Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams
Consumers and card issuers worldwide (Google plaintiff) · United States
In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.
Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds
Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign) · Cambodia
On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.
US and UK charge Scattered Spider pair tied to $115M in ransom payments
47 US organisations including healthcare, transport and technology firms · United States
On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.
Workday discloses CRM breach after social engineering of employees
Workday · United States
Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.
Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts
Cryptocurrency holders and companies targeted by the group · United States
A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.
DOJ moves to forfeit $225M in crypto traced to pig butchering victims
US consumers (multi-victim campaign) · United States
On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.
Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers
US State Department; three foreign ministers, a US governor and a member of Congress · United States
In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.
UK 'safe account' bank and police impersonation drives £450.7M in APP fraud
UK banking customers (multi-victim campaign) · United Kingdom
UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.
FBI warns of AI voice-cloning campaign impersonating senior US officials
Current and former senior US federal and state officials and their contacts · United States
On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.
AI voice impersonation of White House chief of staff Susie Wiles targets Republicans
The White House; senators, governors and business executives contacted · United States
In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.
Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO
Unnamed multinational firm, Singapore office · Singapore
On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.
Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question
Ferrari · Italy
In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.
Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks
US drivers and toll customers (multi-victim campaign) · United States
On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.
LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO
LastPass · United States
On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.
Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee
Retool · United States
Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.
Coinbase employee phished by SMS then talked through by a fake IT caller
Coinbase · United States
In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.
FTC: business and government impersonation scams hit $1.1 billion in 2023
US consumers (multi-victim campaign) · United States
An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.
Activision breached after an HR employee falls for an SMS phishing message
Activision Blizzard · United States
Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.
Zendesk breach followed successful SMS phishing of employees
Zendesk · United States
Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.
DoorDash customer data exposed through phished third-party vendor employees
DoorDash · United States
DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.
Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers
Twilio · United States
In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.
0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations
Over 130 organisations targeted (Group-IB tracked campaign) · United States
Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.
Cloudflare blocks the same SMS phishing attack that breached Twilio
Cloudflare · United States
On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Smishing+%28SMS%29.