Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 47 entries
February 2026·Education

Dickinson Public Schools loses $4.92M to vendor-impersonation BEC

Dickinson Public Schools · United States

Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.

Business Email Compromise
$4.9M funds lostConfirmed2 sources
August 2025·OtherCampaign

Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud

Approximately 88,000 victims across 18 African countries and the UK · Multiple

Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.

Business Email Compromise
$485.0M multi-victim totalConfirmed2 sources
July 2025·Financial Services

Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility

HPS Investment Partners (BlackRock) · United States

HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.

Vendor / Supply Chain Impersonation
$400.0M funds lostReported3 sources
March 2025·Other

Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO

Unnamed multinational firm, Singapore office · Singapore

On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.

Deepfake Video CallConfirmed AI-enabled
$499K funds lostConfirmed1 source
August 10, 2024·Manufacturing

Orion S.A. discloses $60 million loss from fraudulently induced wire transfers

Orion S.A. · United States

Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.

Business Email Compromise
$60.0M funds lostConfirmed2 sources
April 2024·Technology

LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO

LastPass · United States

On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed3 sources
February 2024·Professional Services

Arup Hong Kong office loses about $25 million in deepfake video call scam

Arup Group (Hong Kong office) · Hong Kong

In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.

Deepfake Video CallConfirmed AI-enabled
$25.0M funds lostConfirmed5 sources
2024·OtherBenchmark

FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)

Aggregate: U.S. and international BEC victims reporting to FBI IC3 · United States

The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.

Business Email Compromise
$2.8B multi-victim totalConfirmed2 sources
August 2023·TechnologyCampaign

EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts

More than 100 organisations worldwide (Proofpoint-tracked campaign) · Global

Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.

Credential Phishing Portal
Confirmed2 sources
February 2023·Consumer

Nature's Sunshine loses $4.8 million in BEC against Synergy Japan unit

Nature's Sunshine Products, Inc. (Synergy Japan) · Japan

Nature's Sunshine Products disclosed in a Form 8-K filed February 24, 2023 that a criminal scheme involving employee impersonation and fraudulent requests targeting its Synergy Japan operations produced a series of fraudulently induced wire transfers totaling $4.8 million between February 1 and February 17, 2023. The company discovered the fraud on February 17, 2023, contacted its bank and law enforcement to attempt recovery, and said it had identified no additional fraudulent activity.

Business Email Compromise
$4.8M funds lostConfirmed1 source
November 7, 2022·OtherCampaign

Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds

Multiple (New York law firm, a Maltese bank, a Qatari businessman, others) · United States

Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.

Business Email Compromise
Confirmed1 source
July 12, 2022·TechnologyCampaign

Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations

More than 10,000 organisations targeted (Microsoft-tracked campaign) · Global

Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.

Credential Phishing Portal
Confirmed2 sources
May 4, 2022·Financial ServicesBenchmark

FBI: business email compromise exposed $43 billion in losses across 177 countries

Businesses, government entities and individuals worldwide (multi-victim campaign) · Global

On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.

Business Email Compromise
$43.3B multi-victim total241K affectedConfirmed1 source
March 30, 2022·OtherCampaign

Operation Eagle Sweep: 65 arrests in global BEC disruption

Multiple businesses and individuals (500+ U.S. victims) · United States

Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.

Business Email CompromiseAttempt blocked
Confirmed1 source
July 2021·Government

Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover

Town of Peterborough, New Hampshire · United States

The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.

Business Email Compromise
$2.3M funds lostConfirmed2 sources
February 2021·Financial Services

Sequoia Capital investor data exposed after employee falls for phishing email

Sequoia Capital · United States

Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.

Spear Phishing (Email)
Reported3 sources
2021·Nonprofit

One Treasure Island nonprofit loses $650,000 to hijacked email thread

One Treasure Island · United States

One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.

Business Email Compromise
$650K funds lostReported2 sources
May 2020·Government

Scattered Canary floods Washington's pandemic unemployment system with fake claims

Washington State Employment Security Department · United States

In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.

Credential Phishing Portal
Reported1 source
January 17, 2020·Government

Puerto Rico government agency sends $2.6 million to fraudulent account

Puerto Rico Industrial Development Company (PRIDCO) · Puerto Rico

Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.

Business Email Compromise
$2.6M funds lostConfirmed1 source
2020·Financial Services

Cloned company director's voice used in US$35M bank transfer fraud

Unnamed company and its bank; investigated by UAE authorities · United Arab Emirates

In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.

Voice Clone / Audio DeepfakeSuspected AI-enabled
$35.0M funds lostReported2 sources
September 10, 2019·OtherCampaign

Operation reWired: 281 arrested worldwide in BEC crackdown

Multiple businesses and individuals (global) · United States

Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.

Business Email CompromiseAttempt blocked
Confirmed3 sources
September 2019·Media & Entertainment

Nikkei America employee wires $29 million on fraudulent management instructions

Nikkei Inc. (Nikkei America) · United States

Japanese media group Nikkei disclosed in October 2019 that an employee at its US subsidiary, Nikkei America, had transferred about $29 million to a bank account controlled by fraudsters the previous month. The employee acted on instructions from someone impersonating a Nikkei management executive. Nikkei reported the matter to authorities in the United States and Hong Kong and said it was working to recover the funds.

Business Email Compromise
$29.0M funds lostConfirmed2 sources
August 14, 2019·Manufacturing

Toyota Boshoku European unit loses $37 million to payment-instruction BEC

Toyota Boshoku Corporation (European subsidiary) · Japan

Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.

Business Email Compromise
$37.0M funds lostConfirmed3 sources
March 2019·Energy & Utilities

UK energy firm CEO tricked by AI voice clone of German parent-company boss

Unnamed UK-based energy company (subsidiary of a German parent) · United Kingdom

In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.

Voice Clone / Audio DeepfakeSuspected AI-enabled
$243K funds lostReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Business+Email+Compromise.