Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 4 of 4 entries
September 18, 2025·Other

US and UK charge Scattered Spider pair tied to $115M in ransom payments

47 US organisations including healthcare, transport and technology firms · United States

On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.

Help Desk Impersonation
$115.0M multi-victim totalConfirmed2 sources
July 2025·OtherCampaign

Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware

US retail, airline, transportation and insurance organisations · United States

Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.

Help Desk Impersonation
Confirmed2 sources
June 26, 2025·Transportation & Logistics

Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector

Hawaiian Airlines · United States

Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.

Help Desk Impersonation
Reported1 source
August 2022·TechnologyCampaign

0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations

Over 130 organisations targeted (Group-IB tracked campaign) · United States

Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.

Smishing (SMS)
9.9K affectedConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?q=Scattered+Spider+%2F+UNC3944.