Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 100 entries
August 24, 2026·Technology

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · United States

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
August 7, 2026·Retail

Levi Strauss files 8-K after social engineering compromises three employee computers

Levi Strauss & Co. · United States

Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.

Vishing (Voice Phishing)
Confirmed2 sources
August 6, 2026·Financial Services

Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks

Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States

BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.

Vishing (Voice Phishing)Attempt blocked
$10.6M criminal proceedsConfirmed1 source
July 13, 2026·Consumer

Brinks Home breached after Microsoft Entra vishing call to an employee

Brinks Home · United States

Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.

Vishing (Voice Phishing)
Confirmed2 sources
July 6, 2026·Financial Services

Apollo Global Management breached by BlackFile callers posing as IT support

Apollo Global Management · United States

Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.

Vishing (Voice Phishing)
Confirmed2 sources
July 2026·Technology

RingCentral data on 1.6M accounts leaked after social engineering campaign

RingCentral · United States

Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.

Vishing (Voice Phishing)
1.6M affectedConfirmed2 sources
June 2026·Healthcare

Abbott investigates ShinyHunters claim after mid-June vishing on employees

Abbott Laboratories (legacy Exact Sciences systems) · United States

ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.

Vishing (Voice Phishing)
Reported2 sources
May 29, 2026·Healthcare

Quantum Health network breached after social engineering call to a user

Quantum Health · United States

A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.

Vishing (Voice Phishing)
Reported1 source
May 6, 2026·ManufacturingCampaign

MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices

Multiple organisations in the United States and MENA (unnamed) · United States and Middle East / North Africa

Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.

Help Desk Impersonation
Reported2 sources
May 2026·Professional Services

Cushman & Wakefield confirms vishing-triggered Salesforce data theft

Cushman & Wakefield · United States

Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.

Vishing (Voice Phishing)
Confirmed2 sources
May 2026·OtherCampaign

UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls

Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services · Global

Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.

Help Desk Impersonation
$10.6M criminal proceedsConfirmed2 sources
April 29, 2026·Government

City of Aurora loses $1.1M after employee falls for bank impersonation call

City of Aurora, Illinois · United States

On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.

Vishing (Voice Phishing)
$1.1M funds lostConfirmed2 sources
April 20, 2026·Consumer

ADT confirms breach after vishing attack on employee's Okta SSO account

ADT · United States

ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.

Vishing (Voice Phishing)Suspected AI-enabled
Confirmed2 sources
April 14, 2026·Hospitality

Carnival confirms social engineering of an employee account exposed 6 million customers

Carnival Corporation · United States

Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.

Vishing (Voice Phishing)
6.0M affectedReported3 sources
April 1, 2026·Telecom

Charter Communications breach of 4.9M accounts began with an Entra vishing call

Charter Communications (Spectrum) · United States

ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.

Vishing (Voice Phishing)
4.9M affectedConfirmed2 sources
March 2026·Technology

Identity protection firm Aura breached in vishing attack; ~900,000 records taken

Aura · United States

Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.

Vishing (Voice Phishing)
900K affectedReported1 source
February 19, 2026·Financial Services

Figure Technology loses ~967,000 customer records after employee falls for SSO vishing

Figure Technology Solutions · United States

Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.

Vishing (Voice Phishing)
967K affectedReported3 sources
February 13, 2026·Technology

CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes

CarGurus · United States

Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.

Vishing (Voice Phishing)
Reported2 sources
February 11, 2026·Technology

Optimizely confirms data breach after vishing attack on employees

Optimizely · United States

Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.

Vishing (Voice Phishing)
Confirmed1 source
February 4, 2026·Healthcare

Hims & Hers support tickets stolen through compromised Okta SSO accounts

Hims & Hers Health · United States

Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.

Credential Phishing Portal
Confirmed2 sources
February 2026·RetailCampaign

BlackFile extortion gang runs vishing campaign against retail and hospitality

Multiple retail and hospitality organisations (unnamed) · United States

BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.

Vishing (Voice Phishing)
Confirmed1 source
February 2026·Manufacturing

STAC4749 Teams vishing campaign led to Chaos ransomware in North America

Dozens of North American organisations (unnamed) · Canada

Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.

Vishing (Voice Phishing)
Confirmed1 source
February 2026·Telecom

Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers

Odido (and subsidiary Ben) · Netherlands

Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.

Vishing (Voice Phishing)
6.2M affectedReported3 sources
February 2026·Telecom

Odido: IT impersonation calls and MFA approval requests expose 6.2M customers

Odido · Netherlands

Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.

Vishing (Voice Phishing)
6.2M affectedConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Vishing+%28Voice+Phishing%29.