses, government entities and individuals worldwide (multi-victim campaign) · Global

On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.

Business Email Compromise
$43.3B multi-victim total241K affectedConfirmed1 source
May 2022·Government

Ghostwriter credential phishing against Ukrainian government and military accounts

Ukrainian government and military personnel · Ukraine

Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.

Credential Phishing PortalAttempt blocked
Confirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.