Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 10 of 10 entries
August 2025·Transportation & Logistics

Air France and KLM disclose breach of third-party customer service platform

Air France-KLM · France

Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.

Vishing (Voice Phishing)
Reported2 sources
July 1, 2025·Transportation & Logistics

Qantas contact centre platform breached after help desk tricked into adding MFA

Qantas Airways · Australia

Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.

Help Desk Impersonation
5.7M affectedConfirmed4 sources
June 26, 2025·Transportation & Logistics

Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector

Hawaiian Airlines · United States

Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.

Help Desk Impersonation
Reported1 source
June 13, 2025·Transportation & Logistics

WestJet breach of 1.2 million passengers began with a help desk password reset

WestJet · Canada

Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.

Help Desk Impersonation
1.2M affectedConfirmed2 sources
September 1, 2024·Transportation & Logistics

Transport for London hit by Scattered Spider teens in a £29m intrusion

Transport for London · United Kingdom

Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.

Help Desk Impersonation
$39.0M business impactReported2 sources
April 12, 2024·Transportation & LogisticsCampaign

Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks

US drivers and toll customers (multi-victim campaign) · United States

On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.

Smishing (SMS)
2.0K affectedConfirmed1 source
September 15, 2022·Transportation & Logistics

Uber breached after MFA push bombing and a WhatsApp message posing as IT

Uber Technologies · United States

In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.

MFA Fatigue / Push Bombing
Confirmed5 sources
August 25, 2022·Transportation & Logistics

DoorDash customer data exposed through phished third-party vendor employees

DoorDash · United States

DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.

Vendor / Supply Chain Impersonation
Confirmed3 sources
July 2022·Transportation & Logistics

American Airlines discloses breach after phishing compromised employee mailboxes

American Airlines · United States

American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.

Credential Phishing Portal
1.7K affectedConfirmed2 sources
April 2015·Transportation & Logistics

Ryanair loses nearly $5 million from fuel account via fraudulent transfer

Ryanair Holdings plc · Ireland

In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.

Business Email Compromise
$5.0M funds lostReported1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Transportation+%26+Logistics.