Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 23 of 23 entries
November 2025·ConsumerCampaign

Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams

Consumers and card issuers worldwide (Google plaintiff) · United States

In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.

Smishing (SMS)
Confirmed2 sources
October 14, 2025·ConsumerCampaign

Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds

Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign) · Cambodia

On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.

Romance / Investment Scam
$15.0B assets seizedReported2 sources
September 18, 2025·Other

US and UK charge Scattered Spider pair tied to $115M in ransom payments

47 US organisations including healthcare, transport and technology firms · United States

On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.

Help Desk Impersonation
$115.0M multi-victim totalConfirmed2 sources
August 6, 2025·Technology

Workday discloses CRM breach after social engineering of employees

Workday · United States

Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.

Vishing (Voice Phishing)
Confirmed2 sources
August 2025·Cryptocurrency

Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts

Cryptocurrency holders and companies targeted by the group · United States

A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.

SIM Swap
$13.0M funds lostConfirmed2 sources
June 18, 2025·ConsumerCampaign

DOJ moves to forfeit $225M in crypto traced to pig butchering victims

US consumers (multi-victim campaign) · United States

On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.

Romance / Investment Scam
$19.4M multi-victim total434 affectedConfirmed3 sources
June 2025·Government

Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers

US State Department; three foreign ministers, a US governor and a member of Congress · United States

In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed2 sources
May 19, 2025·Financial ServicesCampaign

UK 'safe account' bank and police impersonation drives £450.7M in APP fraud

UK banking customers (multi-victim campaign) · United Kingdom

UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.

Vishing (Voice Phishing)
186K affectedConfirmed2 sources
May 15, 2025·GovernmentCampaign

FBI warns of AI voice-cloning campaign impersonating senior US officials

Current and former senior US federal and state officials and their contacts · United States

On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.

Voice Clone / Audio DeepfakeConfirmed AI-enabled
Confirmed2 sources
May 2025·Government

AI voice impersonation of White House chief of staff Susie Wiles targets Republicans

The White House; senators, governors and business executives contacted · United States

In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.

Voice Clone / Audio DeepfakeSuspected AI-enabledAttempt blocked
Reported2 sources
March 2025·Other

Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO

Unnamed multinational firm, Singapore office · Singapore

On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.

Deepfake Video CallConfirmed AI-enabled
$499K funds lostConfirmed1 source
July 2024·Manufacturing

Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question

Ferrari · Italy

In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Reported2 sources
April 12, 2024·Transportation & LogisticsCampaign

Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks

US drivers and toll customers (multi-victim campaign) · United States

On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.

Smishing (SMS)
2.0K affectedConfirmed1 source
April 2024·Technology

LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO

LastPass · United States

On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.

Voice Clone / Audio DeepfakeConfirmed AI-enabledAttempt blocked
Confirmed3 sources
August 27, 2023·Technology

Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee

Retool · United States

Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.

Smishing (SMS)Confirmed AI-enabled
27 affectedConfirmed4 sources
February 5, 2023·Cryptocurrency

Coinbase employee phished by SMS then talked through by a fake IT caller

Coinbase · United States

In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.

Smishing (SMS)Attempt blocked
Confirmed3 sources
2023·ConsumerBenchmark

FTC: business and government impersonation scams hit $1.1 billion in 2023

US consumers (multi-victim campaign) · United States

An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.

Tech Support Scam
$1.1B multi-victim total490K affectedConfirmed1 source
December 4, 2022·Gaming & Casino

Activision breached after an HR employee falls for an SMS phishing message

Activision Blizzard · United States

Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.

Smishing (SMS)
19K affectedReported4 sources
October 2022·Technology

Zendesk breach followed successful SMS phishing of employees

Zendesk · United States

Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.

Smishing (SMS)
Reported3 sources
August 25, 2022·Transportation & Logistics

DoorDash customer data exposed through phished third-party vendor employees

DoorDash · United States

DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.

Vendor / Supply Chain Impersonation
Confirmed3 sources
August 4, 2022·Technology

Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers

Twilio · United States

In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.

Smishing (SMS)
Confirmed4 sources
August 2022·TechnologyCampaign

0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations

Over 130 organisations targeted (Group-IB tracked campaign) · United States

Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.

Smishing (SMS)
9.9K affectedConfirmed2 sources
July 20, 2022·Technology

Cloudflare blocks the same SMS phishing attack that breached Twilio

Cloudflare · United States

On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.

Smishing (SMS)Attempt blocked
Confirmed3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Smishing+%28SMS%29.