Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
700+ education and tech sites hijacked to serve ClickFix paste-the-command lures
Visitors to 700+ compromised university and technology company websites · Global
Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.
Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware
An unnamed cryptocurrency company executive · Unknown
Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.
STAC4749 Teams vishing campaign led to Chaos ransomware in North America
Dozens of North American organisations (unnamed) · Canada
Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.
$282M in Bitcoin and Litecoin stolen from a holder via social engineering
Unnamed cryptocurrency holder · Unknown
On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.
CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands
Users of malicious Chrome extension impersonating uBlock Origin Lite · Global
Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.
Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access
Multiple businesses and critical infrastructure organisations (campaign) · Multiple
A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.
DOJ moves to forfeit $225M in crypto traced to pig butchering victims
US consumers (multi-victim campaign) · United States
On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.
Bribed overseas support agents leaked Coinbase data; $20M extortion refused
Coinbase · United States
Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.
FBI warns Silent Ransom Group is callback-phishing US law firms
US law firms and legal services organisations (campaign) · United States
The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.
'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders
Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully · Multiple
From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.
ClickFix fake-CAPTCHA social engineering floods the threat landscape
Multiple organisations and consumers (technique) · Multiple
Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.
Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin
An individual Genesis creditor in Washington, D.C. · United States
On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.
Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta
Multiple organisations (campaign) · Multiple
Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.
FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings
US senior citizens (multi-victim campaign) · United States
On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.
Coinbase employee phished by SMS then talked through by a fake IT caller
Coinbase · United States
In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.
FTC: business and government impersonation scams hit $1.1 billion in 2023
US consumers (multi-victim campaign) · United States
An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.
FTC data: $147.8M in gift card fraud driven by government and business impersonators
US consumers (multi-victim campaign) · United States
An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.
Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups
US consumers (multi-victim campaign) · United States
On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Tech+Support+Scam.