Sectors

Critical Infrastructure, Energy & Utilities

Documented social engineering incidents targeting the critical infrastructure, energy & utilities sector, sourced and fact-checked.


10 Cases
Confirmed

UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)

The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio.

Incident 2019Read →
Confirmed

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.

Incident 2015Read →
Confirmed

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors.

Incident 2010Read →
Confirmed

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls.

Incident 2018Read →
Confirmed

Southern California Edison Utility Disconnection Threat Scam (2025)

Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats.

Incident 2024Read →
Alleged

Saudi Aramco "Badge Surfer" Claim in the 2012 Shamoon Attack - A Security-Awareness Narrative Without Primary-Source Corroboration

A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy.

Incident 2012Read →
Confirmed

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.

Incident 2024Read →
Confirmed

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.

Incident 2025Read →
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.

Incident 2025Read →
Confirmed

Argan, Inc. $3M Phishing-Induced Wire Fraud (2023)

A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3 million pre-tax loss.

Incident 2023Read →
Explore more

Browse the rest of the library