Documented social engineering incidents targeting the critical infrastructure, energy & utilities sector, sourced and fact-checked.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio of his German parent company's own CEO's voice, marking the first widely reported criminal use of AI voice-cloning technology, disclosed by insurer Euler Hermes.
ConfirmedRussia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities, harvesting credentials that let them remotely open substation breakers and cut power to about 225,000 customers, marking the first confirmed cyberattack to cause a real-world blackout.
ConfirmedA nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors, then physically destroyed roughly 1,000 uranium centrifuges.
ConfirmedFraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.
ConfirmedScammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats to extract $131,464 from customers in 2025, a documented 72% drop from 2024 that SCE publicly credited to customer awareness and its recurring scam-education campaigns.
AllegedA widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to help trigger the 2012 Saudi Aramco Shamoon wiper attack, but no primary source (Reuters, Symantec, Kaspersky, CISA, Panetta's Pentagon remarks) corroborates any physical-access role in the actual, well-documented malware intrusion that wiped ~30,000-35,000 Aramco workstations.
ConfirmedA compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.
ConfirmedScammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and tell them to have a store cashier scan it to "pay," draining funds instantly through a channel with no fraud checkpoint; PG&E's own fraud investigator quantified over $211,000 in losses through mid-2026.
ConfirmedA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.
ConfirmedA "complex criminal phishing scheme" fraudulently induced Argan, Inc. to send two outbound wires on March 6-7, 2023, producing a roughly $3 million pre-tax loss with only about $0.2M potentially recoverable through insurance.