Sectors

Cross-Sector / Multiple Industries

Documented social engineering incidents targeting the cross-sector / multiple industries sector, sourced and fact-checked.


15 Cases
Confirmed

Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)

Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to disguise their identity during technical interviews for a Poland-based remote role, and suspected, based on matching vocal accents and one persona's oddly over-rehearsed answers, that both fake personas were run by the same operator.

Incident 2024Read →
Confirmed

UIUC USB Drive Drop Field Experiment (2015)

Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up and 45% were plugged in and opened, with the first connection occurring in under six minutes, the first rigorous, quantified real-world proof that USB-baiting works.

Incident 2015Read →
Confirmed

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles, texting and calling senators, governors and business leaders with requests including a pardon list and a cash transfer, triggering an FBI investigation.

Incident 2025Read →
Confirmed

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and tell them to have a store cashier scan it to "pay," draining funds instantly through a channel with no fraud checkpoint; PG&E's own fraud investigator quantified over $211,000 in losses through mid-2026.

Incident 2025Read →
Confirmed

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried to buy access, operator "CanadianKingpin12" supplied dead credentials and then demanded crypto for a "crack," revealing it as a scam with no working AI product behind the marketing.

Incident 2023Read →
Confirmed

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field, then exfiltrated CRM data through an expired, CSP-whitelisted domain they re-bought for $5, when an employee later asked Agentforce about the lead.

Incident 2025Read →
Confirmed

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.

Incident 2024Read →
Confirmed

Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix

A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile that, instead of the usual ClickFix paste-and-run trick, abused the Windows search-ms protocol to pull a disguised LNK/PDF from an attacker SMB share, ultimately installing an MSI that fingerprinted the host and dropped the MetaStealer infostealer.

Incident 2025Read →
Confirmed

FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)

The FBI's 2025 Internet Crime Report introduced IC3's first-ever dedicated AI-fraud tracking section in its nearly 25-year history, logging 22,364 complaints and $893,346,472 in losses from scams using voice clones, deepfake video, fake AI-generated social profiles, and forged identification documents.

Incident 2025Read →
Confirmed

FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake video to make fraud schemes, including loved-one crisis scams and bank-account impersonation, more scalable and believable.

Incident 2024Read →
Confirmed

OFAC Sanctions DPRK Ministry of National Defense Front Companies Behind Fake-Persona Remote IT-Worker Fraud

Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China, and Vietnam for running fake-persona schemes that placed DPRK IT workers in remote jobs at hundreds of companies worldwide, generating hundreds of millions of dollars for weapons programs, in a scheme whose U.S.-facilitation side (Christina Chapman's laptop farm) generated over $17 million and led to a 102-month prison sentence.

Incident 2025Read →
Confirmed

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.

Incident 2021Read →
Confirmed

Abnormal Security "Missed Voicemail" QR Quishing Campaign (2021)

Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed victims to a Microsoft-credential phishing page hosted on a legitimate enterprise survey service, using compromised Outlook accounts to bypass secure email gateways entirely, one of the earliest vendor-documented "quishing" campaigns.

Incident 2021Read →
Confirmed

Gootloader Returns After 7-Month Hiatus: SEO Poisoning, Glyph-Swapped Fonts, and a Dual-Personality Malformed ZIP (2025)

After going quiet on March 31, 2025 following a researcher's disruption campaign, Gootloader returned on November 5, 2025 with a glyph-swapping WOFF2 web font to hide malicious filenames and a malformed ZIP archive that extracts a working JScript loader in Windows Explorer but a harmless decoy in 7-Zip, Python, or VirusTotal - spread across 100+ SEO-poisoned sites and thousands of keywords, feeding the Supper SOCKS5 backdoor and, via Storm-0494/Vanilla Tempest, ransomware deployment.

Incident 2025Read →
Confirmed

SEC Section 21(a) Report on Nine Issuers' Business Email Compromise Losses

SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public companies, finding that existing wire-authorization controls weren't consistently followed under the pressure of the schemes.

Incident 2018Read →