Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 12 of 12 entries
May 2026·EducationCampaign

700+ education and tech sites hijacked to serve ClickFix paste-the-command lures

Visitors to 700+ compromised university and technology company websites · Global

Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.

Watering Hole / Malvertising
Confirmed1 source
January 2026·TechnologyCampaign

CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands

Users of malicious Chrome extension impersonating uBlock Origin Lite · Global

Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.

Watering Hole / Malvertising
Confirmed1 source
July 22, 2025·HealthcareCampaign

Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access

Multiple businesses and critical infrastructure organisations (campaign) · Multiple

A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.

Watering Hole / Malvertising
Confirmed3 sources
2025·OtherCampaign

ClickFix fake-CAPTCHA social engineering floods the threat landscape

Multiple organisations and consumers (technique) · Multiple

Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.

Watering Hole / Malvertising
Confirmed3 sources
November 2024·ConsumerCampaign

Deepfake Elon Musk videos drive crypto investment scams against US consumers

Multiple US consumers · United States

By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources
May 8, 2024·Healthcare

Ascension ransomware attack began when an employee downloaded a malicious file

Ascension · United States

Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.

Spear Phishing (Email)
5.6M affectedConfirmed2 sources
January 2024·ConsumerCampaign

AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads

Multiple US consumers; brands Taylor Swift and Le Creuset impersonated · United States

In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.

Watering Hole / MalvertisingConfirmed AI-enabled
Reported2 sources
May 2022·Government

Ghostwriter credential phishing against Ukrainian government and military accounts

Ukrainian government and military personnel · Ukraine

Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.

Credential Phishing PortalAttempt blocked
Confirmed1 source
July 23, 2020·Technology

Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed

Garmin Ltd. · United States

Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.

Watering Hole / Malvertising
Alleged3 sources
May 12, 2017·ConsumerCampaign

Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups

US consumers (multi-victim campaign) · United States

On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.

Tech Support Scam
Confirmed1 source
2017·Energy & Utilities

Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign

Wolf Creek Nuclear Operating Corporation · United States

A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.

Spear Phishing (Email)
Confirmed2 sources
April 2011·Professional Services

Epsilon email marketing breach exposes address lists of banks and retailers

Epsilon Data Management and other email service providers · United States

In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.

Spear Phishing (Email)
$2.0M criminal proceeds1.0B affectedConfirmed1 source

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Watering+Hole+%2F+Malvertising.