Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 12 of 12 entries
August 24, 2026·Technology

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · United States

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
February 2026·Telecom

Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers

Odido (and subsidiary Ben) · Netherlands

Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.

Vishing (Voice Phishing)
6.2M affectedReported3 sources
February 2026·Telecom

Odido: IT impersonation calls and MFA approval requests expose 6.2M customers

Odido · Netherlands

Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.

Vishing (Voice Phishing)
6.2M affectedConfirmed2 sources
January 2026·Media & Entertainment

SoundCloud hit as real-time vishing kits drive browsers through SSO logins

SoundCloud · Germany

A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.

Vishing (Voice Phishing)
36.0M affectedReported1 source
January 2026·Financial ServicesCampaign

Okta SSO accounts targeted in vishing campaign against financial firms

Multiple fintech, wealth management and advisory firms (unnamed) · United States

BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed1 source
July 2025·OtherCampaign

Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware

US retail, airline, transportation and insurance organisations · United States

Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.

Help Desk Impersonation
Confirmed2 sources
May 21, 2025·Other

3AM ransomware affiliate used email bombing plus spoofed IT support calls

Unnamed Sophos client · Unknown

Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
April 22, 2025·Retail

Marks & Spencer attack tied to social engineering of outsourced service desk

Marks & Spencer Group plc · United Kingdom

Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.

Help Desk Impersonation
Confirmed6 sources
July 30, 2024·Healthcare

Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients

Michigan Medicine (University of Michigan) · United States

Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.

MFA Fatigue / Push Bombing
58K affectedConfirmed2 sources
September 15, 2022·Transportation & Logistics

Uber breached after MFA push bombing and a WhatsApp message posing as IT

Uber Technologies · United States

In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.

MFA Fatigue / Push Bombing
Confirmed5 sources
May 24, 2022·Technology

Cisco breached after vishing and MFA fatigue against an employee

Cisco Systems · United States

Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.

MFA Fatigue / Push Bombing
Confirmed3 sources
March 2022·Telecom

LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code

T-Mobile US · United States

Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.

SIM Swap
Confirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=MFA+Fatigue+%2F+Push+Bombing.