Case Library

Social Engineering Examples:
173 documented attacks.

Real incidents against named organisations. Each one records how the attacker got in, what it cost, and the control that would have stopped it.


What this library is for

When an attack reaches the news, two questions matter: how did it actually work, and would our own checks have caught it? Most published material answers neither.

173 cases. 170 confirmed by primary reporting or regulatory filings. Every figure on this page is counted from the records, not estimated.

173 cases·Updated 6 Sep 2026·How we verify

10
Attack Types

How the attacker got in.

22
Sectors

Who gets targeted.

7
Threat Actors

Who's behind the attack.

65
Companies

Named victims and targets.

18
Techniques

How the attack is carried out.


The 10 types of social engineering attack, ranked by how often they appear in real incidents

Counted from the 173 cases here, so this is what attackers actually ran rather than a taxonomy. Counts overlap where an attack crossed channels.

Attack typeWhat it isCasesA documented example
Phishing A deceptive email that impersonates a trusted sender to steal credentials or trigger a payment. 62 Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In (2013)
Vishing (Voice Phishing) A phone call. The attacker impersonates IT, a bank, or an executive and works in real time against your hesitation. 32 Retool smishing + deepfake vishing breach (2023) (2023, $15M)
Pretexting & Impersonation An invented but plausible scenario that gives the attacker a reason to be asking, built before any request is made. 28 Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025) (2024, $20K)
Physical Social Engineering (Tailgating & Baiting) Getting bodily into a building or dropping a malicious device, by tailgating an employee or posing as a contractor. 22 Tennant Co. v. Advance Machine Co. - Dumpster Diving / Conversion Punitive Damages Verdict (1978, $100K)
Agentic AI Attacks (AI-Powered Social Engineering) AI systems that research the target, write the lure, and carry the conversation, letting one operator run thousands of tailored attacks. 22 See hub
Smishing (SMS Phishing) The same deception delivered by SMS or a messaging app, where there is no sender address to inspect. 15 Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass) (2024)
Deepfake & Synthetic Media A cloned voice or face, used on a call or voicemail so the victim believes they are speaking to someone they know. 14 Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M) (2024, $25.6M)
ClickFix & SEO Poisoning A poisoned search result or a fake error telling the user to paste a command, so the victim installs the malware themselves. 8 See hub
Help-Desk & MFA Manipulation Calling the service desk as a locked-out employee to have MFA reset, which turns the recovery process into the way in. 8 Caesars Entertainment Vendor Social Engineering Breach (2023) (2023, $15M)
Quishing (QR Code Phishing) A QR code that carries the malicious link, moving the click onto a personal phone outside corporate filtering. 7 UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset (2024)

By the numbers
173
Documented cases
$2.3M
Median disclosed loss
10
Attack families
22
Countries represented
1978–2026
Years covered
46
Most-targeted sector: Financial Services & Insurance

Median disclosed loss across the 52 cases that state a figure in US dollars. We report a median rather than a total because the library records single-victim losses alongside campaign-wide and modelled estimates, and those cannot meaningfully be added together. Non-USD figures are left out rather than converted at a rate we cannot source.

The largest disclosed losses in the library

Sorted by the figure the victim or a regulator disclosed. Alleged means reported estimate, not confirmed accounting.

IncidentYearAttack typeSectorDisclosed lossStatus
Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M 2022 Phishing Cryptocurrency & Digital Assets $540M Confirmed
Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices 2013 Phishing Manufacturing & Industrial $122.1M Confirmed
Crelan Bank CEO Fraud (Belgium, 2016) 2016 Phishing Financial Services & Insurance $75.8M Confirmed
Orion S.A. $60M fraudulently induced wire transfers (2024) 2024 Phishing Manufacturing & Industrial $60M Confirmed
Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes) 2022 Smishing (SMS Phishing) Financial Services & Insurance $47.1M Confirmed
FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier 2016 Phishing Defense & Aerospace $47M Confirmed
Leoni AG CEO Fraud (2016) 2016 Phishing Manufacturing & Industrial $44.6M Confirmed
Ubiquiti Networks $46.7M business email compromise (2015) 2015 Phishing Technology & Software $39.1M Confirmed
Toyota Boshoku European Subsidiary $37M BEC (2019) 2019 Phishing Manufacturing & Industrial $37.5M Confirmed
Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M) 2024 Vishing (Voice Phishing) Construction & Engineering $25.6M Confirmed
Pathé €19.2M fake-CEO cinema-chain fraud (2018) 2018 Phishing Media & Entertainment $21.5M Confirmed
Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls 2018 Phishing Construction & Engineering $18.6M Confirmed
Scoular Company $17.2M grain-trader wire fraud (2014) 2014 Phishing Manufacturing & Industrial $17.2M Confirmed
Retool smishing + deepfake vishing breach (2023) 2023 Phishing Cryptocurrency & Digital Assets $15M Confirmed
Caesars Entertainment Vendor Social Engineering Breach (2023) 2023 Help-Desk & MFA Manipulation Consumer / General Public $15M Confirmed
Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise 2018 Phishing Manufacturing & Industrial $11M Confirmed
Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise 2023 Phishing Healthcare $6.2M Confirmed
New Haven Public Schools $6M COO-email vendor thread-hijack BEC 2023 Phishing Education $6M Confirmed
Medidata Solutions $4.8M CEO-Fraud Wire Transfer (2014) 2014 Phishing Healthcare $4.8M Confirmed
Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong 2026 Vishing (Voice Phishing) Consumer / General Public $3.8M Confirmed
Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company 2021 Phishing Financial Services & Insurance $3.5M Confirmed
Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor 2022 Phishing Technology & Software $3M Confirmed
Argan, Inc. $3M Phishing-Induced Wire Fraud (2023) 2023 Phishing Construction & Engineering $3M Confirmed
Johnson County Schools $3.36M fake-Pearson vendor BEC 2024 Phishing Education $2.6M Confirmed
Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020) 2020 Phishing Government & Public Sector $2.6M Confirmed

Three patterns that hold across all 173 cases

Observations from the corpus itself, not borrowed vendor statistics.

24%
of cases involved a phone or SMS channel at some point (42 of 173). Most awareness programmes are still built almost entirely around email, which leaves the channel attackers increasingly prefer largely untrained.
21%
involved synthetic media or AI-assisted operation (36 cases). Nearly all of these are recent, which is why voice and video can no longer serve as proof of identity on their own.
68
cases occurred in 2024 or later, out of 173 spanning 1978 onward. The concentration is recent because the economics of precision impersonation changed, not because older attacks were rarer.

Where a real attack could have been stopped

One case, set out the way all 173 are: the sequence on the left, the control that would have broken it on the right.

The sequence the attacker ran
  1. Footage gathering: Attackers identified Arup's CFO and several colleagues as impersonation targets and collected publicly available video/audio of them (reporting points to material like broadcast interviews and other public appearances), the kind of footage a public company's leadership routinely generates, and enough to train a likeness/voice model of each person.
  2. Synthetic media production: That footage was used to build deepfake video and voice models good enough to sustain a live-feeling group video call, not just a single pre-recorded clip of one person.
  3. Pretext seeding: A text-based message impersonating the CFO opened the scheme by raising a 'confidential transaction,' establishing the cover story and a reason for secrecy before any video was shown.
  4. Escalation to a synthetic video conference: The target was invited onto a call populated by the deepfaked CFO and several deepfaked 'colleagues' at once, manufacturing social proof that a single deepfaked caller could not achieve alone.
  5. Minimizing exposure: Hong Kong Police noted the fake participants did little live interaction beyond prompting the victim to introduce himself, consistent with attackers keeping synthetic personas passive to reduce the chance a technical glitch would break the illusion.
  6. Authorization bypass: Reassured by the call, the employee bypassed normal verification and proceeded to authorize payment on the 'CFO's' instruction.
  7. Payout / fund dispersal: The victim executed 15 separate wire transfers over about a week to five different Hong Kong bank accounts, splitting the HK$200M total across multiple accounts and transactions, a structuring pattern that is harder to freeze quickly than one large transfer.
The control that would have broken it
  1. Public exposure of unscripted executive video/audio is very hard to fully prevent for a company of Arup's size; the realistic response is assuming this material already exists and hardening what happens downstream, not trying to suppress it.
  2. There is no practical way to block deepfake creation from already-public footage. The correct control sits at the verification stages that follow, not at content-generation itself.
  3. Treat any message demanding confidentiality or secrecy around a financial transaction as an automatic trigger for independent manager-level review, regardless of who appears to be asking.
  4. Establish a live verification challenge for high-value requests made over video (an unexpected, hard-to-script question or action), and never treat 'I saw and heard them on a call' alone as sufficient proof of identity for a financial instruction.
  5. Train staff to notice when 'colleagues' on a call are unusually static or don't engage in normal cross-talk, and make it normal to ask direct, unscripted questions a passive deepfake would struggle to answer.
  6. Enforce mandatory out-of-band verification (call back a known, independently sourced number) plus dual authorization for any large or unusual wire, with no exception for seniority or secrecy demands.
  7. Bank-side monitoring for multiple same-week wires to newly added or unfamiliar payees can flag structuring patterns before all tranches clear; a single approved 'total transaction' cap also forces a second review before a scheme can be split into many smaller transfers.

Common questions

A few of the most common are below. See all 32 questions, answered from documented cases →

What is a real life example of social engineering?
In 2024 an Arup finance employee in Hong Kong joined a video call with people who looked and sounded like the CFO and colleagues. Every participant was a deepfake. The employee approved 15 transfers totalling about US$25.6 million. This library documents 173 such cases, each with named victim, dates, method, and sources.
What are the four types of social engineering?
The four most frequently cited are phishing (by email), vishing (by phone), smishing (by text), and pretexting or impersonation. In this library those account for 62, 32, 15, and 28 cases respectively. The table above lists all ten types with real case counts.
What is the most common form of social engineering?
Phishing. It appears in 62 of the 173 documented cases here (36%), more than any other technique. Email remains the most common channel, though voice and SMS attacks are growing fastest in recent years.
How is social engineering different from hacking?
Traditional hacking exploits a flaw in software. Social engineering exploits a person, so there is no patch for it. That is why attacks like help-desk MFA resets succeed against organisations with fully updated systems.
Browse by sector
Financial Services & Insurance 46 Government & Public Sector 42 Consumer / General Public 38 Technology & Software 38 Manufacturing & Industrial 22 Retail & E-commerce 17 Cross-Sector / Multiple Industries 15 Professional & Business Services 14 Cryptocurrency & Digital Assets 13 Media & Entertainment 12 All sectors →
Browse by threat actor
Organized Crime 55 Nation-State / APT 20 Unaffiliated Individual 13 Authorized Tester or Researcher 6 Corporate / Competitive Intelligence 5 Hacktivist 1 Autonomous AI System 1
Browse by company
AFGlobal Corporation 1 Alkem Laboratories Ltd. 1 American United Mortgage Company 1 Anthem Inc. 1 Argan, Inc. 1 Arup 1 Brownsville Community Development Corporation 1 Cabarrus County, North Carolina 1 Caesars Entertainment, Inc. 1 Carnival Corporation & plc 1 All companies →