Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 17 of 17 entries
April 13, 2026·Cryptocurrency

Kraken refuses extortion after two support insiders accessed client data

Kraken · United States

CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.

Insider RecruitmentAttempt blocked
2.0K affectedConfirmed1 source
November 20, 2025·TelecomCampaign

Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders

AT&T and T-Mobile customers, including four Manhattan residents · United States

Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.

Insider Recruitment
$435K multi-victim totalAlleged1 source
November 3, 2025·Professional Services

US ransomware negotiators charged with running their own BlackCat attacks

US medical device company, pharmaceutical firm, drone maker and other victims · United States

US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.

Insider Recruitment
$1.3M ransom paidConfirmed2 sources
November 2025·Technology

Five plead guilty to helping North Korean IT workers infiltrate 136 US companies

136 US companies (victims of the fake-worker scheme) · United States

The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.

Fake IT Worker Infiltration
$2.2M criminal proceedsConfirmed2 sources
September 8, 2025·ConsumerCampaign

US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud

US, European and Chinese scam victims (multi-victim campaign) · Myanmar and Cambodia

On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.

Fake Job Offer / Recruitment Lure
$10.0B multi-victim totalConfirmed2 sources
July 24, 2025·Technology

Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm

More than 300 US companies (victims of the fake-worker scheme) · United States

A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.

Fake IT Worker Infiltration
$17.0M criminal proceedsConfirmed2 sources
June 30, 2025·TechnologyCampaign

US sweep seizes 200 computers from North Korean IT worker laptop farms

More than 100 US companies, including many Fortune 500 firms · United States

On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.

Fake IT Worker Infiltration
Confirmed2 sources
May 15, 2025·Cryptocurrency

Bribed overseas support agents leaked Coinbase data; $20M extortion refused

Coinbase · United States

Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.

Insider Recruitment
69K affectedConfirmed3 sources
May 2025·Cryptocurrency

Binance and Kraken block bribery attempts aimed at support staff

Binance and Kraken · United States

In the weeks around the Coinbase insider breach, the same style of attack was attempted against Binance and Kraken. Bloomberg-sourced reporting said threat actors approached customer support staff at both exchanges over Telegram and offered bribes for system access and customer data. Both exchanges detected and blocked the approaches, and neither reported any user data exposure.

Insider RecruitmentAttempt blocked
Reported1 source
March 17, 2025·Technology

Rippling sues Deel over a manager allegedly recruited as a corporate spy

Rippling · United States

On March 17, 2025 Rippling sued rival HR and payroll company Deel in the Northern District of California, alleging Deel cultivated a Rippling employee as a spy. The complaint says the employee searched Rippling systems for 'Deel' an average of 23 times a day over four months and accessed Slack channels more than 6,000 times without business justification, funnelling sales pipeline data, pricing, customer churn lists and employee contact details to Deel. Deel denies wrongdoing and the litigation continues.

Insider Recruitment
Alleged2 sources
March 2022·Telecom

LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code

T-Mobile US · United States

Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.

SIM Swap
Confirmed2 sources
August 2020·Manufacturing

Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory

Tesla, Inc. · United States

Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.

Insider RecruitmentAttempt blocked
Confirmed1 source
May 2020·Gaming & Casino

Hacker bribed a Roblox support contractor to access user data and reset accounts

Roblox Corporation · United States

A hacker bribed a Roblox customer support representative, listed publicly as an in-game support contractor, to obtain access to the company's customer support panel. The panel exposed personal data on Roblox's user base and allowed password resets, removal of two-factor authentication, account bans and data changes. Roblox said it acted immediately, notified the small number of affected customers, and reported the hacker to HackerOne.

Insider Recruitment
Reported2 sources
October 2018·Telecom

Mobile carrier employee took $500-a-day bribes to perform SIM swaps

Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers · United States

A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.

Insider Recruitment
19 affectedConfirmed1 source
July 20, 2018·ConsumerCampaign

India-based IRS and USCIS impersonation call centers: 24 defendants sentenced

US consumers, many of them elderly (multi-victim campaign) · United States and India

On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.

Vishing (Voice Phishing)
$9.0M multi-victim totalConfirmed1 source
January 2018·Cryptocurrency

AT&T SIM swap drains $24M in crypto from investor Michael Terpin

Michael Terpin (individual investor; Transform Group) · United States

Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.

SIM Swap
$24.0M funds lostConfirmed2 sources
2018·Cryptocurrency

Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree

Approximately 40 individual cryptocurrency holders · United States

Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.

SIM Swap
$7.5M multi-victim totalConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Insider+Recruitment.