Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Six-month DPRK social engineering operation preceded $285M Drift Protocol theft
Drift Protocol · Unknown
Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.
BlackFile extortion gang runs vishing campaign against retail and hospitality
Multiple retail and hospitality organisations (unnamed) · United States
BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.
25 Canadians charged over $21M grandparent scam targeting seniors in 40 states
Elderly US residents in more than 40 states (multi-victim campaign) · United States and Canada
On 5 March 2025 US authorities announced charges against 25 Canadian nationals over a grandparent scam run from call centers in and around Montreal that defrauded elderly people in more than 40 states of over $21 million. Twenty-three defendants were arrested on 4 March and two remained at large. Money was moved to Canada after cash pickups, sometimes through cryptocurrency, to obscure its source.
SIM swap of the SEC's X account posted a fake Bitcoin ETF approval
U.S. Securities and Exchange Commission · United States
On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.
SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night
FTX (referred to as 'Victim 1' in the indictment) · United States
On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.
Sarah Palin Yahoo email account taken over via password-reset questions
Sarah Palin (then Governor of Alaska and vice-presidential candidate) · United States
During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.
HP boardroom pretexting scandal: investigators impersonate directors to phone carriers
Hewlett-Packard directors, journalists and their family members · United States
California Attorney General Bill Lockyer filed criminal charges on 4 October 2006 against former HP chairwoman Patricia Dunn, former HP ethics chief Kevin Hunsaker and three outside investigators. To identify the source of boardroom leaks to the press, investigators obtained the private telephone billing records of 12 people by impersonating them to phone carriers. Personal identifying information for 13 board members, journalists and family members was obtained and used unlawfully. Each defendant faced four felony counts.
Kevin Mitnick's telecom pretexting campaign and 1995 arrest
Pacific Bell, Digital Equipment Corporation and other telecommunications and computer firms · United States
Kevin Mitnick was arrested by the FBI in Raleigh, North Carolina on 15 February 1995 and found with cloned cellular phones, more than 100 cloned cellular phone codes and multiple pieces of false identification. In 1999 he pleaded guilty to four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting wire communications, and admitted copying proprietary software from large cellular telephone and computer companies. He was sentenced to 46 months plus 22 months for violating supervised release. His case is the formative reference point for social engineering as a discipline.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Physical+Pretexting.