Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks
Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States
BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.
Apollo Global Management breached by BlackFile callers posing as IT support
Apollo Global Management · United States
Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.
Figure Technology loses ~967,000 customer records after employee falls for SSO vishing
Figure Technology Solutions · United States
Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.
Betterment named among victims of the January 2026 real-time vishing wave
Betterment · United States
Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.
Okta SSO accounts targeted in vishing campaign against financial firms
Multiple fintech, wealth management and advisory firms (unnamed) · United States
BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.
TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs
TransUnion · United States
Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.
Allianz Life's Salesforce CRM emptied after social engineering
Allianz Life Insurance Company of North America · United States
Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.
Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility
HPS Investment Partners (BlackRock) · United States
HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.
Aflac breached in insurance-sector social engineering campaign; 22.6M affected
Aflac · United States
Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.
Erie Insurance hit in Scattered Spider help desk campaign against insurers
Erie Insurance · United States
Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.
Philadelphia Insurance Companies disclosed breach in insurer-focused campaign
Philadelphia Insurance Companies · United States
Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.
Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers
Farmers Insurance · United States
Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.
UK 'safe account' bank and police impersonation drives £450.7M in APP fraud
UK banking customers (multi-victim campaign) · United Kingdom
UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.
VC firm Insight Partners breached through social engineering attack
Insight Partners · United States
New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.
FBI: business email compromise exposed $43 billion in losses across 177 countries
Businesses, government entities and individuals worldwide (multi-victim campaign) · Global
On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.
Robinhood support employee socially engineered by phone; 7 million customers exposed
Robinhood Markets · United States
On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.
Sequoia Capital investor data exposed after employee falls for phishing email
Sequoia Capital · United States
Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.
Cloned company director's voice used in US$35M bank transfer fraud
Unnamed company and its bank; investigated by UAE authorities · United Arab Emirates
In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.
Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails
Bangladesh Bank (central bank of Bangladesh) · Bangladesh
In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.
Belgian bank Crelan loses €70 million to CEO-fraud payment orders
Crelan NV/SA · Belgium
Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.
Xoom Corporation loses $30.8 million to employee impersonation fraud
Xoom Corporation · United States
Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Financial+Services.