Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 4 of 4 entries
July 2026·DefenseCampaign

Lazarus pairs fake recruiter approaches with a Windows zero-day

Defence and aerospace organisations in Western Europe, India and South America · Global

Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.

Fake Job Offer / Recruitment Lure
Confirmed1 source
2022·Defense

Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge

Unnamed aerospace company in Spain · Spain

ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.

Fake Job Offer / Recruitment Lure
Confirmed3 sources
March 23, 2022·Cryptocurrency

Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF

Sky Mavis (Ronin Network / Axie Infinity) · Vietnam

On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.

Fake Job Offer / Recruitment Lure
$620.0M funds lostConfirmed4 sources
February 2016·Financial Services

Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails

Bangladesh Bank (central bank of Bangladesh) · Bangladesh

In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.

Spear Phishing (Email)
$81.0M funds lostReported3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?q=Lazarus+Group+%28North+Korea%29.