Documented social engineering incidents targeting the critical infrastructure, energy & utilities sector, sourced and fact-checked.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio.
ConfirmedRussia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
ConfirmedA nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors.
ConfirmedFraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls.
ConfirmedScammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats.
AllegedA widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy.
ConfirmedA compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
ConfirmedScammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
ConfirmedA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
ConfirmedA complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3 million pre-tax loss.