Social engineering incidents
277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.
Six-month DPRK social engineering operation preceded $285M Drift Protocol theft
Drift Protocol · Unknown
Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.
Crunchyroll support tickets stolen via compromised BPO agent SSO account
Crunchyroll · United States
On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.
Contagious Interview: fake developer job interviews deliver backdoors
Software developers at enterprise solution, media and communications firms · Global
Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.
Dickinson Public Schools loses $4.92M to vendor-impersonation BEC
Dickinson Public Schools · United States
Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.
Stellantis confirms customer data stolen from Salesforce platform
Stellantis · Netherlands
Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.
Air France and KLM disclose breach of third-party customer service platform
Air France-KLM · France
Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.
Chanel notifies US clients after third-party client-care database breach
Chanel · United States
Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.
Pandora warns customers after third-party platform breach
Pandora A/S · Denmark
Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.
TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs
TransUnion · United States
Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.
Allianz Life's Salesforce CRM emptied after social engineering
Allianz Life Insurance Company of North America · United States
Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.
Qantas contact centre platform breached after help desk tricked into adding MFA
Qantas Airways · Australia
Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.
Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility
HPS Investment Partners (BlackRock) · United States
HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.
BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware
Employee of a cryptocurrency foundation (Web3 sector) · United States
In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.
Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers
Farmers Insurance · United States
Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.
Adidas customer data stolen through third-party customer service provider
Adidas · Germany
Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.
Marks & Spencer attack tied to social engineering of outsourced service desk
Marks & Spencer Group plc · United Kingdom
Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.
Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI
Bybit · United Arab Emirates
On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.
DPRK actor posing as a former contractor took $50M from Radiant Capital
Radiant Capital · Unknown
Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.
Iran's APT42 phishes Israeli and US officials with think-tank impersonation
Current and former Israeli and US government officials, diplomats and political campaign staff · Israel and United States
On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.
WazirX signers approved a spoofed transaction and lost $235M
WazirX · India
Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.
LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft
DMM Bitcoin, via wallet software vendor Ginco · Japan
Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.
Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs
Cisco Duo (via an unnamed telephony supplier) · United States
Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.
FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)
Aggregate: U.S. and international BEC victims reporting to FBI IC3 · United States
The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.
Ledger Connect Kit poisoned after a former employee's npm account was phished
Ledger SAS · France
On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.
Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vendor+%2F+Supply+Chain+Impersonation.