Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 21 of 21 entries
August 6, 2026·Financial Services

Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks

Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States

BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.

Vishing (Voice Phishing)Attempt blocked
$10.6M criminal proceedsConfirmed1 source
July 6, 2026·Financial Services

Apollo Global Management breached by BlackFile callers posing as IT support

Apollo Global Management · United States

Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.

Vishing (Voice Phishing)
Confirmed2 sources
February 19, 2026·Financial Services

Figure Technology loses ~967,000 customer records after employee falls for SSO vishing

Figure Technology Solutions · United States

Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.

Vishing (Voice Phishing)
967K affectedReported3 sources
January 9, 2026·Financial Services

Betterment named among victims of the January 2026 real-time vishing wave

Betterment · United States

Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.

Vishing (Voice Phishing)
Reported1 source
January 2026·Financial ServicesCampaign

Okta SSO accounts targeted in vishing campaign against financial firms

Multiple fintech, wealth management and advisory firms (unnamed) · United States

BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed1 source
July 28, 2025·Financial Services

TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs

TransUnion · United States

Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.

Vishing (Voice Phishing)
4.4M affectedReported2 sources
July 16, 2025·Financial Services

Allianz Life's Salesforce CRM emptied after social engineering

Allianz Life Insurance Company of North America · United States

Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.

Vishing (Voice Phishing)Suspected AI-enabled
1.1M affectedConfirmed4 sources
July 2025·Financial Services

Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility

HPS Investment Partners (BlackRock) · United States

HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.

Vendor / Supply Chain Impersonation
$400.0M funds lostReported3 sources
June 12, 2025·Financial Services

Aflac breached in insurance-sector social engineering campaign; 22.6M affected

Aflac · United States

Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.

Vishing (Voice Phishing)
22.6M affectedConfirmed5 sources
June 2025·Financial Services

Erie Insurance hit in Scattered Spider help desk campaign against insurers

Erie Insurance · United States

Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.

Help Desk Impersonation
Reported1 source
June 2025·Financial Services

Philadelphia Insurance Companies disclosed breach in insurer-focused campaign

Philadelphia Insurance Companies · United States

Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.

Help Desk Impersonation
Reported1 source
May 29, 2025·Financial Services

Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers

Farmers Insurance · United States

Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.

Vishing (Voice Phishing)
1.1M affectedReported2 sources
May 19, 2025·Financial ServicesCampaign

UK 'safe account' bank and police impersonation drives £450.7M in APP fraud

UK banking customers (multi-victim campaign) · United Kingdom

UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.

Vishing (Voice Phishing)
186K affectedConfirmed2 sources
January 2025·Financial Services

VC firm Insight Partners breached through social engineering attack

Insight Partners · United States

New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.

Spear Phishing (Email)
Confirmed2 sources
May 4, 2022·Financial ServicesBenchmark

FBI: business email compromise exposed $43 billion in losses across 177 countries

Businesses, government entities and individuals worldwide (multi-victim campaign) · Global

On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.

Business Email Compromise
$43.3B multi-victim total241K affectedConfirmed1 source
November 3, 2021·Financial Services

Robinhood support employee socially engineered by phone; 7 million customers exposed

Robinhood Markets · United States

On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.

Vishing (Voice Phishing)
7.0M affectedConfirmed2 sources
February 2021·Financial Services

Sequoia Capital investor data exposed after employee falls for phishing email

Sequoia Capital · United States

Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.

Spear Phishing (Email)
Reported3 sources
2020·Financial Services

Cloned company director's voice used in US$35M bank transfer fraud

Unnamed company and its bank; investigated by UAE authorities · United Arab Emirates

In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.

Voice Clone / Audio DeepfakeSuspected AI-enabled
$35.0M funds lostReported2 sources
February 2016·Financial Services

Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails

Bangladesh Bank (central bank of Bangladesh) · Bangladesh

In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.

Spear Phishing (Email)
$81.0M funds lostReported3 sources
January 2016·Financial Services

Belgian bank Crelan loses €70 million to CEO-fraud payment orders

Crelan NV/SA · Belgium

Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.

Business Email Compromise
$75.8M funds lostConfirmed1 source
December 30, 2014·Financial Services

Xoom Corporation loses $30.8 million to employee impersonation fraud

Xoom Corporation · United States

Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.

Business Email Compromise
$30.8M funds lostConfirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Financial+Services.