Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 6 of 6 entries
May 2026·Professional Services

Cushman & Wakefield confirms vishing-triggered Salesforce data theft

Cushman & Wakefield · United States

Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.

Vishing (Voice Phishing)
Confirmed2 sources
November 3, 2025·Professional Services

US ransomware negotiators charged with running their own BlackCat attacks

US medical device company, pharmaceutical firm, drone maker and other victims · United States

US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.

Insider Recruitment
$1.3M ransom paidConfirmed2 sources
February 2024·Professional Services

Arup Hong Kong office loses about $25 million in deepfake video call scam

Arup Group (Hong Kong office) · Hong Kong

In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.

Deepfake Video CallConfirmed AI-enabled
$25.0M funds lostConfirmed5 sources
August 19, 2023·Professional Services

SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data

Kroll · United States

Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.

SIM Swap
Confirmed2 sources
December 2018·Professional Services

Tecnimont India loses $18.6 million to fake CEO conference calls

Tecnimont SpA (Indian subsidiary, Maire Tecnimont group) · India

The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.

Business Email Compromise
$18.6M funds lostReported2 sources
April 2011·Professional Services

Epsilon email marketing breach exposes address lists of banks and retailers

Epsilon Data Management and other email service providers · United States

In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.

Spear Phishing (Email)
$2.0M criminal proceeds1.0B affectedConfirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Professional+Services.