Sectors

Cross-Sector / Multiple Industries

Documented social engineering incidents targeting the cross-sector / multiple industries sector, sourced and fact-checked.


15 Cases
Confirmed

UIUC USB Drive Drop Field Experiment (2015)

Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up.

Incident 2015Read →
Confirmed

Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)

Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.

Incident 2024Read →
Confirmed

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles.

Incident 2025Read →
Confirmed

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.

Incident 2025Read →
Confirmed

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.

Incident 2025Read →
Confirmed

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.

Incident 2024Read →
Confirmed

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.

Incident 2023Read →
Confirmed

Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix

A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.

Incident 2025Read →
Confirmed

FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)

The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.

Incident 2025Read →
Confirmed

FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.

Incident 2024Read →
Confirmed

OFAC Sanctions DPRK Ministry of National Defense Front Companies Behind Fake-Persona Remote IT-Worker Fraud

Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.

Incident 2025Read →
Confirmed

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms.

Incident 2021Read →
Confirmed

Abnormal Security "Missed Voicemail" QR Quishing Campaign (2021)

Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed.

Incident 2021Read →
Confirmed

Gootloader Returns After 7-Month Hiatus: SEO Poisoning, Glyph-Swapped Fonts, and a Dual-Personality Malformed ZIP (2025)

After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP to hide malware.

Incident 2025Read →
Confirmed

SEC Section 21(a) Report on Nine Issuers' Business Email Compromise Losses

SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public.

Incident 2018Read →
Explore more

Browse the rest of the library