Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 4 of 4 entries
August 2023·Energy & UtilitiesCampaign

QR code phishing campaign targets a major US energy company's Microsoft logins

Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets) · United States

Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.

QR Code PhishingAttempt blocked
Confirmed3 sources
March 2019·Energy & Utilities

UK energy firm CEO tricked by AI voice clone of German parent-company boss

Unnamed UK-based energy company (subsidiary of a German parent) · United Kingdom

In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.

Voice Clone / Audio DeepfakeSuspected AI-enabled
$243K funds lostReported2 sources
2017·Energy & Utilities

Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign

Wolf Creek Nuclear Operating Corporation · United States

A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.

Spear Phishing (Email)
Confirmed2 sources
December 23, 2015·Energy & Utilities

Ukraine power grid blackout of 2015 began with BlackEnergy spear phishing

Kyivoblenergo, Prykarpattyaoblenergo and Chernivtsioblenergo · Ukraine

On 23 December 2015 three Ukrainian regional electricity distribution companies were hit by a coordinated cyberattack that opened breakers at roughly 30 substations and left about 225,000 customers without power. The joint E-ISAC/SANS analysis found the intrusion began months earlier with spear phishing emails carrying malicious Office documents that installed BlackEnergy 3, which was used to harvest credentials for the operators' VPN and SCADA environments.

Spear Phishing (Email)
Confirmed3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Energy+%26+Utilities.