Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices
Multiple organisations in the United States and MENA (unnamed) · United States and Middle East / North Africa
Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.
STAC4749 Teams vishing campaign led to Chaos ransomware in North America
Dozens of North American organisations (unnamed) · Canada
Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.
Stellantis confirms customer data stolen from Salesforce platform
Stellantis · Netherlands
Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.
Orion S.A. discloses $60 million loss from fraudulently induced wire transfers
Orion S.A. · United States
Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.
Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question
Ferrari · Italy
In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.
Clorox attack traced to help desk agents resetting passwords without verification
The Clorox Company · United States
Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.
Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory
Tesla, Inc. · United States
Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.
Toyota Boshoku European unit loses $37 million to payment-instruction BEC
Toyota Boshoku Corporation (European subsidiary) · Japan
Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.
Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer
Norsk Hydro ASA · Norway
Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.
Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud
Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom
Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.
Leoni AG Romanian subsidiary wires €40 million to fraudsters
Leoni AG (Bistrița, Romania subsidiary) · Romania
German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.
Austrian aerospace supplier FACC loses about €50 million to CEO fraud
FACC AG · Austria
FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Manufacturing.