Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 80 entries
July 2026·OtherCampaign

Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts

Corporate Microsoft 365 users across a dozen countries · Global

French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.

Credential Phishing Portal
Confirmed1 source
July 2026·GovernmentCampaign

Armored Likho spear phishing targets government and power sector in three countries

Government agencies and electric power organisations in Russia, Brazil and Kazakhstan · Russia

Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.

Spear Phishing (Email)
Confirmed1 source
July 2026·DefenseCampaign

Lazarus pairs fake recruiter approaches with a Windows zero-day

Defence and aerospace organisations in Western Europe, India and South America · Global

Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.

Fake Job Offer / Recruitment Lure
Confirmed1 source
March 2026·OtherCampaign

Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month

Organisations across education, healthcare, finance, nonprofit and government · Global

Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.

Credential Phishing PortalAttempt blocked
Confirmed2 sources
February 2026·Telecom

Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers

Odido (and subsidiary Ben) · Netherlands

Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.

Vishing (Voice Phishing)
6.2M affectedReported3 sources
February 2026·Telecom

Odido: IT impersonation calls and MFA approval requests expose 6.2M customers

Odido · Netherlands

Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.

Vishing (Voice Phishing)
6.2M affectedConfirmed2 sources
January 20, 2026·Healthcare

Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients

Xsolis · United States

Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.

Spear Phishing (Email)
1.4M affectedConfirmed2 sources
January 19, 2026·Hospitality

Starbucks employee data stolen via cloned Partner Central login pages

Starbucks · United States

Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.

Credential Phishing Portal
900 affectedConfirmed2 sources
January 8, 2026·GovernmentCampaign

FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government

Think tanks, academic institutions and government entities · United States

The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.

QR Code Phishing
Confirmed2 sources
November 2025·Education

Princeton advancement database breached in targeted phishing attack

Princeton University · United States

Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.

Spear Phishing (Email)
Confirmed2 sources
October 31, 2025·Education

University of Pennsylvania donor systems breached via social engineering

University of Pennsylvania · United States

The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.

Credential Phishing Portal
Confirmed2 sources
September 16, 2025·TechnologyCampaign

Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service

Microsoft 365 customers in 94 countries, including US healthcare organisations · United States

Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.

Credential Phishing PortalConfirmed AI-enabled
5.0K affectedConfirmed2 sources
August 2025·Other

Claude Code used to automate extortion of at least 17 organisations

At least 17 organisations across healthcare, emergency services, government and religious institutions · United States

Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.

Credential Phishing PortalConfirmed AI-enabled
Reported2 sources
August 2025·OtherCampaign

Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud

Approximately 88,000 victims across 18 African countries and the UK · Multiple

Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.

Business Email Compromise
$485.0M multi-victim totalConfirmed2 sources
July 24, 2025·Cryptocurrency

Crypto exchange WOO X loses $14 million after staff member phished

WOO X · Taiwan

Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.

Spear Phishing (Email)
$14.0M funds lostConfirmed2 sources
June 18, 2025·ConsumerCampaign

DOJ moves to forfeit $225M in crypto traced to pig butchering victims

US consumers (multi-victim campaign) · United States

On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.

Romance / Investment Scam
$19.4M multi-victim total434 affectedConfirmed3 sources
June 2025·NonprofitCampaign

Russian state-linked actors phish app-specific passwords from academics and critics

Academics, journalists and Russia critics (individuals not named) · Multiple

Google Threat Intelligence and Citizen Lab jointly documented a campaign in June 2025 in which a Russian government-linked cluster tracked as UNC6293 persuaded targets to create Google application-specific passwords and hand them over. Victims included prominent academics and critics of Russia. The technique bypassed multi-factor authentication entirely and gave the attackers durable mailbox access.

Spear Phishing (Email)
Confirmed2 sources
May 8, 2025·Cryptocurrency

Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft

BitoPro · Taiwan

Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.

Spear Phishing (Email)
$11.5M funds lostReported2 sources
March 3, 2025·Healthcare

Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients

Arizona Arthritis and Rheumatology Associates · United States

Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.

Credential Phishing Portal
5.5K affectedConfirmed1 source
March 3, 2025·Healthcare

Monongalia Health System email phishing breach affects 4,895 patients

Monongalia Health System (Mon Health) · United States

West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.

Credential Phishing Portal
4.9K affectedConfirmed1 source
February 21, 2025·Cryptocurrency

Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI

Bybit · United Arab Emirates

On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.

Vendor / Supply Chain Impersonation
$1.5B funds lostConfirmed5 sources
February 13, 2025·GovernmentCampaign

Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts

Multiple government, NGO, defence and energy organisations · Multiple

Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.

Spear Phishing (Email)
Confirmed2 sources
January 2025·Financial Services

VC firm Insight Partners breached through social engineering attack

Insight Partners · United States

New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.

Spear Phishing (Email)
Confirmed2 sources
2025·OtherCampaign

ClickFix fake-CAPTCHA social engineering floods the threat landscape

Multiple organisations and consumers (technique) · Multiple

Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.

Watering Hole / Malvertising
Confirmed3 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Spear+Phishing+%28Email%29.