Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Carnival confirms social engineering of an employee account exposed 6 million customers
Carnival Corporation · United States
Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.
Starbucks employee data stolen via cloned Partner Central login pages
Starbucks · United States
Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.
ShinyHunters claim 14M Panera Bread records after Entra SSO vishing
Panera Bread · United States
ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.
Chipotle payment card breach traced to FIN7 phishing emails backed by phone calls
Chipotle Mexican Grill · United States
Chipotle disclosed in May 2017 that point-of-sale malware had captured payment card track data at restaurants between 24 March and 18 April 2017, including cardholder name, card number, expiry date and verification code. The FBI attributed the intrusion to FIN7, naming Chipotle among the group's publicly disclosed US victims. FIN7 entered victim networks through phishing emails that employees opened, reinforced by follow-up phone calls.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Hospitality.