Methodology
Two things on this site carry numbers: the catalogue, which is a count of what has been documented, and the impact counters, which are estimates of something far larger than the catalogue. They are built differently and should be read differently.
What gets included
An entry qualifies when a decisive step in the attack was a person being deceived. That covers the obvious cases and some that are usually filed elsewhere: a ransomware intrusion that began with a phone call to a help desk belongs here, and a breach that began with a credential bought from an infostealer log does not, however similar the aftermath looks.
Where the reporting is genuinely ambiguous about the entry point, the entry either says so plainly and carries a lower confidence rating, or it is left out. Several widely-cited breaches were excluded on exactly this basis, because the confirmed initial access turned out to be a credential on a system without MFA rather than a human being talked into something.
Every entry cites its sources. 577 source links across 277 entries, and no entry is published without at least one. Where a primary outlet blocks automated access, a verified secondary report stands alongside the citation of the original.
The three entry types
- Incident. A single, dated attack against an identifiable target.
- Campaign. A sustained operation or multi-victim wave rather than one dated breach. Loss figures are campaign-wide.
- Benchmark. An aggregate statistic published by an agency, kept for context. Not counted as an incident and never summed into the counters.
Money figures are not interchangeable
The single most common way to get a database like this wrong is to add up a column labelled “loss”. Published figures measure very different things: an agency total covering 240,000 victims, the dollar value of assets a prosecutor seized, a quarter of lost supermarket revenue, and money wired to a fraudster are four different quantities. Every figure here therefore carries a loss kind, and only the first two below are ever summed, on this site or in the API.
- Funds lost. Money actually taken from, or wired out by, the victim. Summed. 51 entries.
- Ransom paid. An extortion payment the victim chose to make. Summed. 3 entries.
- Business impact. Lost revenue, earnings impact, remediation cost, a settlement or damages sought. Not money stolen. Never summed. 11 entries.
- Criminal proceeds. What the attackers earned. Not the same as what the victims lost, and often much smaller. Never summed. 7 entries.
- Multi-victim total. A total across many victims, or an agency-wide statistic. Overlaps with other entries by construction. Never summed. 16 entries.
- Assets seized. The value of assets seized or forfeited by authorities, not a victim loss. Never summed. 1 entries.
Sorting by largest loss ranks comparable victim losses first for the same reason. If you are pulling this data through the API, read loss_kind before you compare or add anything.
Confidence ratings
- Confirmed. The victim, a court, or an investigating authority has stated it. 190 entries.
- Reported. Credible reporting establishes it, but the victim has not confirmed the detail. 76 entries.
- Alleged. Claimed, often by the attacker, and not independently established. 6 entries.
Known limits
- Coverage skews to English-language reporting and to incidents involving organisations large enough to be newsworthy. Most social engineering never reaches a reporter.
- Comparable victim-loss figures exist for only 54 entries, so the catalogue total of $5.37B is a floor, not a measurement.
- Recent years are denser than early ones. A rising line on the year chart is partly a rising rate of reporting.
- The “control that would have caught it” on each entry is our editorial reading, not a claim any source made, and is shown as a separate block for that reason.
- Entries summarise public reporting. They are not legal findings, and details change as investigations conclude. Corrections are welcome through the submission form.
The two impact counters
The counters on the homepage do not measure this catalogue. They estimate worldwide impact, which is orders of magnitude larger than anything anyone has documented. Both are built from published figures, and both carry wide uncertainty that we would rather show than hide.
This number is an estimate, not a count. No one tallies the world's scam losses. Most victims never tell an authority, and the agencies that do publish figures cover only their own country.
The annual rate combines two verified figures. The Global Anti-Scam Alliance puts worldwide losses to online scams at $442 billion over the past year, extrapolated from a survey of 46,000 adults across 42 markets. To that we add $3.05 billion in business email compromise losses reported to the FBI's IC3 in 2025, because consumer surveys do not capture fraud aimed at organisations. Total: about $445 billion a year, roughly $14,100 per second.
The starting balance projects that rate back to 1 January 2015, using the FBI IC3 reported-loss series as the shape of the growth curve, then adds 2026 to date.
It covers money lost through deception: scams, fraud, business email compromise, impersonation. It excludes ransomware extortion, theft involving no human deception, and the cost of cleaning up afterwards.
This counter estimates how many people are affected each year and then accumulates. It is not a headcount of distinct human beings, and it leans high on purpose.
The rate starts from GASA's 2026 survey of US adults, in which 9% experienced financial or data loss from a scam in the previous year. Applied to the World Bank's 6.21 billion people aged 15 and over, that is about 559 million a year, roughly 18 per second. As a check: 9% of US adults is 25.5 million, and the ~1.14 million loss-bearing fraud reports the FTC received in 2025 would be 4.5% of that, closely matching GASA's separate finding that only 4% of US victims report to authorities.
The double counting is real and unavoidable. One person scammed three times in a year is counted three times. A breach exposes records, not verified people, and the same person's records recur across many breaches. Because the figure sums affected persons per year across eleven and a half years, the total exceeds world population. That is arithmetic, not a claim that everyone alive has been a victim. Read it as an upper-bound-leaning estimate of affected records and persons.
| Component | Value | Period | How it was arrived at |
|---|---|---|---|
| Worldwide consumer losses to online scams (annual) | $442.00B | 12 months to publication of GASA's 2025 Global State of Scams research | Taken directly from GASA's stated headline figure, '$442 Bn lost worldwide to online scams in the past year'. GASA derives this by extrapolating self-reported losses from a survey of 46,000 adults across 42 markets to national adult populations. This is the single largest and most global component; everything else in this model is either a supplement to it or a shape used to project it backwards. |
| Business email compromise losses (annual, US-reported floor) | $3.05B | calendar year 2025 | FBI IC3 2025 report: 24,768 BEC complaints totalling $3,046,598,558. Added because GASA surveys individuals and therefore does not capture social engineering aimed at organisations. Deliberately left unscaled: this is US complaints only, so the true worldwide BEC figure is larger, but no multiplier was applied because none could be verified from a fetched source. Context on scale: IC3 separately reports $55,499,915,582 in domestic and international BEC exposed losses between October 2013 and December 2023. |
| Annual run rate (sum) | $445.00B | current, treated as flat | 442,000,000,000 + 3,046,598,558 = 445,046,598,558, rounded DOWN to 445,000,000,000. Per second: 445,000,000,000 / 31,557,600 = 14,101.20. |
| Growth-shape index from the FBI IC3 reported-loss series | $81.58B | 2015 to 2025 inclusive | IC3 cumulative reported losses: $10.2B (2015-2019 five-year total, 2019 report) + $50.5B (2020-2024 five-year total, 2024 report) + $20.877B (2025 report) = $81.577B. Dividing by the 2025 figure of $20.877B gives 3.9075, i.e. the whole 2015-2025 period is worth 3.9075 times a single 2025. This ratio is used as the shape of the growth curve, on the neutral assumption that worldwide social-engineering losses grew at roughly the same rate as US reported losses. |
| Cumulative worldwide losses, 1 Jan 2015 to 31 Dec 2025 | $1.74T | 2015-01-01 to 2025-12-31 | 445,000,000,000 x 3.9075058677 = 1,738,840,111,127. Equivalent to holding the world-to-IC3 ratio (445 / 20.877 = 21.32) constant across the period. |
| 2026 year to date | $288.95B | 2026-01-01 to 2026-08-26 | 237 days elapsed (2026 is not a leap year). 445,000,000,000 x 237/365 = 288,945,205,479. The 2026 rate is held flat at the 2025 rate rather than extrapolated upward, which is conservative given every verified national series rose year on year. |
| Baseline shown on the counter at anchor date | $2.03T | 2015-01-01 to 2026-08-26 | 1,738,840,111,127 + 288,945,205,479 = 2,027,785,316,606, rounded to 2,027,785,316,607. The counter then accrues at 14,101.20 USD per second. |
| Corroborating national figures (not added, used as sanity checks) | $15.90B | calendar year 2025 | FTC: 3 million fraud reports and $15.9 billion in reported losses in 2025, of which imposter scams were more than $3.5 billion across more than 1 million reports. Alongside IC3's $20.877B, UK Finance's GBP 1,279.8m total payment fraud (GBP 576.4m of it APP fraud), and Australia's A$2.18 billion, officially reported losses across these large, well-instrumented economies total well under $50 billion. That gap against the $445B estimate is the measure of how much rests on survey extrapolation rather than counted transactions, and is why the confidence band below is wide. |
| World population aged 15 and over | 6.21B | 2025 | World Bank 2025: population ages 15-64 = 5,355,513,094, plus ages 65 and above = 854,604,026, total 6,210,117,120. Used as the exposed adult population. |
| Annual share of adults suffering financial or data loss from a scam | 558.91M | 12 months to early 2026 | GASA's State of Scams in the United States of America 2026 (n=3,110 US adults) reports that 82% encountered a scam in the past year and '9% experienced financial or data loss'. 0.09 x 6,210,117,120 = 558,910,541 people per year, or 17.71 per second. This is the model's weakest link and is flagged as such: it applies a single-country rate worldwide because no fetched source gave a global loss rate. Note that GASA's global survey finds 57% of adults worldwide were scammed in 12 months, so 9% suffering an actual loss is well inside that exposure figure rather than an extrapolation beyond it. |
| Cross-check against US official reporting | 1.14M | calendar year 2025 | Independent sanity check. 9% of the US 15+ population (220,498,172 + 62,844,750 = 283,342,922) is 25,500,863 victims. The FTC received 3 million fraud reports in 2025; applying the 38% loss rate from its 2024 data gives about 1,140,000 reports involving a loss, which is 4.47% of 25.5 million. GASA's US report independently finds that 'only 4% reported the incident to authorities'. Two unrelated sources landing on 4% versus 4.47% is meaningful support for the 9% rate. |
| Growth-shape index from IC3 complaint counts | 6.92M | 2015 to 2025 inclusive | IC3 complaints: 1,707,618 (2015-2019 total) + 4,200,000 (2020-2024 total) + 1,008,597 (2025) = 6,916,215. Divided by the 2025 count of 1,008,597 gives 6.8573, the people-side analogue of the money-side shape index. |
| Cumulative affected persons, 1 Jan 2015 to 31 Dec 2025 | 3.83B | 2015-01-01 to 2025-12-31 | 558,910,541 x 6.8572631 = 3,832,596,633. This is a sum of affected-persons-per-year, so an individual scammed in three different years contributes three times. |
| 2026 year to date | 362.91M | 2026-01-01 to 2026-08-26 | 558,910,541 x 237/365 = 362,909,036. |
| Baseline shown on the counter at anchor date | 4.20B | 2015-01-01 to 2026-08-26 | 3,832,596,633 + 362,909,036 = 4,195,505,669. The counter then accrues at 17.71 people per second. |
Plausible range $1.10T to $4.60T
The band is roughly half to roughly 2.3 times the central baseline, obtained by rerunning the same arithmetic with annual run rates of $250B and $1,000B. It is this wide for three compounding reasons. First, the dominant input is a survey extrapolation: GASA projects self-reported losses from 46,000 respondents onto billions of adults, and mean-versus-median effects and top-coding of very large individual losses can move such a total by a factor of two in either direction. Second, under-reporting is severe and unmeasured; GASA finds 59% of scam victims never report the incident at all, so counted official data cannot bound the true figure from above. Third, the backward projection assumes worldwide losses tracked the US IC3 series, and IC3's growth partly reflects rising awareness and reporting rather than rising crime, which would push the early years of the cumulative total downward.
Plausible range 2.10B to 8.40B
Half to double the central figure, from rerunning the arithmetic at loss rates of 4.5% and 18%. The band is this wide because a single US survey rate is being applied to the world, because 'financial or data loss' is a broader category than 'lost money' and different national surveys draw that line differently, and because the quantity being counted is itself ambiguous. Note that the upper bound exceeds world population. That is not an error: the figure sums affected persons per year over eleven and a half years, and a person can be counted in many of those years. See the tooltip.
The server calculates a total as of an anchor moment: the sourced baseline projected forward, plus every loss and impact figure in this catalogue. Right now that is $2,037,089,606,336 and 6,040,105,054 people, of which $5.37B and 1.8B come from the 54 and 56 entries here that carry a published figure. Your browser then extrapolates forward from that anchor at a flat rate of $14,101 and 17.7 per second, so the number always rises and every visitor sees the same value at the same moment.
It is not reacting to live events. Nobody has a live feed of the world’s fraud losses. When the catalogue changes, because a scheduled research pass adds incidents or an editor approves a submission, the anchor is recalculated from scratch and the counter snaps to the new total. That reset is deliberate: it stops the running number from drifting away from the evidence underneath it.
Every source behind the counters
"$442 Bn lost worldwide to online scams in the past year"; "57% of adults experienced a scam in 12 months"; "59% of scam victims never report the incident"; "45% encountered even more scams than the year before"
"seven in ten adults globally have encountered a scam in the last 12 months, with 13% encountering a scam at least once a day"; based on "46,000 adults across 42 markets". Feedzai's page for the same report states "57% of adults worldwide have been scammed in the past year". The monetary total is behind a membership wall on both pages; the $442Bn figure is therefore cited from GASA's own homepage instead.
"82% encountering a scam in the past year"; "9% experienced financial or data loss"; "only 4% reported the incident to authorities"; "86% say they are confident in recognizing scams, 43% still interacted with a scammer"; survey of 3,110 US adults
"1,008,597 complaints" generating "$20.877 billion in losses"; BEC: 24,768 complaints, $3,046,598,558 (versus $2,770,151,146 in 2024 and $2,946,830,270 in 2023)
2019 report five-year totals: "1,707,618 TOTAL COMPLAINTS" and "$10.2 Billion TOTAL LOSSES" (2015-2019). 2023 report: "880,418 complaints were registered, with potential losses exceeding $12.5 billion" and 2019-2023 totals of "3.79 million complaints, reporting a loss of $37.4 Billion". 2024 report: 859,532 complaints, $16.6 billion, and 2020-2024 five-year totals of "4.2 Million Complaints" and "$50.5 Billion in Losses". 2025 report: 1,008,597 complaints, $20.877 billion.
Cumulative exposed loss of $55,499,915,582, described as "Domestic and international exposed dollar loss" "reported to the FBI IC3, law enforcement and derived from filings with financial institutions between October 2013 and December 2023"
2025: "3 million fraud reports from consumers" and "$15.9 billion in losses". "The agency received more than 1 million reports about imposter scams, with consumers reporting more than $3.5 billion in losses." "Consumers, however, reported losing the most money ($7.9 billion) to investment scams in 2025." For 2024: "consumers submitted 2.6 million fraud reports and reported fraud losses of over $12 billion".
"consumers reported losing more than $12.5 billion to fraud in 2024, which represents a 25% increase over the prior year"; 2.6 million fraud reports; share of reports involving a monetary loss rose from 27% in 2023 to 38% in 2024; "The second highest reported loss amount came from imposter scams, with $2.95 billion reported lost"; government imposter scams $789 million
"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories." (Fraud is one subset of this total; the fraud-specific figures are in the accompanying press release.)
Social media scam losses "reaching a staggering $2.1 billion" in 2025, of which "$1.1 billion, more than half the money reported lost, was to investment scammers"; series $261M (2020), $789M (2021), $1.2B (2022), $1.5B (2023), $1.9B (2024), $2.1B (2025); "nearly 30% of people who reported losing money to a scam said it started on social media"
Total payment fraud losses 2025 "Total £1,279.8m" (criminals "stole £1.28 billion through payment fraud in 2025, an increase of four per cent"); authorised push payment fraud "Total £576.4m"; APP cases "Total 248,070"; all confirmed fraud cases "Total 4,062,198", an 11 per cent year-on-year increase
2025 combined reported losses "$2.18 billion (an increase of 7.8%)" from "481,523 scam reports (a decrease of 2.3%)", combining data from Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC
"Human element was present in 62% of breaches, a slight increase from the previous year's 60%." Social Engineering represented "16% of all breaches". Dataset of "more than 22,000 breaches" (22,345 breaches in the actor analysis).
Human element present in 60% of breaches (n=10,798 for the component analysis); Social Engineering 22% of incident classification patterns; 12,195 confirmed data breaches analysed, "the highest number of breaches ever analyzed in a single report"
World population ages 15-64 (2025): 5,355,513,094; ages 65 and above (2025): 854,604,026; world total population (2025): 8,215,424,893. United States ages 15-64 (2025): 220,498,172; ages 65 and above (2025): 62,844,750.
"Since the launch of INTERPOL's Global Rapid Intervention of Payments (I-GRIP) stop-payment mechanism in 2022, the Organization has helped member countries intercept more than USD 500 million in criminal proceeds, stemming largely from cyber-enabled fraud." INTERPOL describes "an epidemic in the growth of financial fraud" but publishes no worldwide loss total, which is why no INTERPOL figure enters the derivation.
Not a source. Marks derivation rows whose values are computed from the sourced rows above; the arithmetic is shown in full in each note field.
Submissions and review
Anyone can submit an incident. Nothing published on this site arrives automatically. Each submission goes into a private queue where an editor checks the sources actually say what the submission claims, normalises the fields to the controlled vocabulary, merges duplicates against existing entries, and either publishes it with a community contribution label or rejects it with a reason.
Submissions naming private individuals as victims in an identifying way, unverified accusations against named people or companies, claims sourced only to social media, and operational detail that would help someone run an attack rather than recognise one are not published.
Reuse
The catalogue is licensed CC BY 4.0. Attribute it to the Netarx Social Engineering Incident Database with a link to global-social-engineering-impact-da.vercel.app, and when you cite an entry, cite its underlying sources too. Machine access, including a filterable JSON API, bulk exports and an MCP server, is documented on the API page.