Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 35 entries
August 24, 2026·Technology

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · United States

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
June 2026·Healthcare

Abbott investigates ShinyHunters claim after mid-June vishing on employees

Abbott Laboratories (legacy Exact Sciences systems) · United States

ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.

Vishing (Voice Phishing)
Reported2 sources
January 29, 2026·Technology

Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records

Match Group (Match, Hinge, OkCupid) · United States

ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.

Credential Phishing Portal
10.0M affectedReported2 sources
January 2026·Technology

Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked

Crunchbase · United States

Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.

Vishing (Voice Phishing)
2.0M affectedReported3 sources
January 2026·OtherCampaign

ShinyHunters SSO vishing campaign hits 100+ organizations

100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance · Global

Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.

Vishing (Voice Phishing)
Confirmed2 sources
January 2026·Hospitality

ShinyHunters claim 14M Panera Bread records after Entra SSO vishing

Panera Bread · United States

ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.

Vishing (Voice Phishing)
Alleged2 sources
July 13, 2026·Consumer

Brinks Home breached after Microsoft Entra vishing call to an employee

Brinks Home · United States

Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.

Vishing (Voice Phishing)
Confirmed2 sources
July 2026·Technology

RingCentral data on 1.6M accounts leaked after social engineering campaign

RingCentral · United States

Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.

Vishing (Voice Phishing)
1.6M affectedConfirmed2 sources
May 2026·Professional Services

Cushman & Wakefield confirms vishing-triggered Salesforce data theft

Cushman & Wakefield · United States

Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.

Vishing (Voice Phishing)
Confirmed2 sources
April 20, 2026·Consumer

ADT confirms breach after vishing attack on employee's Okta SSO account

ADT · United States

ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed2 sources
April 14, 2026·Hospitality

Carnival confirms social engineering of an employee account exposed 6 million customers

Carnival Corporation · United States

Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.

Vishing (Voice Phishing)
6.0M affectedReported3 sources
April 1, 2026·Telecom

Charter Communications breach of 4.9M accounts began with an Entra vishing call

Charter Communications (Spectrum) · United States

ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.

Vishing (Voice Phishing)
4.9M affectedConfirmed2 sources
March 2026·Technology

Identity protection firm Aura breached in vishing attack; ~900,000 records taken

Aura · United States

Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.

Vishing (Voice Phishing)
900K affectedReported1 source
February 19, 2026·Financial Services

Figure Technology loses ~967,000 customer records after employee falls for SSO vishing

Figure Technology Solutions · United States

Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.

Vishing (Voice Phishing)
967K affectedReported3 sources
February 13, 2026·Technology

CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes

CarGurus · United States

Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.

Vishing (Voice Phishing)
Reported2 sources
February 11, 2026·Technology

Optimizely confirms data breach after vishing attack on employees

Optimizely · United States

Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.

Vishing (Voice Phishing)
Confirmed1 source
February 4, 2026·Healthcare

Hims & Hers support tickets stolen through compromised Okta SSO accounts

Hims & Hers Health · United States

Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.

Credential Phishing Portal
Confirmed2 sources
January 9, 2026·Financial Services

Betterment named among victims of the January 2026 real-time vishing wave

Betterment · United States

Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.

Vishing (Voice Phishing)
Reported1 source
January 2026·Media & Entertainment

SoundCloud hit as real-time vishing kits drive browsers through SSO logins

SoundCloud · Germany

A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.

Vishing (Voice Phishing)
36.0M affectedReported1 source
January 2026·Financial ServicesCampaign

Okta SSO accounts targeted in vishing campaign against financial firms

Multiple fintech, wealth management and advisory firms (unnamed) · United States

BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed1 source
September 2025·Manufacturing

Stellantis confirms customer data stolen from Salesforce platform

Stellantis · Netherlands

Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.

Vishing (Voice Phishing)
Reported2 sources
September 2025·Retail

Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft

Kering (Gucci, Balenciaga, Alexander McQueen) · France

Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.

Vishing (Voice Phishing)
Reported2 sources
August 6, 2025·Technology

Workday discloses CRM breach after social engineering of employees

Workday · United States

Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.

Vishing (Voice Phishing)
Confirmed2 sources
August 2025·Transportation & Logistics

Air France and KLM disclose breach of third-party customer service platform

Air France-KLM · France

Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.

Vishing (Voice Phishing)
Reported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?q=ShinyHunters.