Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 277 entries · page 9 of 12
April 3, 2022·Cryptocurrency

Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds

SatoshiLabs (Trezor), via email provider Mailchimp · Czech Republic

Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.

Vendor / Supply Chain Impersonation
Confirmed2 sources
March 30, 2022·OtherCampaign

Operation Eagle Sweep: 65 arrests in global BEC disruption

Multiple businesses and individuals (500+ U.S. victims) · United States

Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.

Business Email CompromiseAttempt blocked
Confirmed1 source
March 23, 2022·Cryptocurrency

Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF

Sky Mavis (Ronin Network / Axie Infinity) · Vietnam

On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.

Fake Job Offer / Recruitment Lure
$620.0M funds lostConfirmed4 sources
March 18, 2022·Technology

HubSpot employee account compromised, exposing customer data at crypto firms

HubSpot · United States

On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.

Credential Phishing Portal
Confirmed2 sources
March 2022·Telecom

LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code

T-Mobile US · United States

Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.

SIM Swap
Confirmed2 sources
January 21, 2022·Technology

Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling

Okta (via subprocessor Sitel/Sykes) · United States

A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.

Vendor / Supply Chain Impersonation
Confirmed2 sources
2022·Defense

Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge

Unnamed aerospace company in Spain · Spain

ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.

Fake Job Offer / Recruitment Lure
Confirmed3 sources
December 8, 2021·ConsumerBenchmark

FTC data: $147.8M in gift card fraud driven by government and business impersonators

US consumers (multi-victim campaign) · United States

An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.

Vishing (Voice Phishing)
$147.8M multi-victim total39K affectedConfirmed1 source
November 3, 2021·Financial Services

Robinhood support employee socially engineered by phone; 7 million customers exposed

Robinhood Markets · United States

On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.

Vishing (Voice Phishing)
7.0M affectedConfirmed2 sources
July 2021·Government

Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover

Town of Peterborough, New Hampshire · United States

The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.

Business Email Compromise
$2.3M funds lostConfirmed2 sources
June 2021·Gaming & Casino

Electronic Arts source code stolen via Slack cookie and IT help desk impersonation

Electronic Arts · United States

In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.

Help Desk Impersonation
Reported3 sources
February 2021·Financial Services

Sequoia Capital investor data exposed after employee falls for phishing email

Sequoia Capital · United States

Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.

Spear Phishing (Email)
Reported3 sources
2021·Nonprofit

One Treasure Island nonprofit loses $650,000 to hijacked email thread

One Treasure Island · United States

One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.

Business Email Compromise
$650K funds lostReported2 sources
November 24, 2020·Education

Baltimore County schools ransomware started with a contractor opening a phishing email

Baltimore County Public Schools · United States

Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.

Spear Phishing (Email)
$9.7M business impactConfirmed2 sources
November 13, 2020·Cryptocurrency

Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash

GoDaddy (registrar); Liquid.com and NiceHash · United States

Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.

Vishing (Voice Phishing)
Confirmed2 sources
August 2020·Manufacturing

Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory

Tesla, Inc. · United States

Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.

Insider RecruitmentAttempt blocked
Confirmed1 source
July 23, 2020·Technology

Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed

Garmin Ltd. · United States

Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.

Watering Hole / Malvertising
Alleged3 sources
July 15, 2020·Technology

Twitter's July 2020 account takeover started with phone spear phishing of employees

Twitter, Inc. · United States

On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.

Vishing (Voice Phishing)
$118K criminal proceeds130 affectedConfirmed6 sources
May 2020·Government

Scattered Canary floods Washington's pandemic unemployment system with fake claims

Washington State Employment Security Department · United States

In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.

Credential Phishing Portal
Reported1 source
May 2020·Gaming & Casino

Hacker bribed a Roblox support contractor to access user data and reset accounts

Roblox Corporation · United States

A hacker bribed a Roblox customer support representative, listed publicly as an in-game support contractor, to obtain access to the company's customer support panel. The panel exposed personal data on Roblox's user base and allowed password resets, removal of two-factor authentication, account bans and data changes. Roblox said it acted immediately, notified the small number of affected customers, and reported the hacker to HackerOne.

Insider Recruitment
Reported2 sources
April 23, 2020·HealthcareCampaign

WHO impersonation surge during COVID-19 targets donors and staff

World Health Organization and the general public (multi-victim campaign) · Global

On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.

Spear Phishing (Email)
450 affectedConfirmed2 sources
April 6, 2020·Healthcare

Magellan Health ransomware began with a phishing email impersonating a client

Magellan Health · United States

Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.

Spear Phishing (Email)
$1.4M business impact365K affectedConfirmed2 sources
January 17, 2020·Government

Puerto Rico government agency sends $2.6 million to fraudulent account

Puerto Rico Industrial Development Company (PRIDCO) · Puerto Rico

Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.

Business Email Compromise
$2.6M funds lostConfirmed1 source
2020·Financial Services

Cloned company director's voice used in US$35M bank transfer fraud

Unnamed company and its bank; investigated by UAE authorities · United Arab Emirates

In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.

Voice Clone / Audio DeepfakeSuspected AI-enabled
$35.0M funds lostReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents.