Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Armored Likho spear phishing targets government and power sector in three countries
Government agencies and electric power organisations in Russia, Brazil and Kazakhstan · Russia
Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.
FBI identifies North Korean remote IT worker employed by a US federal agency
Unnamed US federal agency · United States
FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.
City of Aurora loses $1.1M after employee falls for bank impersonation call
City of Aurora, Illinois · United States
On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.
FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government
Think tanks, academic institutions and government entities · United States
The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.
Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers
US State Department; three foreign ministers, a US governor and a member of Congress · United States
In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.
FBI warns of AI voice-cloning campaign impersonating senior US officials
Current and former senior US federal and state officials and their contacts · United States
On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.
AI voice impersonation of White House chief of staff Susie Wiles targets Republicans
The White House; senators, governors and business executives contacted · United States
In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.
Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts
Multiple government, NGO, defence and energy organisations · Multiple
Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.
US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM
Office of US Senator Ben Cardin, Senate Foreign Relations Committee · United States
In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.
Iran's APT42 phishes Israeli and US officials with think-tank impersonation
Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States
On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.
Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected
Los Angeles County Department of Public Health · United States
The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.
SIM swap of the SEC's X account posted a fake Bitcoin ETF approval
U.S. Securities and Exchange Commission · United States
On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.
AI-cloned Biden robocall told New Hampshire voters to skip the primary
New Hampshire primary voters · United States
On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.
European mayors duped by deepfake video calls posing as Kyiv mayor Klitschko
City governments of Berlin, Madrid and Vienna · Germany
In June 2022 the mayors of Berlin (Franziska Giffey), Madrid (Jose Luis Martinez-Almeida) and Vienna (Michael Ludwig) each held video calls with someone presenting as Kyiv mayor Vitali Klitschko. Giffey's office said the call was cut short when the topics and framing became implausible, and concluded a deepfake had been used. Klitschko linked the calls to Russian efforts to drive a wedge between Ukraine and its European partners. Attribution was never publicly established.
Ghostwriter credential phishing against Ukrainian government and military accounts
Ukrainian government and military personnel · Ukraine
Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.
Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover
Town of Peterborough, New Hampshire · United States
The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.
Scattered Canary floods Washington's pandemic unemployment system with fake claims
Washington State Employment Security Department · United States
In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.
Puerto Rico government agency sends $2.6 million to fraudulent account
Puerto Rico Industrial Development Company (PRIDCO) · Puerto Rico
Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.
Riviera Beach pays $600,000 ransom after an employee clicked a malicious email link
City of Riviera Beach, Florida · United States
The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.
Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients
Oregon Department of Human Services · United States
On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.
Cabarrus County, NC diverts $2.5 million school payment to BEC actors
Cabarrus County, North Carolina · United States
Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.
City of Ottawa treasurer wires about US$98,000 to fake city manager
City of Ottawa · Canada
In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.
GRU spear-phished election vendor VR Systems, then 122 local election officials
VR Systems and US local election administrators · United States
A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.
John Podesta and DNC staff phished by fake Google security alerts in 2016
Hillary for America campaign and the Democratic National Committee · United States
On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Government.