Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 17 of 17 entries
July 2026·Government

FBI identifies North Korean remote IT worker employed by a US federal agency

Unnamed US federal agency · United States

FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.

Fake IT Worker Infiltration
Confirmed2 sources
July 2026·DefenseCampaign

Lazarus pairs fake recruiter approaches with a Windows zero-day

Defence and aerospace organisations in Western Europe, India and South America · Global

Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.

Fake Job Offer / Recruitment Lure
Confirmed1 source
April 1, 2026·Cryptocurrency

Six-month DPRK social engineering operation preceded $285M Drift Protocol theft

Drift Protocol · Unknown

Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.

Vendor / Supply Chain Impersonation
$285.0M funds lostReported2 sources
March 2026·TechnologyCampaign

Contagious Interview: fake developer job interviews deliver backdoors

Software developers at enterprise solution, media and communications firms · Global

Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.

Fake Job Offer / Recruitment Lure
Confirmed1 source
February 2026·Cryptocurrency

Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware

An unnamed cryptocurrency company executive · Unknown

Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
October 14, 2025·ConsumerCampaign

Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds

Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign) · Cambodia

On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.

Romance / Investment Scam
$15.0B assets seizedReported2 sources
September 8, 2025·ConsumerCampaign

US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud

US, European and Chinese scam victims (multi-victim campaign) · Myanmar and Cambodia

On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.

Fake Job Offer / Recruitment Lure
$10.0B multi-victim totalConfirmed2 sources
August 2025·Technology

North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs

US Fortune 500 technology companies employing fraudulent remote workers · United States

In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.

Fake IT Worker InfiltrationConfirmed AI-enabled
Reported2 sources
April 2025·TechnologyCampaign

North Korean operatives adopt real-time deepfakes to pass remote job interviews

Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate · United States

In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed2 sources
July 15, 2024·Technology

KnowBe4 hired a North Korean fake IT worker who loaded malware on day one

KnowBe4 · United States

Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed3 sources
May 2024·Cryptocurrency

LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft

DMM Bitcoin, via wallet software vendor Ginco · Japan

Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.

Fake Job Offer / Recruitment Lure
$308.0M funds lostConfirmed2 sources
July 22, 2023·Cryptocurrency

Fake recruiter's coding test cost payment processor CoinsPaid $37M

CoinsPaid · Estonia

Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.

Fake Job Offer / Recruitment Lure
$37.0M funds lostReported2 sources
May 8, 2023·Technology

Dragos intrusion began with the hijacked personal email of an employee due to start work

Dragos · United States

Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.

Fake Job Offer / Recruitment LureAttempt blocked
Confirmed2 sources
March 23, 2022·Cryptocurrency

Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF

Sky Mavis (Ronin Network / Axie Infinity) · Vietnam

On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.

Fake Job Offer / Recruitment Lure
$620.0M funds lostConfirmed4 sources
2022·Defense

Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge

Unnamed aerospace company in Spain · Spain

ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.

Fake Job Offer / Recruitment Lure
Confirmed3 sources
December 8, 2021·ConsumerBenchmark

FTC data: $147.8M in gift card fraud driven by government and business impersonators

US consumers (multi-victim campaign) · United States

An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.

Vishing (Voice Phishing)
$147.8M multi-victim total39K affectedConfirmed1 source
February 2016·Financial Services

Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails

Bangladesh Bank (central bank of Bangladesh) · Bangladesh

In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.

Spear Phishing (Email)
$81.0M funds lostReported3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Fake+Job+Offer+%2F+Recruitment+Lure.