Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 9 of 9 entries
May 2026·EducationCampaign

700+ education and tech sites hijacked to serve ClickFix paste-the-command lures

Visitors to 700+ compromised university and technology company websites · Global

Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.

Watering Hole / Malvertising
Confirmed1 source
February 2026·Education

Dickinson Public Schools loses $4.92M to vendor-impersonation BEC

Dickinson Public Schools · United States

Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.

Business Email Compromise
$4.9M funds lostConfirmed2 sources
November 18, 2025·Education

Harvard alumni and donor data stolen in phone-based phishing attack

Harvard University · United States

Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.

Vishing (Voice Phishing)
Confirmed2 sources
November 2025·Education

Princeton advancement database breached in targeted phishing attack

Princeton University · United States

Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.

Spear Phishing (Email)
Confirmed2 sources
October 31, 2025·Education

University of Pennsylvania donor systems breached via social engineering

University of Pennsylvania · United States

The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.

Credential Phishing Portal
Confirmed2 sources
November 24, 2020·Education

Baltimore County schools ransomware started with a contractor opening a phishing email

Baltimore County Public Schools · United States

Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.

Spear Phishing (Email)
$9.7M business impactConfirmed2 sources
July 2019·Education

Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow

Lancaster University · United Kingdom

Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.

Credential Phishing Portal
13K affectedConfirmed2 sources
October 2018·Education

San Diego Unified staff phished, exposing 500,000 students, parents and employees

San Diego Unified School District · United States

San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.

Credential Phishing Portal
500K affectedConfirmed2 sources
February 2, 2017·EducationCampaign

IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits

US school districts, tribal organizations, nonprofits and employers (multi-victim campaign) · United States

In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.

Business Email Compromise
Confirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Education.