Documented social engineering incidents targeting the cross-sector / multiple industries sector, sourced and fact-checked.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up.
ConfirmedVidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
ConfirmedAn unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles.
ConfirmedScammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
ConfirmedNoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
ConfirmedFTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
ConfirmedA Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
ConfirmedA victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.
ConfirmedThe FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
ConfirmedThe FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
ConfirmedTreasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
ConfirmedTwo New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms.
ConfirmedBetween September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed.
ConfirmedAfter going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP to hide malware.
ConfirmedSEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public.