Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 14 of 14 entries
August 7, 2026·Retail

Levi Strauss files 8-K after social engineering compromises three employee computers

Levi Strauss & Co. · United States

Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.

Vishing (Voice Phishing)
Confirmed2 sources
February 2026·RetailCampaign

BlackFile extortion gang runs vishing campaign against retail and hospitality

Multiple retail and hospitality organisations (unnamed) · United States

BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.

Vishing (Voice Phishing)
Confirmed1 source
September 2025·Retail

Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft

Kering (Gucci, Balenciaga, Alexander McQueen) · France

Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Retail

Chanel notifies US clients after third-party client-care database breach

Chanel · United States

Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.

Vishing (Voice Phishing)
Reported2 sources
August 2025·Retail

Pandora warns customers after third-party platform breach

Pandora A/S · Denmark

Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.

Vishing (Voice Phishing)
Reported2 sources
July 2025·Retail

LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave

LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.) · France

Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.

Vishing (Voice Phishing)
Reported2 sources
May 1, 2025·Retail

Harrods restricts internet access after intrusion attempts in UK retail wave

Harrods · United Kingdom

Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.

Help Desk Impersonation
Alleged2 sources
May 2025·Retail

Adidas customer data stolen through third-party customer service provider

Adidas · Germany

Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.

Vishing (Voice Phishing)
Reported2 sources
April 22, 2025·Retail

Marks & Spencer attack tied to social engineering of outsourced service desk

Marks & Spencer Group plc · United Kingdom

Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.

Help Desk Impersonation
Confirmed6 sources
April 2025·Retail

Co-op loses £206m of revenue and 6.5 million members' data to DragonForce

Co-operative Group · United Kingdom

The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.

Help Desk Impersonation
$275.0M business impact6.5M affectedConfirmed5 sources
October 2022·Retail

Bed Bath & Beyond discloses data breach to SEC after an employee was phished

Bed Bath & Beyond · United States

Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.

Credential Phishing Portal
Confirmed2 sources
April 2018·Retail

FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards

Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor) · United States

In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.

Spear Phishing (Email)
5.0M affectedReported2 sources
March 2016·Retail

Sprouts Farmers Market payroll employee emails 21,000 staff W-2s to a scammer

Sprouts Farmers Market · United States

In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.

Business Email Compromise
21K affectedConfirmed2 sources
December 2013·Retail

Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical

Target Corporation · United States

Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.

Vendor / Supply Chain Impersonation
110.0M affectedReported3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Retail.