Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 12 of 12 entries
May 6, 2026·ManufacturingCampaign

MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices

Multiple organisations in the United States and MENA (unnamed) · United States and Middle East / North Africa

Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.

Help Desk Impersonation
Reported2 sources
February 2026·Manufacturing

STAC4749 Teams vishing campaign led to Chaos ransomware in North America

Dozens of North American organisations (unnamed) · Canada

Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.

Vishing (Voice Phishing)
Confirmed1 source
September 2025·Manufacturing

Stellantis confirms customer data stolen from Salesforce platform

Stellantis · Netherlands

Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.

Vishing (Voice Phishing)
Reported2 sources
August 10, 2024·Manufacturing

Orion S.A. discloses $60 million loss from fraudulently induced wire transfers

Orion S.A. · United States

Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.

Business Email Compromise
$60.0M funds lostConfirmed2 sources
July 2024·Manufacturing

Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question

Ferrari · Italy

In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Reported2 sources
August 11, 2023·Manufacturing

Clorox attack traced to help desk agents resetting passwords without verification

The Clorox Company · United States

Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.

Help Desk Impersonation
$380.0M business impactConfirmed5 sources
August 2020·Manufacturing

Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory

Tesla, Inc. · United States

Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.

Insider RecruitmentAttempt blocked
Confirmed1 source
August 14, 2019·Manufacturing

Toyota Boshoku European unit loses $37 million to payment-instruction BEC

Toyota Boshoku Corporation (European subsidiary) · Japan

Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.

Business Email Compromise
$37.0M funds lostConfirmed3 sources
March 19, 2019·Manufacturing

Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer

Norsk Hydro ASA · Norway

Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.

Vendor / Supply Chain Impersonation
$71.0M business impactReported3 sources
April 2018·Manufacturing

Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud

Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom

Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.

Business Email Compromise
$11.0M funds lostConfirmed1 source
August 2016·Manufacturing

Leoni AG Romanian subsidiary wires €40 million to fraudsters

Leoni AG (Bistrița, Romania subsidiary) · Romania

German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.

Business Email Compromise
$44.0M funds lostConfirmed2 sources
January 2016·Manufacturing

Austrian aerospace supplier FACC loses about €50 million to CEO fraud

FACC AG · Austria

FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.

Business Email Compromise
$54.0M funds lostConfirmed3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Manufacturing.