Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 15 of 15 entries
June 2026·Healthcare

Abbott investigates ShinyHunters claim after mid-June vishing on employees

Abbott Laboratories (legacy Exact Sciences systems) · United States

ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.

Vishing (Voice Phishing)
Reported2 sources
May 29, 2026·Healthcare

Quantum Health network breached after social engineering call to a user

Quantum Health · United States

A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.

Vishing (Voice Phishing)
Reported1 source
February 4, 2026·Healthcare

Hims & Hers support tickets stolen through compromised Okta SSO accounts

Hims & Hers Health · United States

Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.

Credential Phishing Portal
Confirmed2 sources
January 20, 2026·Healthcare

Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients

Xsolis · United States

Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.

Spear Phishing (Email)
1.4M affectedConfirmed2 sources
July 22, 2025·HealthcareCampaign

Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access

Multiple businesses and critical infrastructure organisations (campaign) · Multiple

A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.

Watering Hole / Malvertising
Confirmed3 sources
March 3, 2025·Healthcare

Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients

Arizona Arthritis and Rheumatology Associates · United States

Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.

Credential Phishing Portal
5.5K affectedConfirmed1 source
March 3, 2025·Healthcare

Monongalia Health System email phishing breach affects 4,895 patients

Monongalia Health System (Mon Health) · United States

West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.

Credential Phishing Portal
4.9K affectedConfirmed1 source
July 30, 2024·Healthcare

Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients

Michigan Medicine (University of Michigan) · United States

Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.

MFA Fatigue / Push Bombing
58K affectedConfirmed2 sources
May 8, 2024·Healthcare

Ascension ransomware attack began when an employee downloaded a malicious file

Ascension · United States

Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.

Spear Phishing (Email)
5.6M affectedConfirmed2 sources
April 23, 2020·HealthcareCampaign

WHO impersonation surge during COVID-19 targets donors and staff

World Health Organization and the general public (multi-victim campaign) · Global

On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.

Spear Phishing (Email)
450 affectedConfirmed2 sources
April 6, 2020·Healthcare

Magellan Health ransomware began with a phishing email impersonating a client

Magellan Health · United States

Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.

Spear Phishing (Email)
$1.4M business impact365K affectedConfirmed2 sources
May 9, 2019·Healthcare

Presbyterian Healthcare Services phishing exposes data on 183,000 patients

Presbyterian Healthcare Services · United States

New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.

Credential Phishing Portal
183K affectedConfirmed2 sources
March 2018·Healthcare

UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients

UnityPoint Health · United States

UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.

Business Email Compromise
$2.8M business impact1.4M affectedConfirmed2 sources
February 4, 2015·Healthcare

Anthem breach of 78.8 million records started with a spear phishing email

Anthem Inc. · United States

Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.

Spear Phishing (Email)
$115.0M business impact78.8M affectedConfirmed3 sources
May 2014·Healthcare

Premera Blue Cross breach began with a spear-phishing email, 10.4 million affected

Premera Blue Cross · United States

Attackers compromised Premera Blue Cross in May 2014 and remained undetected for about nine months until January 2015. The intrusion exposed the protected health information of roughly 10.4 million individuals, including names, dates of birth, Social Security numbers, bank account details and clinical information. The HHS Office for Civil Rights, describing the incident, stated that the entry point was a spear-phishing email that installed malware.

Spear Phishing (Email)
$6.8M business impact10.4M affectedConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Healthcare.