{
    "name": "Social Engineering Examples case library",
    "publisher": "Diopter AI",
    "url": "https://socialengineeringexamples.com/",
    "license": "https://creativecommons.org/licenses/by/4.0/",
    "attribution": "Social Engineering Examples, a Diopter AI research project",
    "generated": "2026-08-11T11:53:44+00:00",
    "case_count": 173,
    "cases": [
        {
            "case_id": "0ktapus-okta-phishing-campaign-2022",
            "title": "0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs",
            "victim": "130+ organizations including Twilio, Cloudflare (attempt, not breached), Mailchimp, and Klaviyo; downstream victims included Signal, DigitalOcean, and Twilio's Authy users.",
            "incident_date": "March 2022 to August 2022 (Group-IB disclosure August 25, 2022; Twilio breach detected August 4, 2022; Cloudflare attempt July 20, 2022)",
            "year": 2022,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Financial Services & Insurance; Retail & E-commerce; Technology & Software; Telecommunications",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No consolidated dollar figure publicly disclosed; impact measured in credential/data theft (~9,931 credentials, 5,441 MFA codes). 163 affected Twilio customers, 93 compromised Authy accounts, and 1,900 Signal phone numbers exposed.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/0ktapus-okta-phishing-campaign-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "south-carolina-12-defendant-bec-ring-2025",
            "title": "12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)",
            "victim": "Multiple businesses and individuals nationwide and abroad, including construction companies, private equity firms, title/escrow companies, and law firms in South Carolina, New Jersey, Florida, Texas, Pennsylvania, and Japan, plus a Boston-area point-of-service company, an estate executor, a Dallas real estate company, and a Pennsylvania specialty-metals recycling firm",
            "incident_date": "Scheme active from at least January 2020 through 2024; 12-count indictment returned by a federal grand jury in Columbia, SC on January 21, 2025 (unsealed/announced January 23-24, 2025) in United States v. Bosket et al., No. 3:25-cr-00055 (D.S.C.); first defendant arrest (Jamian Butler) November 18, 2025; first trial convictions (Demani and Tanya Bosket) June 11, 2026",
            "year": 2020,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Financial Services & Insurance; Hospitality, Gaming & Travel; Legal Services; Manufacturing & Industrial; Professional & Business Services; Real Estate; Retail & E-commerce",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "A 12-count indictment itemizes roughly $5.3 million in losses across ten victim transactions. The 12-count indictment itemizes roughly $5.3 million in losses across ten specific victim transactions (e.g., $1,234,848 from a New Jersey construction group; $1,525,890 tied to a Dallas, TX real estate matter; $909,609.60 from a Columbia, SC law firm; $637,616.34 from a Boston-area company; $318,981 from an estate; smaller sums from Florida title and private-equity victims, a Pennsylvania specialty-metals company, and a Japanese engineering firm). Broader trial evidence presented in June 2026 put the full multi-year scheme (2020-2024) at more than $25 million stolen from individuals and businesses nationwide; the U.S. Secret Service recovered approximately $2.5 million for return to victims. Figures beyond the two 2026 convictions (Demani and Tanya Bosket) remain allegations pending further pleas/trials.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/south-carolina-12-defendant-bec-ring-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ukraine-power-grid-attack-2015",
            "title": "2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)",
            "victim": "Three Ukrainian regional electricity distribution companies (oblenergos): Prykarpattyaoblenergo, Kyivoblenergo, and Chernivtsioblenergo",
            "incident_date": "Spear-phishing/intrusion campaign observed from as early as March 2015 through January 2016; the coordinated blackout occurred December 23, 2015",
            "year": 2015,
            "country": "Ukraine",
            "attack_channels": "Help-Desk & MFA Manipulation; Phishing",
            "sectors": "Critical Infrastructure, Energy & Utilities",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No official dollar loss figure was disclosed by the Ukrainian utilities or US government. Impact is measured operationally: approximately 225,000 customers lost power for roughly 3 to 6 hours (individual utility outages ranged from about 3 hours up to 6 hours before manual restoration); affected oblenergos continued operating under constrained/manual conditions for months afterward because corrupted firmware on serial-to-Ethernet converters and wiped systems had to be replaced/rebuilt, and one utility's call center was also disabled by a telephone denial-of-service flood during the response.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/ukraine-power-grid-attack-2015",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "cisa-fbi-aa21-148a-usaid-constant-contact-nobelium-2021",
            "title": "AA21-148A: Nobelium’s USAID/Constant Contact Spearphishing Campaign",
            "victim": "Approximately 150-350 government organizations, intergovernmental organizations (IGOs), and NGOs worldwide (figures differ by source: Microsoft counted ~3,000 individual email accounts across 150+ organizations; CISA/FBI's advisory cited more than 7,000 accounts across approximately 350 organizations). USAID itself was impersonated but was not the entity whose systems were breached; a third-party marketing vendor (Constant Contact) account tied to USAID's mailing list was the compromised access point.",
            "incident_date": "2021-05-25 to 2021-05-28 (campaign escalation and peak activity); CISA/FBI advisory AA21-148A published 2021-05-28; DOJ court-authorized domain seizures executed same day, publicly announced 2021-06-01",
            "year": 2021,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Government & Public Sector; Nonprofit & NGO",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar loss figures were disclosed or are applicable; this was an espionage-oriented intrusion campaign, not a fraud/BEC incident. No confirmed monetary loss reported.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/cisa-fbi-aa21-148a-usaid-constant-contact-nobelium-2021",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "abnormal-security-missed-voicemail-qr-quishing-2021",
            "title": "Abnormal Security “Missed Voicemail” QR Quishing Campaign (2021)",
            "victim": "Approximately 200 email recipients across Abnormal Security's enterprise customer base (unnamed organizations), all Microsoft 365 / Office 365 users; no individual victim organizations were named",
            "incident_date": "2021-09-15 to 2021-10-13 (campaign window); reported by Abnormal Security on 2021-10-26",
            "year": 2021,
            "country": "United States",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "Cross-Sector / Multiple Industries",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not disclosed / not quantified. Abnormal Security and all secondary coverage describe this as a credential-harvesting campaign that was detected and blocked before compromise; no dollar loss, ransom, or downstream fraud figure was ever reported publicly. Abnormal states it blocked \"almost 200\" emails targeting its own customer base; this is a count of blocked malicious emails/attempts, not 200 confirmed distinct victim organizations, and there is no public confirmation any recipient actually entered credentials.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/abnormal-security-missed-voicemail-qr-quishing-2021",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "abu-trica-ai-romance-scam-network-2025",
            "title": "Abu Trica AI Romance Scam Network (Kumi & Yussif) – $8M+ Elder Fraud, Northern District of Ohio",
            "victim": "80+ elderly Americans, predominantly widows and divorcees, contacted via online dating platforms and social media across the United States.",
            "incident_date": "Scheme: approx. April 2023 to November 2025. Indictment unsealed / Kumi arrested in Ghana: December 11, 2025. Kumi extradited from Ghana to the US: July 9, 2026.",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Consumer / General Public",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "More than $8 million allegedly defrauded from 80+ elderly victims (figure as charged in the indictment; not yet adjudicated at trial).",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/abu-trica-ai-romance-scam-network-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "abubakari-twins-ohio-ai-romance-fraud-2026",
            "title": "Abubakari Twins / Ohio $15M AI-Driven Romance Fraud Ring",
            "victim": "130+ older Americans (predominantly widows/divorcees) across the United States",
            "incident_date": "2024-07 to 2026-04 (alleged scheme period); indictment unsealed 2026-05-14; DOJ rollout/detail 2026-06-04",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Consumer / General Public; Cryptocurrency & Digital Assets",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "DOJ alleges $15 million+ in losses from 130+ victims in the Abubakari/Opoku-Boachie indictment (this is the case named in the task). A closely related, DOJ-linked case against Frederick \"Abu Trica\" Kumi and Daniel Yussif (part of the same network/announcement) separately alleges $8 million+ from 80+ elderly victims (April 2023-November 2025). DOJ's June 4, 2026 release attributes over $3 million in Ghana search-and-arrest asset seizures, including a Lamborghini, a Tesla Cybertruck, a Mercedes-Benz, and a BMW, to the combined operation across the three linked indictments, without breaking the total out by defendant. Separate Ghanaian press coverage (Pulse Ghana, MyJoyOnline) specifically reported the same four vehicles plus a mansion in Ghana as assets seized from Kumi, though without an independent dollar figure for that subset. All figures are prosecutorial allegations, not yet proven at trial or finalized in forfeiture judgments.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/abubakari-twins-ohio-ai-romance-fraud-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "afglobal-ceo-fraud-bec-2014",
            "title": "AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)",
            "victim": "AFGlobal Corporation (Ameriforge Group Inc.), a Houston, Texas manufacturer serving the oil/energy and aerospace markets; direct victim was Director of Accounting Glen Wurm.",
            "incident_date": "2014-05-21",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Defense & Aerospace; Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 480000,
            "loss_basis": "$480,000 wired and unrecoverable (recipient account at Agricultural Bank of China was emptied and closed shortly after transfer). A second fraudulent request for $18,000,000 was stopped. Loss became the subject of a coverage dispute over a policy covering up to $3M with a $100,000 deductible.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/afglobal-ceo-fraud-bec-2014",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ahmedabad-aadhaar-deepfake-ekyc-loan-fraud-2026",
            "title": "Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)",
            "victim": "Indian digital lending platforms and banks relying on Aadhaar e-KYC/biometric liveness verification for instant loans and account opening (named: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, RKBANSAL, True Credits, EarlySalary), plus the individual Aadhaar holders whose identities and mobile numbers were hijacked to obtain the loans",
            "incident_date": "Case registered 10 April 2026 (Ahmedabad Cyber Crime Police Station); first 4 arrests announced 29 April 2026; 3 further arrests announced 7-8 May 2026 (total 7 arrested as of reporting, with one suspect, Oli Ullah, reported still absconding)",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media; Phishing",
            "sectors": "Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 300,
            "loss_basis": "At least one fraudulent instant loan of Rs 25,000 (about $300) was confirmed obtained in the victim's name. Confirmed loss disclosed in reporting: at least one fraudulent instant loan of Rs 25,000 (~$300) obtained in a Thaltej (Ahmedabad) victim's name via Jio Payments Bank, discovered only when the victim noticed suspicious loan enquiries on his credit report. Investigators separately gave an unverified estimate that the wider racket may have generated roughly Rs 10-15 lakh per year (~$12,000-$18,000) across multiple victims and lenders; this figure is described in press reporting as a police estimate, not a court-established or audited total. Full victim count and aggregate fraudulent-loan value were still under investigation (police were \"probing to unveil the scale of the scam\") as of the last reporting found.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/ahmedabad-aadhaar-deepfake-ekyc-loan-fraud-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "maharashtra-sule-patole-ai-bitcoin-audio-2024",
            "title": "AI-Cloned “Bitcoin Bribery” Audio Targets Maharashtra Opposition Leaders Sule and Patole on Election Eve",
            "victim": "Supriya Sule (MP, NCP-Sharad Pawar faction) and Nana Patole (President, Maharashtra Congress Committee)",
            "incident_date": "2024-11-19",
            "year": 2024,
            "country": "India",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No direct monetary loss from the audio itself; the referenced underlying 2018 Pune crypto case involved disputed claims of roughly ₹235 crore, unproven and unverified.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/maharashtra-sule-patole-ai-bitcoin-audio-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "air-canada-westjet-curbside-dumpster-diving-2003-2004",
            "title": "Air Canada v. WestJet: Curbside Garbage Collection From Co-Founder Mark Hill’s Home",
            "victim": "Mark Hill, WestJet Airlines co-founder and Vice-President of Strategic Planning (targeted at his personal residence in Victoria, B.C.)",
            "incident_date": "2003-2004 (garbage collections confirmed March 22 and April 5, 2004); Air Canada's lawsuit against WestJet was filed/announced in early April 2004: contemporaneous Globe and Mail reporting (April 8, 2004) and a later retrospective (December 6, 2006) place the filing/announcement on April 6, 2004, while a separate June 30, 2004 Globe and Mail report states the suit \"was launched April 7\"; the exact date is disputed across contemporaneous sources and is best stated as \"early April 2004\"; the garbage-collection admission surfaced in Jasper Smith's affidavit, disclosed in reporting on June 30, 2004; case settled May 29, 2006",
            "year": 2003,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Legal Services; Professional & Business Services; Transportation & Logistics",
            "threat_actors": "Corporate / Competitive Intelligence",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "WestJet paid Air Canada's investigation and litigation costs of CAD 5.5 million. Confirmed via the joint press release filed as a U.S. SEC exhibit (May 29, 2006): WestJet paid Air Canada's investigation and litigation costs of CAD 5.5 million, plus made a CAD 10 million donation to children's charities across Canada in the name of both airlines, for a combined CAD 15.5 million, not the CAD 15M+5M figure sometimes cited in secondary summaries. No fine or criminal penalty was imposed; this was a negotiated civil settlement with all legal proceedings terminated.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/air-canada-westjet-curbside-dumpster-diving-2003-2004",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "alkem-laboratories-ascend-enzene-bec-2023-2024",
            "title": "Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise",
            "victim": "Alkem Laboratories Ltd. (Mumbai-headquartered multinational pharmaceutical company; NSE/BSE-listed) via its US subsidiary Ascend Laboratories LLC being impersonated, and separately via employee email compromise at its subsidiary Enzene Biosciences Ltd.'s US operation",
            "incident_date": "27 October 2023 - 17 November 2023 (fraud execution window); fraud discovered ~mid-November 2023; board resolved to disclose 12 January 2024; separate Enzene Biosciences US subsidiary incident disclosed 15 May 2025",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Healthcare",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 6200000,
            "loss_basis": "Ascend Laboratories impersonation case: Rs 51.30 crore (~$6.2M) fraudulently wired via SWIFT to a fraudulent US bank account. Company filings round to Rs 51.31 crore (Rs 513.1 million). Rs 28.98 crore was seized by US law enforcement and refunded to Alkem; net unrecovered loss reported as Rs 22.31 crore (per Mumbai Police/Hindustan Times reporting). Alkem's own FY2023-24 statutory accounts record a slightly different rounding: Rs 29.04 crore (Rs 290.4 million) recovered in Q4FY24 and a Rs 22.27 crore (Rs 222.7 million) net exceptional loss booked for the incident. Separately, the Enzene Biosciences US subsidiary email-compromise incident (disclosed 15 May 2025) resulted in an undisclosed fraudulent fund transfer; Alkem stated the total quantum was \"under investigation\" and did not publish a figure in the primary filings reviewed.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/alkem-laboratories-ascend-enzene-bec-2023-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "american-united-mortgage-dumpster-diving-2007",
            "title": "American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)",
            "victim": "American United Mortgage Company (Northbrook, IL) as the regulated entity; its mortgage customers (at least 36 identified consumers whose credit reports were found discarded) as the at-risk data subjects",
            "incident_date": "2006-02 (documents first discovered) to 2008-01-28 (final judgment entered); FTC complaint filed 2007-12-17/18",
            "year": 2006,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting); Pretexting & Impersonation",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 50000,
            "loss_basis": "$50,000 civil penalty paid by American United Mortgage Company to the U.S. Treasury via the FTC/DOJ action. The case record does not document a specific dollar loss to consumers from identity theft or fraud attributable to the exposed documents.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/american-united-mortgage-dumpster-diving-2007",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "anthem-health-insurer-breach-2015",
            "title": "Anthem health-insurer breach (78.8M records)",
            "victim": "Anthem Inc. (formerly WellPoint), then the second-largest U.S. health insurer, and 78.8 million of its current and former plan members and employees.",
            "incident_date": "2014-02-18",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Financial Services & Insurance; Healthcare",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 260000000,
            "loss_basis": "Anthem reported ~$260M+ in security-related spending tied to the breach (including $115M security improvements, $31M public/individual notification. $112M credit protection, $2.5M expert consultants). Separately it paid a $115M class-action settlement, a $16M HHS OCR HIPAA settlement (2018), and $48.2M to state attorneys general (2020), for roughly $179M in legal settlements overall.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/anthem-health-insurer-breach-2015",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "argan-inc-3m-phishing-wire-fraud-2023",
            "title": "Argan, Inc. $3M Phishing-Induced Wire Fraud (2023)",
            "victim": "Argan, Inc. (NYSE: AGX), a Rockville, Maryland holding company whose subsidiaries provide engineering, procurement and construction services to the power and industrial sectors.",
            "incident_date": "2023-03-06",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Critical Infrastructure, Energy & Utilities",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 3000000,
            "loss_basis": "Two fraudulently-induced outbound wire transfers on March 6-7, 2023. Argan initially projected a one-time pre-tax charge of approximately $3.0 million (up to $0.2M recoverable via insurance, net of deductible); the charge actually recorded in Q1 fiscal 2024 (quarter ended April 30, 2023) was approximately $3.2 million, booked to the \"other loss\" line. Per the company's 10-Q (Note 15), the ~$3.2M total comprised roughly $3.0M of unrecovered wired funds plus roughly $0.2M of forensic, legal, and professional/audit fees; this ~$0.2M in fees is distinct from the coincidentally-equal ~$0.2M of potential insurance recovery. Management quantified the charge at about $0.24 per diluted share; on the ~13.5M diluted-share base this is consistent as a pre-tax per-share figure, not an after-tax EPS impact. The 10-Q later characterized expected insurance reimbursement as not material.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/argan-inc-3m-phishing-wire-fraud-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "arup-deepfake-cfo-video-call-2024",
            "title": "Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)",
            "victim": "Arup (UK-based multinational design and engineering firm), Hong Kong office finance department; ~18,000 employees globally, revenues over £2bn.",
            "incident_date": "2024-01",
            "year": 2024,
            "country": "United Kingdom",
            "attack_channels": "Deepfake & Synthetic Media; Vishing (Voice Phishing)",
            "sectors": "Construction & Engineering; Professional & Business Services",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 25600000,
            "loss_basis": "HK$200M (~US$25.6M / ~£20M)",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/arup-deepfake-cfo-video-call-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "austin-pig-butchering-daiq-courier-arrest-2026",
            "title": "Austin “Pig Butchering” Courier Arrest – $1.4M DAIQ Crypto Investment Scam",
            "victim": "Anonymized Austin, Texas resident, referred to in court records and reporting by the alias \"Eduardo\"",
            "incident_date": "Initial contact September 2025; financial losses October 2025-March 2026; courier arrested April 13, 2026 (probable cause found April 14, 2026)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Consumer / General Public; Cryptocurrency & Digital Assets",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 1408850,
            "loss_basis": "$1,408,850 total confirmed victim loss (reported by KXAN/Statesman as \"more than $1.4 million\"), accumulated via cash handoffs, wire transfers. And gold purchases between October 2025 and March 2026. The arrest sting itself was staged around a further $40,000 gold/cash exchange on April 13, 2026, which was never completed with the courier (he was detained before it changed hands).",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/austin-pig-butchering-daiq-courier-arrest-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "axie-infinity-ronin-bridge-linkedin-job-offer-heist-2022",
            "title": "Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M",
            "victim": "Sky Mavis (operator of the Ronin Network sidechain and the Axie Infinity play-to-earn game). The compromised individual was a senior Sky Mavis engineer.",
            "incident_date": "2022-03-23",
            "year": 2022,
            "country": "Vietnam",
            "attack_channels": "Phishing",
            "sectors": "Cryptocurrency & Digital Assets; Financial Services & Insurance; Hospitality, Gaming & Travel",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 540000000,
            "loss_basis": "173,600 ETH plus 25.5M USDC stolen, valued at roughly $540 million at the time of the theft. 173,600 ETH plus 25.5M USDC stolen, valued at roughly $540M at the time of the theft on March 23, rising to $615-625M by the time the exploit was discovered and disclosed six days later as ETH's price moved (figures per Elliptic and CoinDesk). Sky Mavis reimbursed users via treasury reserves plus a $150M round led by Binance. The Ronin bridge relaunched in June 2022 with hardened controls.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/axie-infinity-ronin-bridge-linkedin-job-offer-heist-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "azure-monitor-alert-toad-billing-scam-2026",
            "title": "Azure Monitor Alert Abuse TOAD Scam: Fake $459.90 Windows Defender Billing Notice Cleared as a False Positive",
            "victim": "An unnamed security reviewer/employee at a global IoT technology company (per IRONSCALES' primary case); a related same-technique sample separately targeted a mid-size U.S. professional services firm. Both organizations are vendor-anonymized in IRONSCALES' reporting and have not been independently identified or confirmed.",
            "incident_date": "2026-03-21 (IRONSCALES publication date; underlying campaign observed shortly before)",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Phishing; Vishing (Voice Phishing)",
            "sectors": "Professional & Business Services; Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 459,
            "loss_basis": "No confirmed financial loss has been publicly disclosed for either IRONSCALES case. The primary lure demanded a disputed charge of $459.90 (framed as a \"Windows Defender\" billing item). IRONSCALES' companion sample (professional services firm, transaction ID PP456-887A-22B) cited the identical $459.90 figure, not a different \"$389.90 variant\" as earlier summarized. The $389.90 figure instead belongs to a third, distinct in-the-wild example that BleepingComputer independently observed and reported: a lure combining the primary case's reference number (MS-FRA-6673829-KP) with the companion case's transaction ID (PP456-887A-22B) and a transaction date of 03/05/2026, but with different callback numbers and a $389.90 charge. That figure is BleepingComputer's own finding, not a value IRONSCALES reported for either of its two documented samples. Because the primary email was marked a false positive by a human reviewer and IRONSCALES does not report a completed callback or fraud outcome for that case, whether the targeted employee called the number or lost money is not documented in the public record. The companion sample was quarantined by IRONSCALES' AI/behavioral detection before any recipient engagement (4 mailboxes affected, no reported loss).",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/azure-monitor-alert-toad-billing-scam-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "scottish-small-business-bank-fraud-vishing-2019-2026",
            "title": "Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)",
            "victim": "An unnamed small business in Perth, Scotland (2019); Handmade Craft House, a family-run handcraft/woodware business in Dumfries, Scotland, owned and operated by Mike Dixon with wife Gail, daughter Gemma, son-in-law Tim Riddiford, and grandsons Joe and Ben (2026)",
            "incident_date": "2019-02 (Perth case, reported 2019-02-15); 2026-01-26 (Handmade Craft House call, \"Monday afternoon\"), company statement 2026-01-28, Daily Record report 2026-01-30, Herald follow-up 2026-02-08",
            "year": 2019,
            "country": "United Kingdom",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Retail & E-commerce",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "2019 Perth case: £31,000 stolen; no recovery reported in available coverage. 2026 Handmade Craft House case: total drained from business and personal/savings accounts, with \"some money\" later returned by the bank, leaving a net loss of \"over £5,000\" that the bank told the family was \"not its responsibility.\" Both are UK-Finance-category authorised push payment (APP) fraud; bank-and-police impersonation accounted for 11% of APP scam losses (£27.1m) in the UK in H1 of the prior year, per UK Finance figures cited in the Herald's coverage of the 2026 case.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/scottish-small-business-bank-fraud-vishing-2019-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "barclays-jeweller-anydesk-vishing-2024",
            "title": "Barclays-Impersonation Vishing of UK Jeweller (2024)",
            "victim": "Unnamed UK jeweller (family-run jewellery business; victim is the owner, a man in his 70s), client of National Fraud Helpline / Richardson Hartley Law",
            "incident_date": "2024-04 (scam call); reported publicly ~January 31, 2025 (Jewellery Focus) and February 7, 2025 (National Fraud Helpline)",
            "year": 2024,
            "country": "United Kingdom",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Retail & E-commerce",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "GBP 48,451.78 stolen from two of the victim's business bank accounts. Barclays initially returned only GBP 30.21 and offered GBP 100 in goodwill compensation. After National Fraud Helpline solicitors intervened and argued Barclays should have flagged the unusual payment activity, the firm recovered GBP 25,650 from Barclays (a little over half the stolen amount) for the victim; National Fraud Helpline stated it intended to pursue the remaining shortfall via a complaint to the Financial Ombudsman Service, but no publicly reported Ombudsman decision/outcome for this specific case was found as of the reporting period.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/barclays-jeweller-anydesk-vishing-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "binance-cco-hillmann-deepfake-hologram-2022",
            "title": "Binance CCO Patrick Hillmann’s Alleged Deepfake ‘Hologram’ Listing Scam Claim (2022)",
            "victim": "Binance (Patrick Hillmann, then Chief Communications Officer), impersonated as the vector, per his own unverified account; the alleged defrauded parties were unnamed crypto/blockchain project teams who said they believed they were meeting with the real Hillmann about a Binance token listing",
            "incident_date": "2022-08-23",
            "year": 2022,
            "country": "Unknown",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Cryptocurrency & Digital Assets",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "alleged",
            "loss_usd": 0,
            "loss_basis": "No verified public dollar-loss total was disclosed by Binance or Hillmann. One unverified LinkedIn commenter (Sahr Johnny) alleged a crypto project lost roughly $250,000 worth of \"AFR\" tokens that were then dumped on the Stellar DEX (a ~98% price crash), but this claim was not corroborated by Binance, Hillmann, or any primary/secondary source found. It is flagged here as an unverified allegation, not a confirmed figure.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/binance-cco-hillmann-deepfake-hologram-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "cabarrus-county-vendor-bec-2019",
            "title": "Cabarrus County $1.7M vendor-impersonation BEC (2019)",
            "victim": "Cabarrus County, North Carolina (county government and Cabarrus County Schools accounts payable); impersonated vendor was Branch and Associates, Inc. of Roanoke, VA, general contractor for West Cabarrus High School.",
            "incident_date": "2018-11-27 to 2019-07-29",
            "year": 2018,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Education; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 2504601,
            "loss_basis": "$2,504,601 wired to the fraud account; $776,518.40 frozen/recovered by Bank of America; net loss $1,728,082.60. Insurance covered only $75,000; county backfilled approximately $1,653,082.60 from its Assigned Fund Balance.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/cabarrus-county-vendor-bec-2019",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "caesars-entertainment-vendor-social-engineering-2023",
            "title": "Caesars Entertainment Vendor Social Engineering Breach (2023)",
            "victim": "Caesars Entertainment, Inc.",
            "incident_date": "Intrusion on or about August 18, 2023 (per later Nevada federal court filings); Caesars identified suspicious activity August 19, 2023 (per state breach notices) / August 18, 2023 per the court's later background recitation; publicly disclosed via SEC Form 8-K filed September 14, 2023, referencing a September 7, 2023 determination date",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Help-Desk & MFA Manipulation",
            "sectors": "Consumer / General Public; Hospitality, Gaming & Travel",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 15000000,
            "loss_basis": "Widely reported (Bloomberg/WSJ/Reuters) that Caesars paid approximately $15 million in cryptocurrency, reduced from an initial $30 million demand. To prevent publication of stolen loyalty-program data. This figure is NOT stated in Caesars' SEC 8-K itself: the filing discusses steps taken to have the actor delete the data (implying payment/negotiation) but does not disclose an amount, so treat $15M as reported/attributed rather than company-confirmed in the primary filing (Caesars' own 2024 motion to dismiss likewise characterizes the $15M figure as a plaintiffs' allegation, not a Caesars admission). Additional undisclosed costs from incident response, legal fees, state AG notifications, and a consolidated federal class action in the District of Nevada.",
            "source_count": 14,
            "url": "https://socialengineeringexamples.com/caesars-entertainment-vendor-social-engineering-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "carnival-corporation-employee-vishing-breach-2026",
            "title": "Carnival Corporation Employee Vishing Breach (2026)",
            "victim": "Carnival Corporation & plc, the world's largest cruise operator, parent of Carnival Cruise Line, Holland America Line, Princess Cruises, Costa, Cunard, Seabourn, AIDA, and P&O; roughly 5,995,277 individuals notified.",
            "incident_date": "2026-04-10 (vishing call and credential theft) to 2026-05-27 (public disclosure); SEC Form 10-Q filed 2026-06-26",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Hospitality, Gaming & Travel",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Carnival did not disclose a specific dollar loss tied to the incident itself. Six purported class-action lawsuits were filed in April 2026 in the U.S. District Court for the Southern District of Florida and were later consolidated; in its Form 10-Q for the quarter ended May 31, 2026 (filed June 26, 2026), Carnival stated it believes the outcome of this litigation will not have a material impact on its consolidated financial statements. Carnival offered affected U.S. individuals two years of complimentary identity/credit monitoring (via TransUnion per the notice), a remediation cost that was not itemized in dollars.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/carnival-corporation-employee-vishing-breach-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "citizens-disability-ssdi-robocall-scheme-2025",
            "title": "Citizens Disability SSDI Impersonation/Robocall Scheme",
            "victim": "General public / consumers nationwide, particularly lower-income and disabled individuals, whose numbers were on or off the National Do Not Call Registry",
            "incident_date": "Conduct: January 2019 - July 2022. Complaint filed and stipulated order entered: September 30, 2025.",
            "year": 2019,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Professional & Business Services",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$2,000,000 civil penalty judgment entered jointly and severally against Citizens Disability, LLC and CD Media, LLC in the stipulated order. $1,000,000 of that is suspended contingent on compliance (becomes immediately due in full if defendants misrepresented their financial condition); the non-suspended $1,000,000 is payable in two $500,000 installments (within 7 days of entry, and within one year of entry). FTC publicly characterized the outcome as the companies \"will pay $1 million.\" No consumer restitution/redress fund was reported in the sources reviewed.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/citizens-disability-ssdi-robocall-scheme-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "clorox-cognizant-helpdesk-vishing-2023",
            "title": "Clorox / Cognizant Help-Desk Pretexting Breach",
            "victim": "The Clorox Company and Clorox Services Company (via its outsourced IT service-desk vendor, Cognizant Technology Solutions / Cognizant Worldwide Limited)",
            "incident_date": "2023-08-11 (attack); 2023-08-14 and 2023-09-18 (SEC 8-K disclosures); 2025-07-22 (lawsuit filed)",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Retail & E-commerce; Technology & Software",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 380000000,
            "loss_basis": "Clorox alleges total damages of approximately $380 million. Including more than $49 million in remedial/remediation costs plus \"hundreds of millions of dollars\" in business-interruption losses from lost sales, paused manufacturing, and weeks of manual order processing. These figures are Clorox's pleaded damages claim in active litigation, not a court-awarded or independently audited amount.",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/clorox-cognizant-helpdesk-vishing-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "cohost-fabricated-ai-candidate-references-2026",
            "title": "CoHost’s Near-Hire of a Fabricated AI Candidate with Deepfake-Mimicking References",
            "victim": "CoHost, a podcast growth and analytics tool operated by Quill Inc. (Toronto, Canada); CEO Fatima Zaidi and CTO Abhinav Mathur are the named first-party sources.",
            "incident_date": "2026 (interview process ran roughly Feb-April 2026; publicly disclosed April 21, 2026)",
            "year": 2026,
            "country": "Canada",
            "attack_channels": "Deepfake & Synthetic Media; Phishing",
            "sectors": "Media & Entertainment; Professional & Business Services; Technology & Software",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None disclosed. The fraud was caught before an offer was extended, so no salary, payroll, or onboarding losses occurred. No dollar figure was reported in the primary account or in secondary press coverage; the only \"cost\" described is roughly two months of hiring-team time across seven interview rounds.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/cohost-fabricated-ai-candidate-references-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "council-foreign-relations-watering-hole-ie-zero-day-2012",
            "title": "Council on Foreign Relations Watering-Hole Attack (IE Zero-Day, CVE-2012-4792)",
            "victim": "Visitors to the Council on Foreign Relations (CFR.org) website, primarily policy, government, and foreign-affairs professionals, plus CFR itself as the compromised host.",
            "incident_date": "2012-12-21 to 2012-12-29 (malicious content live from ~Dec 21; publicly disclosed Dec 28-29, 2012)",
            "year": 2012,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Government & Public Sector; Nonprofit & NGO",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not disclosed / not quantified publicly; impact framed as espionage risk rather than direct financial loss.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/council-foreign-relations-watering-hole-ie-zero-day-2012",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "cra-rcmp-tax-scam-vishing-project-octavia-2018-2020",
            "title": "CRA/RCMP Tax-Scam Vishing Network – Project OCTAVIA (2018-2020)",
            "victim": "Tens of thousands of Canadian taxpayers (CAFC/CRA reported roughly 60,000 complaints over the scam's run; separately, CAFC reported nearly 20,000 reports and more than 5,500 victims in 2019, but that figure covers the combined CRA, SIN, tech-support, and bank-investigator scam family, not the CRA scam specifically), disproportionately elderly Canadians and new immigrants",
            "incident_date": "2014-2020 (scam active); RCMP Project OCTAVIA investigation launched October 2018; India raids concentrated 2018-2019; Canadian arrests/charges Feb 2020-Dec 2020",
            "year": 2014,
            "country": "Canada",
            "attack_channels": "Pretexting & Impersonation; Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "The CRA phone scam alone caused over $16.8 million in reported victim losses from 2014 to 2019. RCMP reported the CRA phone scam alone caused over $16.8 million in reported victim losses from 2014-2019, rising to over $18.5 million cumulative by October 1, 2020; including the related Bank Investigator and Tech Support scams run by the same networks, total reported losses exceeded $30 million (Feb 2020) and later over $34 million (Oct 2020). Public Safety Canada separately reported CRA-scam losses fell from $6.4 million in 2018 to $1.4 million in 2019 after Project OCTAVIA disruption. CBC reported in 2018 that over $10 million had been stolen over five years with individual victims losing as little as $700 and as much as $110,000+ (one Toronto victim, Gehangir Rashidi, lost his entire $110,000 life savings via Bitcoin ATMs). These are reported-loss figures only; CAFC and RCMP both note significant underreporting.",
            "source_count": 11,
            "url": "https://socialengineeringexamples.com/cra-rcmp-tax-scam-vishing-project-octavia-2018-2020",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "crelan-bank-ceo-fraud-2016",
            "title": "Crelan Bank CEO Fraud (Belgium, 2016)",
            "victim": "Crelan Bank (Belgium)",
            "incident_date": "2016-01-14 (fraud discovered internally); 2016-01-19 (publicly disclosed by Crelan)",
            "year": 2016,
            "country": "Belgium",
            "attack_channels": "Phishing",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 75800000,
            "loss_basis": "Gross loss of nearly/up to EUR 70 million (~US$75.8 million at contemporaneous exchange rates). This top-line figure is directly confirmed by Crelan's own 2016 press statement (\"fraude van bijna 70 miljoen EUR\" / \"fraude de près de 70 mio EUR\") and by contemporaneous Belgian press (VRT, De Standaard, De Tijd, RTBF, De Morgen). The finer FY-by-FY accounting breakdown is only partially verifiable. Crelan's 2015 annual report confirms the fraud reduced the Crelan Group's FY2015 net result to EUR 40.59 million (from a hypothetical EUR 71 million \"without this impact\"), implying an after-tax FY2015 hit of roughly EUR 30.4 million that year, with the remainder of the loss presumably absorbed in FY2016. A widely-circulated granular breakdown of \"EUR 44.6 million booked in FY2015, EUR 24.5 million in FY2016\" could NOT be corroborated in either Crelan's 2015/2016 annual report PDFs or in any secondary press coverage found across multiple searches, and should be treated as unverified rather than confirmed. Notably, EUR 24.5 million also recurs, unrelated, as a 2019 cooperative-dividend figure in Crelan's later (2019/2020) consolidated financial statements, raising concern that figure may have been misattributed to the fraud loss rather than drawn from the actual disclosure. On the insurance side, CrelanCo's FSMA-approved 2018 cooperative-share prospectus states plainly that during 2016 Crelan received a EUR 10 million payment from its insurer for the fraud damage, the maximum amount recoverable under the relevant policy, so the widely-repeated \"EUR 10 million insurance payout\" figure IS independently confirmed by a primary regulatory filing. That 2016 insurance payout is distinct from, and should not be confused with, the separately-disclosed \"exceptional recovery\" that Crelan's 2020 Consolidated Financial Statements say occurred in FY2019 in relation to the 2016 fraud, whose amount is not stated in that document. Crelan stated no customers were financially affected and that the bank could absorb the loss through its reserves/capital buffers without external assistance.",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/crelan-bank-ceo-fraud-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "cvs-caremark-pharmacy-trash-disposal-2009",
            "title": "CVS Caremark Pharmacy Trash Disposal Case (FTC/HHS Settlement)",
            "victim": "CVS Caremark Corporation / CVS Pharmacy, Inc. (and, downstream, CVS's pharmacy customers and employees whose records were exposed)",
            "incident_date": "Discovered July 2006 into 2007; HHS resolution agreement signed January 16, 2009; settlement announced February 18, 2009; FTC final consent order approved June 23, 2009",
            "year": 2006,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Healthcare",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 2250000,
            "loss_basis": "$2,250,000 paid by CVS Pharmacy, Inc. to HHS Office for Civil Rights (HIPAA Privacy Rule resolution), plus a 3-year Corrective Action Plan. The parallel FTC consent order imposed no monetary payment but required an ongoing security program, independent biennial assessments, and recordkeeping, with civil penalties possible only for future violations of the order",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/cvs-caremark-pharmacy-trash-disposal-2009",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "vidoc-security-deepfake-candidate-interviews-2025",
            "title": "Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)",
            "victim": "Vidoc Security Lab, a San Francisco-headquartered, Polish-founded, remote-first, AI-assisted code-security startup (also operating a Polish legal entity, VIDOC SECURITY LAB SP. Z O.O., registered in Gdańsk) cofounded by Dawid Moczadło and Klaudia Kloc (formerly ethical hackers/bug-bounty researchers), which had raised a $600K pre-seed/seed round in 2023 and a further $2.4M seed round in October 2024 (from Pebblebed, Firestreak Ventures, XFactor Ventures, and 500 Emerging Europe) and was hiring backend engineers for a Poland-based remote role at the time of both incidents.",
            "incident_date": "First incident: approx. December 2024 (exact date not published in primary sources). Second incident: 2025-02-04 (per Dawid Moczadło's LinkedIn post). Vidoc Security Lab's own postmortem blog post published 2025-03-27; The Pragmatic Engineer newsletter deep-dive published 2025-03-11 (based on interview with cofounder before the blog post went up).",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Cross-Sector / Multiple Industries; Cybersecurity Industry; Technology & Software",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No confirmed direct financial loss: neither fake candidate was extended an offer or paid a salary, and no funds were transferred. Costs were operational and opportunity costs: recruiter and cofounder interview time, disrupted hiring funnel for a role sourced from roughly 500 applications, and the reputational and security risk that would have materialized had either impostor been hired into a codebase-access engineering role at a security company. No dollar figure has been published by any source.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/vidoc-security-deepfake-candidate-interviews-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "des-healey-deepfake-martin-lewis-elon-musk-revolut-scam-2023",
            "title": "Deepfake Martin Lewis/Elon Musk Investment Scam Costs Brighton Man £76,000 via Fake Revolut Account “Carl”",
            "victim": "Derren \"Des\" Healey, self-employed kitchen fitter, Brighton/Peacehaven, East Sussex, UK",
            "incident_date": "August 2023 (initial loss); ongoing coverage through March 2025 (ITV documentary)",
            "year": 2023,
            "country": "United Kingdom",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Consumer / General Public; Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Approximately £76,000 total (reported as £75,000 in some later headlines): an initial £1,000 \"investment,\" then £5,000 of life savings. Followed by four separate loans totaling £70,000 taken out to keep feeding the scheme. Two of the four loans were later cancelled by their lenders after review, but Des Healey was left owing roughly £20,000 plus almost £6,000 in accrued interest, and was pursuing the UK Financial Ombudsman Service for further redress. No source confirms recovery of the funds actually stolen/transferred to the scammer.",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/des-healey-deepfake-martin-lewis-elon-musk-revolut-scam-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "dickinson-public-schools-vendor-bec-2026",
            "title": "Dickinson Public Schools $4.9M Vendor-Impersonation BEC",
            "victim": "Dickinson Public Schools (K-12 district), Dickinson, North Dakota",
            "incident_date": "2026-02 (disclosed 2026-02-10; recovery announced 2026-04-30)",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Education; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 4920000,
            "loss_basis": "$4.92M initially lost across two redirected vendor payments; ~$4,856,578.51 seized and held in federal custody, pending return to the district",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/dickinson-public-schools-vendor-bec-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "doj-225m-pig-butchering-usdt-forfeiture-2025",
            "title": "DOJ files record $225.3M civil forfeiture against USDT laundered from pig-butchering crypto scams (2025)",
            "victim": "The unsealed civil forfeiture complaint identifies approximately 430-434 suspected victims (rounded to more than 400 in the DOJ press release), described in the complaint as located primarily in the United States, with additional victims in the United Kingdom, Australia, and Germany. Of these, law enforcement interviewed about 60 confirmed victims who collectively lost roughly $19 million in the transactions specifically traced in the complaint; the complaint recounts millions of dollars in victim losses overall.",
            "incident_date": "2025-06",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Cryptocurrency & Digital Assets; Financial Services & Insurance",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$225.3M USD in cryptocurrency (USDT, precisely $225,364,961 USDT) targeted for forfeiture. Laundering network moved roughly $3B in crypto through approximately 144 OKX exchange accounts over about a year",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/doj-225m-pig-butchering-usdt-forfeiture-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "chinese-organized-crime-mistaken-refund-elder-fraud-2025",
            "title": "DOJ/IRS-CI Unseal $65M “Mistaken Refund” Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring",
            "victim": "Thousands of US senior citizens, including a named 97-year-old San Diego widow of a Holocaust survivor who lost her entire life savings",
            "incident_date": "2025-08-27 (nationwide takedown/indictments unsealed); scheme operated since at least 2019; guilty pleas continuing into 2026 (Ziyue Zhao plea reported Apr. 2, 2026; Hua Wang and 10 others by ~July 2026)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation; Smishing (SMS Phishing); Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$65 million in alleged total fraud/laundering proceeds cited in the indictments. More than $4.2 million seized in cash/financial accounts during the August 2025 takedown, plus luxury vehicles (a 2022 Mercedes-Benz G63, 2024 Porsche Panamera, and 2025 GMC Yukon Denali) seized as suspected proceeds. Subset admissions from later guilty pleas: defendant Ziyue Zhao admitted the organization received roughly 1,269 victim cash packages averaging about $14,000 each (~$17.8M) during Feb. 2020-Mar. 2021 alone; defendant Hua Wang later admitted responsibility for over 2,000 cash packages and $64 million in victim losses tied to his portion of the scheme (per follow-up DOJ/IRS reporting in 2026). Defendant Zhiyi Zhang alone was linked to at least $1.8 million in losses per the government's detention memo. One named victim, a 97-year-old San Diego widow of a Holocaust survivor, lost her entire life savings.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/chinese-organized-crime-mistaken-refund-elder-fraud-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "dominican-republic-grandparent-scam-attorney-police-impersonation-2024",
            "title": "Dominican Republic “Grandparent Scam” – Attorney/Police Impersonation Ring (D.N.J. Indictment)",
            "victim": "Hundreds of elderly US residents, concentrated in New Jersey, New York, Pennsylvania, and Massachusetts; nine victims specifically identified in the indictment (Victims 1-9, mostly New Jersey, one Pennsylvania)",
            "incident_date": "Conspiracy charged (Count One, Mail and Wire Fraud Conspiracy) as operating from at least January 2019 through December 2023, per the indictment's own charging language; the money-laundering conspiracy (Count Seventeen) is charged over the same January 2019-December 2023 window. Specific overt acts underlying the wire/mail fraud counts (Counts 2-16) that were reviewed run from May 2021 through June 2022, a narrower slice within the charged conspiracy period. 19-count indictment filed in D.N.J. 2024-01-04, unsealed 2024-04-29; DOJ announced charges 2024-04-30; ongoing prosecution through 2024-2025 with extraditions and a guilty plea. Note: the separately charged courier case against Victor Valdez covers roughly August 2020-August 2021, and that window belongs to Valdez's individual courier conduct only and should not be read as the main scheme's charged period.",
            "year": 2019,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 10000,
            "loss_basis": "DOJ states the scheme defrauded \"hundreds\" of elderly Americans of \"millions of dollars\" in aggregate. But no exact total-loss figure or victim-by-victim damages table is disclosed in the public charging documents reviewed. In a related but distinct case, courier Victor Valdez is alleged to have collected cash from victims over roughly August 2020-August 2021, with individual pickups described in the tens of thousands of dollars in some instances; that figure and window belong to Valdez's case, not an audited total for the main 11-defendant scheme. On the money-laundering counts specifically: Count Seventeen (money-laundering conspiracy, 18 U.S.C. § 1956(h)) alleges, as one of three alternative theories of the conspiracy, that conspirators engaged in monetary transactions in criminally derived property valued at more than $10,000, in violation of 18 U.S.C. § 1957(a), but that $10,000 threshold attaches to Count Seventeen's Section 1957(a) object clause, not to the substantive money-laundering Counts Eighteen and Nineteen, which are charged under 18 U.S.C. § 1956(a)(1)(B)(i) and do not carry a stated dollar threshold in the charging language. Count Eighteen concerns cash taken from Victim 5 (Williamstown, NJ) and Count Nineteen concerns cash taken from Victim 9 (Paterson, NJ), per the indictment, though the specific dollar amounts of those individual transactions are not stated in the portions of the charging documents reviewed. Figures beyond \"hundreds of victims\" / \"millions of dollars\" should be treated as DOJ's characterization, not an audited total.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/dominican-republic-grandparent-scam-attorney-police-impersonation-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "doorstep-dispensaree-gdpr-paper-records-fine-2019",
            "title": "Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy’s Back Yard Trigger the ICO’s First GDPR Fine (2019)",
            "victim": "Doorstep Dispensaree Ltd (UK pharmacy/medicines supplier to care homes); indirectly, an estimated tens of thousands of care-home residents whose NHS and prescription records were exposed",
            "incident_date": "2018-07-24 (MHRA search warrant); 2019-12-17 (ICO Monetary Penalty Notice)",
            "year": 2018,
            "country": "United Kingdom",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting); Pretexting & Impersonation",
            "sectors": "Healthcare",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "An initial ICO monetary penalty of £275,000 was issued in December 2019. Initial ICO Monetary Penalty Notice: £275,000 (issued 17 December 2019, reduced by the Commissioner from an original Notice of Intent figure of £400,000 in light of the company's financial position). On appeal, the First-tier Tribunal (18 August 2021) reduced the fine further to £92,000 after finding the actual audited document count (roughly 73,719 total documents seized, of which the tribunal found approximately 66,000 contained personal data: about 12,491 personal-data-only plus roughly 53,871 special-category/medical data documents, figures that reflect some internal rounding in the tribunal's own arithmetic) was far below the MHRA's original estimate of ~500,000; the Enforcement Notice was upheld in full. The Upper Tribunal ([2023] UKUT 132 (AAC)) and the Court of Appeal (9 December 2024, [2024] EWCA Civ 1515) both dismissed Doorstep Dispensaree's further appeals, leaving the £92,000 fine and Enforcement Notice standing. No customer/patient financial loss has been publicly attributed to this specific cache of exposed records; the company (Doorstep Dispensaree Limited, Companies House no. 09634666) is now shown as in liquidation.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/doorstep-dispensaree-gdpr-paper-records-fine-2019",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "dprk-revgen-wang-brothers-laptop-farm-2026",
            "title": "DPRK RevGen Massachusetts Scheme: Wang Brothers’ Laptop Farms and Shell Companies for North Korean IT Workers",
            "victim": "100+ U.S. companies, including multiple Fortune 500 firms; named/described victims include an unnamed California-based AI/defense contractor (\"Company C\") whose ITAR-controlled data was stolen, and a Massachusetts-based semiconductor distributor; more than 80 U.S. persons whose identities were stolen and used to secure the fraudulent jobs.",
            "incident_date": "Conduct: ~2021 to October 2024. Charges unsealed: June 27-30, 2025 (Zhenxing Wang indictment; Kejia Wang criminal information). Guilty pleas: Kejia Wang September 2025, Zhenxing Wang January 2026. Sentenced: April 15, 2026.",
            "year": 2021,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Cross-Sector / Multiple Industries; Defense & Aerospace; Manufacturing & Industrial; Professional & Business Services; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "DOJ: scheme generated more than $5 million in illicit revenue for the DPRK regime. Victim companies incurred at least $3 million in legal fees, network-remediation costs, and other damages. Kejia Wang, Zhenxing Wang, and four other US facilitators collectively received nearly $700,000 for their roles. Court ordered $600,000 in forfeiture (of which $400,000 had been recovered by sentencing) plus $29,236.03 in restitution from Kejia Wang. All figures per DOJ press releases; not independently audited outside the criminal case.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/dprk-revgen-wang-brothers-laptop-farm-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ea-games-slack-mfa-breach-2021",
            "title": "EA Games Slack/MFA Social Engineering Breach (2021)",
            "victim": "Electronic Arts (EA)",
            "incident_date": "2021-06-06 to 2021-07-14 (intrusion/theft occurred by early June 2021; forum sale ad ~June 6; EA confirmed breach June 11, 2021; extortion threat and partial file leak disclosed by EA July 14, 2021)",
            "year": 2021,
            "country": "United States",
            "attack_channels": "Help-Desk & MFA Manipulation",
            "sectors": "Media & Entertainment; Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No direct ransom paid and no material financial impact publicly confirmed by EA. The stolen ~780GB dataset (including FIFA 21 and Frostbite engine source code) was initially advertised for sale on underground forums for $28 million; hackers later shifted to extortion, releasing a portion of files publicly in July 2021 while demanding payment. EA's official statements said it saw no material risk to its games or business and no impact to player data; no SEC filing or disclosed monetary loss figure was located.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/ea-games-slack-mfa-breach-2021",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "edva-simex-domain-seizure-pig-butchering-2022",
            "title": "EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme",
            "victim": "5 individual US-based victims (unnamed in the DOJ release)",
            "incident_date": "2022-05 through 2022-08 (fraud period); announced/seized 2022-11-21",
            "year": 2022,
            "country": "United States",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Cryptocurrency & Digital Assets",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Over $10 million combined losses across 5 US victims (reported regionally as roughly S$13.8 million). Documented detail on one victim: after being tricked in May 2022 into installing a fake investment app with an initial deposit of just $400, that victim went on to transfer approximately $9.6 million in USD Coin (USDC) to a scammer-controlled deposit address.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/edva-simex-domain-seizure-pig-butchering-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "rimasauskas-google-facebook-bec-2019",
            "title": "Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake “Quanta Computer” vendor invoices",
            "victim": "Google (Alphabet), \"Victim-1\", ~$23M; and Facebook (Meta), \"Victim-2\", ~$99M. The real vendor impersonated was Quanta Computer Inc. of Taiwan.",
            "incident_date": "2013 to 2015 (scheme); indictment unsealed 2017; guilty plea 2019-03; sentenced 2019-12",
            "year": 2013,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial; Technology & Software",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 122130000,
            "loss_basis": "~$122.13M wired to attacker accounts ($23.26M from Google, $98.87M from Facebook, per the sentencing transcript), commonly cited by DOJ/press as \"over $120M\" or \"over $100M\". Much of Facebook's transfers were frozen or reversed; ~$26.48M restitution/forfeiture ordered and Rimasauskas agreed to forfeit $49.7M he personally obtained. Some losses remained unrecovered.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/rimasauskas-google-facebook-bec-2019",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "facc-fake-president-ceo-fraud-2016",
            "title": "FACC “Fake President” CEO fraud drains ~EUR 42M from Austrian aerospace supplier",
            "victim": "FACC AG / FACC Operations GmbH, an Austrian aerospace parts manufacturer (Ried im Innkreis) and Tier-1 supplier to Airbus, Boeing and Rolls-Royce; majority-owned by Aviation Industry Corp. of China. The finance/accounting department was the direct target.",
            "incident_date": "2016-01-19",
            "year": 2016,
            "country": "Austria",
            "attack_channels": "Phishing",
            "sectors": "Defense & Aerospace; Transportation & Logistics",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 47,
            "loss_basis": "Approx. EUR 50M initially transferred out; EUR 10.9M was frozen/blocked in recipient accounts and later partially recovered. Leaving a one-time charge of EUR 41.9M (~$47-50M) on the 2015/16 results. The loss pushed FACC to an EBIT of EUR -23.4M for the year.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/facc-fake-president-ceo-fraud-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fake-anydesk-installer-filefix-metastealer-2025",
            "title": "Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix",
            "victim": "Unidentified individual searching online for the AnyDesk remote-access tool, who reported the encounter to Huntress researcher John Hammond",
            "incident_date": "2025-08-29 (Huntress publication date; underlying victim encounter occurred in the preceding weeks, reported to Huntress researcher John Hammond by email)",
            "year": 2025,
            "country": "Unknown",
            "attack_channels": "ClickFix & SEO Poisoning",
            "sectors": "Consumer / General Public; Cross-Sector / Multiple Industries",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not disclosed. This was an individual/consumer-level incident surfaced via a tip to a researcher rather than a breach with reported monetary loss; Huntress's write-up focuses on the technical infection chain and does not report a dollar figure. MetaStealer is a credential/file/crypto-wallet stealer, so financial impact to the reporting victim (if any) was not quantified in the source material.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/fake-anydesk-installer-filefix-metastealer-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fake-chatgpt-download-site-openew-app-2026",
            "title": "Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload",
            "victim": "Windows and macOS users who searched for or clicked ads/links for a \"ChatGPT download,\" believing they were installing OpenAI's official desktop app",
            "incident_date": "Publicly disclosed by Malwarebytes on 2026-05-28 (the earliest date solidly corroborated by a source); related Push Security LLMShare research published 2026-05-29; the Joe Sandbox analysis of the Chat_GPT.exe sample is also dated 2026-05-29 (uploaded 14:28 CEST, analysis completed 16:43 CEST). No source found in verification corroborates the campaign being active as early as 2026-05-26; that earlier date was an unsupported inference and has been removed.",
            "year": 2026,
            "country": "Unknown",
            "attack_channels": "ClickFix & SEO Poisoning; Phishing",
            "sectors": "Consumer / General Public; Cryptocurrency & Digital Assets; Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 15,
            "loss_basis": "No confirmed victim count or aggregate theft total was publicly reported by Malwarebytes or Push Security. The Malwarebytes blog only cites the attackers' likely operating costs as estimates: roughly $15/year for the openew[.]app domain, an estimated setup cost of under $100 for the Windows delivery chain, and a reported rental price of about $3,000/month in cryptocurrency for access to Odyssey Stealer as malware-as-a-service. Actual victim losses (stolen crypto, credentials, wallet contents) are not quantified in the source reporting.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/fake-chatgpt-download-site-openew-app-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fbi-ic3-psa241203-generative-ai-financial-fraud-2024",
            "title": "FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)",
            "victim": "General public and financial institutions in the United States (advisory synthesizes aggregated IC3 victim-complaint patterns rather than naming specific victims)",
            "incident_date": "2024-12-03",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Consumer / General Public; Cross-Sector / Multiple Industries; Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "The PSA itself cites no dollar figures or complaint counts: it is a qualitative awareness bulletin. The FBI's later 2025 IC3 Annual Report (published April 6, 2026) quantified the same threat category for the first time: 22,364 AI-related complaints with $893,346,472 in adjusted losses in 2025. The report's dedicated AI section itemizes several sub-category figures, including Investment fraud (4,356 complaints, $632,041,188), Business Email Compromise (135 complaints, $30,256,592), Confidence/Romance (626 complaints, $19,041,653), and Employment fraud (691 complaints, $12,550,185); the remainder of the $893 million total is attributed to other AI-tagged categories the report also lists, such as Tech/Customer Support, Personal Data Breach, Phishing/Spoofing, and Government Impersonation. The FBI states these AI-related figures are likely an undercount since they rely on complainant keyword self-reporting. Total 2025 IC3 complaints across all categories: 1,008,597, with $20.877 billion in total reported losses.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/fbi-ic3-psa241203-generative-ai-financial-fraud-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fbi-ic3-ai-fraud-893m-2025",
            "title": "FBI IC3’s First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)",
            "victim": "US consumers nationally who filed complaints with the FBI's Internet Crime Complaint Center (IC3) in which AI was identified as involved in the fraud, 22,364 complaints in aggregate, drawn from IC3's broader 2025 intake of over 1 million total complaints.",
            "incident_date": "Calendar year 2025 (figure published in FBI's 2025 Internet Crime Report, released April 6, 2026)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Cross-Sector / Multiple Industries; Cryptocurrency & Digital Assets; Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$893,346,472 in reported losses across 22,364 AI-related complaints for 2025, per the FBI. $893,346,472 in adjusted/reported losses across 22,364 AI-related complaints for calendar year 2025, a subset (roughly 4.3%) of IC3's total 2025 reported losses of approximately $20.877 billion (per the FBI's April 6, 2026 press release, \"nearly $21 billion\" across ~1,008,597 total complaints). For comparison, IC3's prior (2024) annual report, which had no dedicated AI category, recorded $16.6 billion in total losses.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/fbi-ic3-ai-fraud-893m-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fbi-uspis-ftc-quishing-brushing-package-scam-2025",
            "title": "FBI/USPIS/FTC “Brushing 2.0” Quishing Package Scam Advisories (2025)",
            "victim": "US postal customers / consumers nationwide (general public, no named individual victims)",
            "incident_date": "2025 (FTC consumer alert Jan 23, 2025; FBI IC3 PSA I-073125-PSA Jul 31, 2025; USPS employee advisory Aug 5, 2025; USPIS holiday advisory campaign Nov-Dec 2025)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "Consumer / General Public; Retail & E-commerce; Transportation & Logistics",
            "threat_actors": "",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar-loss figure or victim/complaint count specific to this quishing-brushing package variant has been published by any of the three agencies. The FBI PSA explicitly characterizes the scheme as \"not as widespread as other fraud schemes\" and gives no loss estimate; the FTC's Jan. 23, 2025 alert and the USPIS quishing/brushing pages likewise cite no figures for this specific scam. (For context only, not specific to this scheme: the FTC separately reported $470 million in aggregate consumer losses to text-message scams in 2024, with fake package-delivery texts the most commonly reported type, a related but distinct SMS-based scam category.) Given the absence of hard loss/victim data, financial impact should be treated as unquantified/unknown rather than zero.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/fbi-uspis-ftc-quishing-brushing-package-scam-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "federal-pretexting-prosecutions-bunch-anderson-2008",
            "title": "Federal Pretexting Prosecutions Post-2006: Bunch and Anderson Charged Under New Anti-Pretexting Statute (2008)",
            "victim": "Individual T-Mobile and Sprint/Nextel subscriber account holders whose confidential call detail records were obtained without their knowledge or consent (identities not publicly disclosed in the available record)",
            "incident_date": "2008 (Bunch: charged November 2008 per Wired's contemporaneous report, with the N.D. Alabama criminal information described by the prosecuting attorney as filed roughly three weeks before Jan. 8, 2009, i.e. ~mid-to-late December 2008; Anderson: grand jury indictment returned December 30, 2008, N.D. Ohio)",
            "year": 2008,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Telecommunications",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No financial-loss figures for victims and no final restitution or fine amounts are documented in the available primary or secondary record for either defendant. The statute (18 U.S.C. Section 1039) carried a maximum statutory penalty of 10 years' imprisonment and a $250,000 fine per violation, cited in contemporaneous reporting as Anderson's maximum exposure, not an amount actually imposed or lost by victims. Nicholas Shaun Bunch was also charged with aggravated identity theft, which carried a separate maximum of up to 2 years' imprisonment and a $250,000 fine per offense; per Wired's January 2009 report, Bunch agreed to plead guilty to both charges and to pay restitution in an amount to be determined by the court, with prosecutors agreeing to recommend a reduced sentence for his cooperation, but the actual restitution amount, final sentence, and any fine imposed are not documented in the available record. Secondary reporting (Tech Law Journal) states Anderson was later sentenced to 21 months in prison, but this could not be verified against a primary DOJ or court-docket source.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/federal-pretexting-prosecutions-bunch-anderson-2008",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fin7-carbanak-doj-prosecution-2018-2021",
            "title": "FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)",
            "victim": "100+ U.S. companies, predominantly restaurant, gaming/casino, and hospitality chains; publicly named victims include Chipotle Mexican Grill, Chili's, Arby's, Jason's Deli, Red Robin, and Emerald Queen Casino; a later, related mailed-USB campaign attributed to FIN7 targeted retail, restaurant, and hotel companies (2020) and expanded to transportation, insurance, and defense-sector companies (2021)",
            "incident_date": "2015-2021 (intrusion campaign); superseding indictments filed July 27, 2018, unsealed August 1, 2018; Hladyr arrested Jan. 2018 (Germany), pleaded guilty Sept. 11, 2019, sentenced April 16, 2021; Kolpakov arrested June 28, 2018 (Spain), pleaded guilty Nov. 16, 2020, sentenced ~June 24-25, 2021; Fedorov arrested early 2018 (Poland) and, per the last clear reporting located for this record, remained in Polish custody pending extradition with no confirmed plea or sentencing outcome identified; his case status is unconfirmed, not scheduled dates as previously stated; Iarmak (indicted separately as a fourth defendant, CR19-257RSM) arrested Nov. 2019 in Bangkok, Thailand, extradited to U.S. custody in 2020, pleaded guilty Nov. 22, 2021 to conspiracy to commit wire fraud and conspiracy to commit computer hacking, sentenced April 7, 2022 in Seattle to 5 years in federal prison; related FBI USB-campaign advisories issued March 2020 and updated through late 2021/2022",
            "year": 2015,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting); Vishing (Voice Phishing)",
            "sectors": "Defense & Aerospace; Financial Services & Insurance; Hospitality, Gaming & Travel; Retail & E-commerce; Transportation & Logistics",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "DOJ plea agreements (e.g., Hladyr's, Sept. 2019) stipulate FIN7 activity caused \"more than $100 million in losses\" tied to theft of roughly 15 million payment card records; prosecutors and security researchers have cited broader cumulative damage estimates as high as $1 billion when combined with the group's earlier Carbanak bank-targeting operations (AP News reported over 20 million card records and an estimated $1 billion in losses in its coverage of Iarmak's April 2022 sentencing). Courts ordered $2.5 million in restitution against both Hladyr and Kolpakov (each ordered jointly/severally liable up to that amount, distributed to victims). These are DOJ/plea-agreement and press figures, not a single independently audited total loss for the entire 100+-victim campaign.",
            "source_count": 16,
            "url": "https://socialengineeringexamples.com/fin7-carbanak-doj-prosecution-2018-2021",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fin7-badusb-bestbuy-giftcard-usps-mailing-2020",
            "title": "FIN7 BadUSB “Best Buy” Gift Card Mailings via USPS",
            "victim": "Unnamed US hospitality-sector organization analyzed by Trustwave SpiderLabs (package intercepted, February 2020); broader campaign per FBI FLASH targeted unnamed retail, restaurant, and hotel businesses nationwide, primarily HR, IT, and executive-management staff",
            "incident_date": "2020-02 (package received by Trustwave-analyzed victim mid-February 2020); FBI FLASH alert issued 2020-03-26 (MI-000120-MW); follow-on FBI update 2022-01-06 (MU-000160-MW)",
            "year": 2020,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Defense & Aerospace; Hospitality, Gaming & Travel; Retail & E-commerce",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None confirmed for the documented 2020 Trustwave/FBI case; the recipient did not connect the device, so no compromise, data loss. Or ransom payment resulted from this specific intercepted package. No public reporting ties a dollar loss or confirmed breach to this particular mailing. (Later FBI reporting says FIN7's broader post-access objective in related campaigns was ransomware deployment, e.g., BlackMatter/REvil, but that outcome was not documented as resulting from this intercepted USB package.)",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/fin7-badusb-bestbuy-giftcard-usps-mailing-2020",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "forcedleak-salesforce-agentforce-2025",
            "title": "ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain",
            "victim": "Salesforce Agentforce and Einstein AI customers (organizations using Web-to-Lead-integrated CRM with AI agents), with no specific named victim organization; disclosed as a platform-wide vulnerability affecting the Salesforce customer base broadly",
            "incident_date": "2025-09-25 (public disclosure); vulnerability reported to Salesforce 2025-07-28, acknowledged 2025-07-31, mitigated 2025-09-08",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Cross-Sector / Multiple Industries; Technology & Software",
            "threat_actors": "Authorized Tester or Researcher",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No confirmed monetary loss disclosed. Attacker-side cost to exploit: approximately $5 to re-register/purchase the expired, still-CSP-whitelisted domain my-salesforce-cms.com used as the exfiltration endpoint. No breach notifications, fines, or customer financial-loss figures were reported in the cited sources; Salesforce and Noma both describe this as a responsibly-disclosed research finding rather than an incident with confirmed real-world victim losses.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/forcedleak-salesforce-agentforce-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "forest-blizzard-apt28-llm-recon-2024",
            "title": "Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance",
            "victim": "No specific victim organization was named by Microsoft or OpenAI. The subject matter researched, satellite communication protocols and radar imaging technology, is generically relevant to conventional military operations in the Russia-Ukraine war; no confirmed compromise of any organization was tied to this LLM activity.",
            "incident_date": "2024-02-14 (public disclosure date by Microsoft and OpenAI); the underlying LLM usage by Forest Blizzard occurred prior to disclosure but exact activity dates were not published",
            "year": 2024,
            "country": "Ukraine",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); Pretexting & Impersonation",
            "sectors": "Defense & Aerospace; Government & Public Sector; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None disclosed. This was a disrupted AI-service-abuse case, not a completed intrusion with quantified losses; no dollar figures, ransom, or breach costs were reported by Microsoft or OpenAI for the Forest Blizzard LLM activity.",
            "source_count": 2,
            "url": "https://socialengineeringexamples.com/forest-blizzard-apt28-llm-recon-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "fraudgpt-underground-chatbot-2023",
            "title": "FraudGPT Underground Chatbot",
            "victim": "Primary claimed victim class (per the advertised product): general phishing/BEC/carding targets that would be victimized by buyers using FraudGPT-generated content. No specific confirmed victim organization or individual identified in the public record. Secondary, independently documented victims: cybercrime-forum buyers themselves, who Cisco Talos found were defrauded of cryptocurrency by CanadianKingpin12 after being sold access to a product that did not function.",
            "incident_date": "2023-06-23 (Telegram channel created) through 2023-07-22/25 (public circulation and first vendor report); ongoing advertising into later 2023; Cisco Talos published a follow-up confirming the scam finding in 2025-06",
            "year": 2023,
            "country": "Unknown",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Cross-Sector / Multiple Industries; Cybersecurity Industry; Technology & Software",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 200,
            "loss_basis": "Advertised subscription: $200/month or $1,700/year (per Netenrich's original post); some secondary coverage adds an unverified $1,000/6-month tier. The seller claimed \"3,000+ confirmed sales/reviews,\" an unverified vendor/advertiser claim. No aggregate financial loss to downstream phishing/BEC victims has been publicly documented or attributed specifically to FraudGPT-generated content. Separately, Cisco Talos documented that the actor CanadianKingpin12 defrauded prospective buyers directly: after negotiation, Talos was given non-working login credentials and then asked to pay in cryptocurrency for a \"crack\" to unlock the site, which Talos and other would-be buyers concluded meant there was no working product at all. No specific dollar figure for buyer losses was disclosed.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/fraudgpt-underground-chatbot-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ftc-qr-code-scam-consumer-alert-2023",
            "title": "FTC Consumer Alert: QR Code Scams (Quishing)",
            "victim": "US consumers generally",
            "incident_date": "2023-12-06",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "Consumer / General Public; Government & Public Sector",
            "threat_actors": "",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No aggregate dollar-loss figure was published by the FTC or FBI for this specific wave. The FBI's Sept 19, 2023 advisory noted that in 2022 it began receiving reports of people falling victim to QR code scams, including some who lost money, but gave no total. Third-party figures cited in coverage (not FTC/FBI): eMarketer estimated 94 million US QR-scanner users in 2023 (102.6M projected by 2026, via CNBC); Trellix reported over 60,000 QR-code attack samples detected in Q3 2023 (via NYT/The Verge).",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/ftc-qr-code-scam-consumer-alert-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ftc-pretexting-sweep-telephone-record-sellers-2006-2008",
            "title": "FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)",
            "victim": "US consumers whose confidential telephone call records (Customer Proprietary Network Information / CPNI) were obtained without authorization from their carriers and sold to third parties; secondarily, the telecom carriers whose customer-service identity checks were defeated",
            "incident_date": "2006-05-01 to 2008-05-28 (FTC complaints filed 2006-05-01 and 2007-02-14; settlements and default judgments entered from 2006-10-05 through 2008-05-28)",
            "year": 2006,
            "country": "United States",
            "attack_channels": "Help-Desk & MFA Manipulation; Pretexting & Impersonation",
            "sectors": "Government & Public Sector; Professional & Business Services; Telecommunications",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Verified monetary judgments across confirmed sweep defendants totaled approximately $1,070,695.71. Verified monetary judgments across confirmed sweep defendants (from primary FTC complaint/order documents) total approximately $1,070,695.71 combined: Integrity Security & Investigation Services/Edmund Edmister $2,700 (paid in full, described by FTC as entire ill-gotten gains); Information Search Inc./David Kacala $40,075 judgment with all but $3,000 suspended for inability to pay; Action Research Group/Joseph & Matthew DePante $67,000 judgment with all but $3,000 suspended; Bryan Wagner (Action Research) $428,085 disgorgement via default judgment; Eye in the Sky Investigations/Cassandra Selvage $110,762 disgorgement via default judgment; CEO Group/Scott Joseph $222,381 judgment with all but $25,000 suspended; AccuSearch Inc./Jay Patel $199,692.71 monetary judgment (affirmed on appeal by the Tenth Circuit, 2009-06-29). No verified monetary figure was located in primary sources for the 16th defendant, 77 Investigations/Reginald Kimbro. Actual cash collected was far below the nominal totals because most judgments were suspended based on defendants' documented inability to pay.",
            "source_count": 20,
            "url": "https://socialengineeringexamples.com/ftc-pretexting-sweep-telephone-record-sellers-2006-2008",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ftc-task-scam-gamified-job-scam-spotlight-2024",
            "title": "FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)",
            "victim": "U.S. consumers nationwide (aggregate victims who filed reports with the FTC's Consumer Sentinel Network); no individual victims were named in the FTC materials",
            "incident_date": "2024-12-12 (FTC press release and Data Spotlight publication); underlying incident data spans H1 2024 (Jan-Jun 2024) with year-over-year comparisons back to 2020",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Phishing; Pretexting & Impersonation; Smishing (SMS Phishing)",
            "sectors": "Cross-Sector / Multiple Industries; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "FTC Consumer Sentinel data show $223 million reported lost to job scams in H1 2024 alone (task scams described as the fastest-growing. Driver of this category), compared to $286 million for all of 2023, $179 million (2022), $131 million (2021), and $90 million (2020). Cryptocurrency-specific job-scam losses were about $41 million in H1 2024 versus about $21 million in all of 2023, reflecting task scams' reliance on crypto deposits. No task-scam-specific median-loss figure was published; the FTC's broader 2024 Consumer Sentinel Data Book put the overall median fraud loss (all fraud types) at $497, with victims aged 80-and-over showing a much higher median (~$1,650), and victims aged 70-79 showing a median of about $1,000 (versus $417 for ages 20-29)",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/ftc-task-scam-gamified-job-scam-spotlight-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gao-fake-law-enforcement-badge-federal-building-breaches-2000-2009",
            "title": "GAO Covert Testers Use Fake Law-Enforcement Badges and Driver’s Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)",
            "victim": "Federal Protective Service-guarded facilities: in 2000, CIA HQ, FBI HQ, DOJ HQ, State Dept, Pentagon, Dept. of Energy, INS, Library of Congress, National Archives, USDA, HHS, HUD, Labor, DOT, FEMA, NASA HQ, a U.S. courthouse, plus Reagan National and Orlando International airports; in 2002, four Atlanta federal office buildings including the IRS Service Center; in 2009, 10 Level IV federal facilities in four cities including Dept. of Homeland Security, State and Justice Dept offices and congressional district offices. (No public GAO report documents a U.S. Capitol breach via this method.)",
            "incident_date": "April-May 2000 (GAO/T-OSI-00-10); February-March 2002 (GAO-02-668T, Atlanta incl. IRS Service Center); April-May 2009 (GAO-09-859T, driver's-license method); recurring low-disclosure FPS covert testing FY2010-FY2013 per GAO-15-445 (March 2015)",
            "year": 2000,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Government & Public Sector; Transportation & Logistics",
            "threat_actors": "Authorized Tester or Researcher",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No theft/fraud loss. These were GAO-authorized security audits, not criminal attacks. Contextual figures from the reports: FPS's contract-guard program was budgeted at roughly $613 million (cited in 2009) rising to about $1 billion with ~13,000 guards; the IED components used in the 2009 test were bought at retail/online for under $150; FY2011 FPS basic security fees totaled $236 million (GAO-12-739).",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/gao-fake-law-enforcement-badge-federal-building-breaches-2000-2009",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gci-w2-ceo-spoof-phish-2016",
            "title": "GCI (Alaska telecom) W-2 phishing: CFO-spoof email drained 2,500+ employees’ tax data",
            "victim": "General Communication, Inc. (GCI), an Anchorage-based Alaska telecom/ISP, and its subsidiaries Denali Media, UUI and Unicom; roughly 2,500+ current and former employees whose 2015 W-2 data was exposed.",
            "incident_date": "2016-02-24",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Media & Entertainment; Technology & Software; Telecommunications",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar-loss figure was publicly disclosed. Direct fraud losses were not quantified; costs included two years of AllClear ID credit monitoring, identity-theft counseling and identity-theft insurance for all affected employees, plus incident response. The exposed data (SSNs, income) created downstream tax-refund-fraud and identity-theft risk for 2,500+ people.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/gci-w2-ceo-spoof-phish-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "wesley-clark-phone-records-pretexting-2006",
            "title": "Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)",
            "victim": "Retired Gen. Wesley Clark (former NATO Supreme Allied Commander Europe, 2004 Democratic presidential candidate); secondarily, T-Mobile/Omnipoint Communications and Cingular Wireless as the carriers whose CPNI-release procedures were exploited",
            "incident_date": "2005-11-15 to 2006-01-12 (records obtained Nov 15-18, 2005; purchased and publicized by AMERICAblog on/around Jan 12, 2006)",
            "year": 2005,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Government & Public Sector; Media & Entertainment; Professional & Business Services; Telecommunications",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 89,
            "loss_basis": "Direct transaction values were small and personal, not corporate: Clark's 100-call record was purchased for $89.95 from CellTolls.com. Blogger John Aravosis separately paid $110 to LocateCell.com for his own records as a proof-of-concept. The episode's real \"cost\" was regulatory and legislative: it triggered FTC litigation against five phone-record broker companies (complaints dated May 1, 2006 and publicly announced May 3, 2006) and directly fed a federal law (Public Law 109-476) with compliance and enforcement costs borne industry-wide. No fine amount specific to the Clark purchase itself is documented.",
            "source_count": 11,
            "url": "https://socialengineeringexamples.com/wesley-clark-phone-records-pretexting-2006",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gmail-china-human-rights-activist-phishing-2010",
            "title": "Google Discloses Chinese Human-Rights-Activist Gmail Phishing/Malware Compromises (2010)",
            "victim": "Dozens of Gmail account holders identified by Google as human-rights advocates based in the US, China, and Europe. Individuals who later came forward publicly included artist/activist Ai Weiwei, Tibetan-rights activist and Stanford student Tenzin Seldon, human-rights lawyer/law professor Teng Biao, and activist Zeng Jinyan (wife of jailed dissident Hu Jia).",
            "incident_date": "Disclosed January 12, 2010; underlying account compromises were ongoing/routine, with some named victims reporting intrusions dating back to 2007",
            "year": 2010,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Media & Entertainment; Nonprofit & NGO; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None publicly quantified. This was an espionage/surveillance incident, not a financial-fraud one; the harm was unauthorized access to victims' private communications and contacts, not monetary loss. No fines, settlements, or breach-notification costs tied specifically to the activist-account compromises have been reported.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/gmail-china-human-rights-activist-phishing-2010",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gootloader-socgholish-six-law-firms-2023",
            "title": "GootLoader and SocGholish Dual Campaign Against Six Law Firms (2023)",
            "victim": "Six unnamed law firms (client identities withheld by eSentire)",
            "incident_date": "2023-01 to 2023-02 (attacks); report published 2023-02-28",
            "year": 2023,
            "country": "United States",
            "attack_channels": "ClickFix & SEO Poisoning",
            "sectors": "Legal Services",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No financial loss, ransom payment, or breach was disclosed. eSentire reported all 10 attack attempts were blocked before completion; no confirmed data exfiltration, ransomware deployment, or business email compromise was reported for this specific six-law-firm incident set.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/gootloader-socgholish-six-law-firms-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gootloader-returns-2025",
            "title": "Gootloader Returns After 7-Month Hiatus: SEO Poisoning, Glyph-Swapped Fonts, and a Dual-Personality Malformed ZIP (2025)",
            "victim": "General search users seeking legal/business document templates (e.g., NDAs, utility-easement agreements) whose machines become initial-access footholds into their employers' corporate networks",
            "incident_date": "Hiatus began 2025-03-31; campaign confirmed back and publicly reported 2025-11-05 (Huntress telemetry shows infections beginning 2025-10-27)",
            "year": 2025,
            "country": "Unknown",
            "attack_channels": "ClickFix & SEO Poisoning",
            "sectors": "Cross-Sector / Multiple Industries; Legal Services",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar figures were disclosed for this 2025 return specifically: no named victim, ransom demand, or loss total was published by Huntress. The independent researcher, The DFIR Report, or BleepingComputer. The downstream risk is real but unquantified in public reporting: Gootloader hands off access to Storm-0494, which grants it to Vanilla Tempest, a ransomware affiliate that has historically deployed Rhysida, BlackCat/ALPHV, Zeppelin, and Quantum Locker, all ransomware families associated with large (often six-to-seven-figure) extortion demands in other incidents, but none of those historical figures are tied to a confirmed victim of this specific November 2025 wave.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/gootloader-returns-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gootloader-seo-poisoning-legal-services-2021",
            "title": "GootLoader SEO Poisoning of Legal Services Firms",
            "victim": "Multiple (unnamed) law firms within CFC's cyber-insurance client base, plus a broader legal-services industry pattern independently corroborated by Sophos, eSentire, Mandiant, and Cybereason",
            "incident_date": "2021 (CFC client advisory published 2021-07-01/07-02; underlying GootLoader campaign against legal services documented from at least early 2021 through 2022-2023)",
            "year": 2021,
            "country": "Unknown",
            "attack_channels": "ClickFix & SEO Poisoning",
            "sectors": "Financial Services & Insurance; Legal Services",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar loss, ransom payment, or remediation-cost figure is documented in any primary source reviewed (CFC, Sophos, Mandiant, eSentire. Cybereason) for this specific legal-services GootLoader wave. CFC's advisory describes \"several ransomware attacks on legal services firms\" without naming victims or quantifying losses. The only dollar figure appearing on CFC's site from the same period is an unrelated item (the $2.3 million partial recovery of the Colonial Pipeline ransom, in a separate June 2021 news round-up). eSentire separately reported that legal-services clients accounted for 70% of all GootLoader cases its SOC handled in 2021, indicating scale of targeting without dollar figures.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/gootloader-seo-poisoning-legal-services-2021",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "greenpeace-dow-sasol-dline-dumpster-espionage-1998",
            "title": "Greenpeace v. Dow Chemical / Sasol Corporate Espionage (“D-Lines”)",
            "victim": "Greenpeace Inc. (and, per the complaint, its ally organization CLEAN)",
            "incident_date": "1998-2000 (D-line operations, July 13 1998 - July 18 2000); Lawsuit filed November 29, 2010; D.C. Court of Appeals ruling August 21, 2014",
            "year": 1998,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Manufacturing & Industrial; Media & Entertainment; Nonprofit & NGO; Professional & Business Services",
            "threat_actors": "Corporate / Competitive Intelligence",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Alleged espionage spending only (no financial harm figure to Greenpeace itself was quantified in the litigation. Which was dismissed before any damages phase): Dezenhall allegedly paid Beckett Brown International (BBI) approximately $150,000 between October 1998 and July 1999 for the \"U Street Project\" (on behalf of Sasol/CONDEA Vista); Ketchum allegedly paid BBI more than $125,000 between October 1998 and January 2001 for work on behalf of Dow Chemical. Sasol allegedly also paid BBI directly for the separate \"Lake Charles Project.\" No damages were ever awarded; the case was dismissed on procedural/legal grounds (RICO dismissed 2011; remaining state tort claims dismissed, affirmed by DC Court of Appeals in 2014) before reaching a merits trial or damages determination.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/greenpeace-dow-sasol-dline-dumpster-espionage-1998",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "dnc-clinton-podesta-google-alert-phishing-2016",
            "title": "GRU ‘Someone has your password’ phishing of the DNC and Clinton campaign (2016)",
            "victim": "Democratic National Committee (DNC), Democratic Congressional Campaign Committee (DCCC), and the Hillary for America (Clinton) campaign, including chairman John Podesta; 300+ targeted individuals",
            "incident_date": "2016-03-19",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Government & Public Sector; Nonprofit & NGO",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No direct fraud loss. The objective was espionage and election interference. Podesta's stolen archive and DNC/DCCC documents were leaked via DCLeaks, Guccifer 2.0, and WikiLeaks, causing major political damage during the 2016 U.S. presidential election.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/dnc-clinton-podesta-google-alert-phishing-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "anthropic-gtg-1002-ai-espionage-2025",
            "title": "GTG-1002: AI-Orchestrated Cyber-Espionage Campaign Run Through Claude Code (2025)",
            "victim": "Roughly 30 global organizations targeted, including large technology companies, financial institutions, chemical manufacturers, and government agencies, with a \"small number\" / \"handful\" of successful intrusions validated",
            "incident_date": "2025-09",
            "year": 2025,
            "country": "Unknown",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Financial Services & Insurance; Government & Public Sector; Manufacturing & Industrial; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "n/a (espionage / intelligence-collection operation; no dollar loss disclosed)",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/anthropic-gtg-1002-ai-espionage-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "anthropic-gtg2002-vibe-hacking-2025",
            "title": "GTG-2002 “Vibe Hacking”: Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations",
            "victim": "At least 17 distinct organizations across healthcare, government, emergency services, religious institutions, a defense contractor, and a financial institution (victims not individually named by Anthropic)",
            "incident_date": "2025-08",
            "year": 2025,
            "country": "Unknown",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Defense & Aerospace; Financial Services & Insurance; Government & Public Sector; Healthcare; Nonprofit & NGO",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 75000,
            "loss_basis": "Ransom demands of $75,000 to over $500,000 in Bitcoin per victim; total losses / payments not disclosed by Anthropic",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/anthropic-gtg2002-vibe-hacking-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gtg-5004-ai-generated-ransomware-as-a-service-2025",
            "title": "GTG-5004: UK Threat Actor Uses Claude to Develop and Sell AI-Generated Ransomware-as-a-Service",
            "victim": "Diffuse: other cybercriminals who purchased the ransomware builds on dark web forums (buyers), and by extension any downstream organizations later hit by ransomware built from the kits; no specific named end-victim organization is documented in Anthropic's report",
            "incident_date": "2025-01 (active since at least Jan 17, 2025) through 2025-08-27 (Anthropic disclosure/ban)",
            "year": 2025,
            "country": "United Kingdom",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Technology & Software",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 400,
            "loss_basis": "Ransomware packages sold for $400 to $1,200, per Anthropic's three-tier pricing. Ransomware packages sold for $400-$1,200 USD per Anthropic's three-tier pricing: (1) ransomware DLL/executable - $400, (2) full RaaS kit with PHP console and C2 tooling - $800, (3) Windows 10/11 FUD (fully undetectable) crypter for native binaries - $1,200. No aggregate revenue, victim count, or downstream ransom-payment total is disclosed by Anthropic.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/gtg-5004-ai-generated-ransomware-as-a-service-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "gtig-promptflux-ai-self-obfuscating-malware-2025",
            "title": "GTIG Discloses PROMPTFLUX: First “Just-in-Time” Self-Obfuscating AI Malware Using the Gemini API",
            "victim": "No specific named victim; GTIG reports no confirmed compromise of any victim network or device. Impact was limited to Google disabling the actor's own Gemini API assets (keys/projects/accounts) used to build and test the malware.",
            "incident_date": "2025-06 (first identified by GTIG) / 2025-11-05 (publicly disclosed)",
            "year": 2025,
            "country": "Unknown",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); Phishing; Pretexting & Impersonation",
            "sectors": "Cybersecurity Industry",
            "threat_actors": "",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None reported/quantified. GTIG states PROMPTFLUX's \"current state ... does not demonstrate an ability to compromise a victim network or device,\" and no ransom, theft, or breach loss figure is associated with it. (Contrast: the related PROMPTSTEAL/LAMEHUG family, attributed to Russia's APT28/FROZENLAKE and used operationally against Ukraine's security and defence sector, did achieve real data exfiltration per CERT-UA's July 2025 alert, but that is a distinct, already-operational malware family, not PROMPTFLUX itself.)",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/gtig-promptflux-ai-self-obfuscating-malware-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "hamilton-academical-rbs-vishing-fraud-2017",
            "title": "Hamilton Academical FC £989,000 Vishing Fraud (RBS Bank Impersonation)",
            "victim": "Hamilton Academical Football Club (\"Hamilton Accies\"), a Scottish Premiership football club; the dispute also directly implicates Royal Bank of Scotland (RBS) as the club's banking provider",
            "incident_date": "2017-10-09 to 2017-10-10 (fraudulent transfers); scam publicly disclosed by the club 2017-10-13; legal action against RBS announced 2018-02-06; RBS refused a Bankline daily transfer limit request 2018-03-22",
            "year": 2017,
            "country": "United Kingdom",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Media & Entertainment",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 1300000,
            "loss_basis": "Approximately £989,000 (~$1.3M) was transferred out of three Hamilton Academical bank accounts into 26 new accounts over 9-10 October 2017. The club recovered roughly £170,000 via suspended/clawed-back payments, leaving a net loss reported variably as approximately £800,000 (BBC, STV, and The Herald, February 2018) and £830,000 (Daily Record/Hamilton Advertiser, March 2018), the bulk of the club's financial reserves. Hamilton sought £400,000 to £415,000 (about 50% of the net loss, the two figures tracking the two loss estimates) from RBS in compensation via solicitors Levy & McRae. RBS rejected liability, and no publicly reported settlement, judgment, or case resolution was found as of the last dated coverage reviewed (March 2018).",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/hamilton-academical-rbs-vishing-fraud-2017",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "heartland-tri-state-bank-ceo-pig-butchering-2023",
            "title": "Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)",
            "victim": "Shan Hanes, CEO of Heartland Tri-State Bank (direct victim of the scam); Heartland Tri-State Bank, its shareholders, the FDIC, Elkhart Church of Christ, and the Santa Fe Trail Investment Club (all financial victims of Hanes's subsequent embezzlement)",
            "incident_date": "2022-12 to 2024-08-19 (scam contact began Dec 2022; bank wires May 17-Jul 7 2023; bank closed Jul 28 2023; federal charges filed Feb 12 2024; guilty plea May 23 2024; sentenced Aug 19 2024)",
            "year": 2022,
            "country": "United States",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Financial Services & Insurance; Nonprofit & NGO",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 47100000,
            "loss_basis": "Approximately $47.1 million embezzled from Heartland Tri-State Bank via 11 wire transfers. Approximately $47.1 million (exactly $47,105,000 per the U.S. sentencing memorandum) embezzled from Heartland Tri-State Bank via 11 wire transfers between 2023-05-17 and 2023-07-07, all funneled into cryptocurrency purchases that were then stolen by the scam operators; this loss was fully absorbed by the FDIC deposit insurance fund after the bank's failure, and bank shareholders/investors separately lost roughly $9 million in equity value (later reported as recovered in full via an FBI asset seizure from a Tether-held account, per Nov 2024 restitution proceedings). Additionally, before touching bank funds, Hanes stole $40,000 from Elkhart Church of Christ, $10,000 from the Santa Fe Trail Investment Club, and $60,000 from one of his daughters' college savings accounts, and lost roughly $1.1 million of his own personal funds, all of it fed into the same scam. The bank itself, a ~$139 million-asset agricultural community bank founded four decades earlier by a local family, was permanently closed and sold; it was one of only five U.S. bank failures in 2023.",
            "source_count": 11,
            "url": "https://socialengineeringexamples.com/heartland-tri-state-bank-ceo-pig-butchering-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "hp-boardroom-pretexting-2006",
            "title": "Hewlett-Packard Boardroom “Pretexting” Spying Scandal (2006)",
            "victim": "Hewlett-Packard board members (including Tom Perkins and George \"Jay\" Keyworth II), journalists covering HP (among them Pui-Wing Tam of The Wall Street Journal and Dawn Kawamoto of CNET News.com), HP employees, and family members of those targeted. HP itself was both the instigator and, ultimately, the corporate defendant.",
            "incident_date": "2005-04",
            "year": 2005,
            "country": "United States",
            "attack_channels": "Phishing; Pretexting & Impersonation",
            "sectors": "Media & Entertainment; Technology & Software",
            "threat_actors": "Corporate / Competitive Intelligence",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 14500000,
            "loss_basis": "$14.5M settlement with the California Attorney General in December 2006. $14.5M USD (December 2006 civil settlement with the California Attorney General: $13.5M to a new state Privacy and Piracy Fund, $650,000 civil penalties, $350,000 investigation costs; no admission of liability). Separate reputational and governance fallout; a shareholder suit also targeted ~$40M in executive stock sales around the disclosure.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/hp-boardroom-pretexting-2006",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "hornetsecurity-qrishing-us-msp-2023",
            "title": "Hornetsecurity QRishing Attack on US-Based MSP (2023)",
            "victim": "Unnamed US-based Managed Service Provider (MSP); single employee targeted",
            "incident_date": "2023-05-19",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None disclosed. Hornetsecurity's report contains no dollar figure, quantified loss, incident-response cost, or ransom/extortion amount. The vendor also does not confirm that the M365 account was actually compromised; its language describes the credential-harvesting login page as \"likely\" intended to capture credentials, not a confirmed successful takeover.",
            "source_count": 2,
            "url": "https://socialengineeringexamples.com/hornetsecurity-qrishing-us-msp-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "imperva-openclaw-message-object-prompt-injection-2026",
            "title": "Imperva OpenClaw Message-Object Prompt Injection (vCard/Contact/Geolocation)",
            "victim": "OpenClaw AI agent platform (self-hosted personal AI assistant deployments); no named individual or enterprise victim: this is a vendor security-research disclosure, not a reported exploited breach",
            "incident_date": "2026-06-10",
            "year": 2026,
            "country": "Unknown",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Consumer / General Public; Cybersecurity Industry; Technology & Software",
            "threat_actors": "Authorized Tester or Researcher",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None reported. This was a responsible-disclosure security research finding (proof-of-concept), not an exploited incident with named victims or financial loss. No dollar figures, breach costs, or affected-deployment counts were published by Imperva or found in any primary source.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/imperva-openclaw-message-object-prompt-injection-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "india-irs-uscis-vishing-call-center-takedown-2016",
            "title": "India-Based IRS/USCIS Impersonation Call-Center Takedown (U.S. v. HGlobal et al., 61 Defendants)",
            "victim": "Approximately 15,000+ U.S. residents deceived into paying the scam directly (elderly and immigrant populations disproportionately targeted), plus tens of thousands of separate identity-theft victims whose stolen PII was used to register the laundering prepaid cards",
            "incident_date": "2016-10-19 (grand jury returns superseding indictment; unsealed 2016-10-27); underlying scheme ran 2012/2013-2016; sentencings 2018-01-29 through 2020-11-30",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "DOJ's Oct. 2016 indictment alleged \"hundreds of millions of dollars\" in losses (a Fox News/press-conference figure cited $300M+) and over 15,000 known U.S. victims with upwards of 50,000 identities misappropriated to register prepaid cards - these are charging-document allegations, not judicially confirmed loss findings. (One outlier: NBC News' Oct. 2016 story cited a lower \"$50 million\" estimate from the same press conference, versus the \"$300M+\"/\"hundreds of millions\" figure reported by AP, Fox News, USA Today, CNN, Boston Globe, and ICE's own release.) TIGTA's own tracked/reported-victim figures were substantially lower and grew over time: ~12,027 victims reporting >$60.7M in losses as of Sept. 30, 2017, rising to more than 14,700 taxpayers reporting upwards of $72.8M as of TIGTA's Sept. 30, 2018 reporting period (figure independently corroborated by the U.S. Senate Special Committee on Aging's \"Fighting Fraud\" report). Individual defendants were held accountable at sentencing for specific laundered-funds ranges, e.g. Miteshkumar Patel for $9.5-25M, Hardik Patel for $3.5-9.5M, Sunny Joshi/Rajesh Bhatt (Call Mantra runners) for up to ~$9.5M; Hitesh Madhubhai Patel (HGlobal owner) was ordered to pay $8,970,396 in restitution at his 2020 sentencing.",
            "source_count": 12,
            "url": "https://socialengineeringexamples.com/india-irs-uscis-vishing-call-center-takedown-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ispoof-caller-id-spoofing-fletcher-2022",
            "title": "iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)",
            "victim": "Thousands of UK and global bank customers, with more than 200,000 people targeted in the UK alone and roughly 70,000 UK victims/targets subsequently contacted by police; secondary reporting names Barclays, HSBC, NatWest, Santander, Lloyds, Halifax, First Direct, Nationwide and TSB among the banks impersonated by iSpoof-enabled callers (not independently confirmed by a primary source), alongside government tax offices and retail companies",
            "incident_date": "Platform active 30 November 2020 to 8 November 2022 (created Dec 2020; Met Police \"Operation Elaborate\" investigation began June 2021; international takedown and server seizure 8 Nov 2022; Fletcher arrested 6 Nov 2022, pleaded guilty 20 April 2023, sentenced 19 May 2023)",
            "year": 2020,
            "country": "United Kingdom",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); Pretexting & Impersonation",
            "sectors": "Financial Services & Insurance; Government & Public Sector; Retail & E-commerce",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "UK losses exceeded £43 million; global losses estimated at over £100 million (both per CPS and Eurojust). iSpoof itself grossed roughly 112.6 BTC (~£3.2 million / EUR 3.7 million) in subscription revenue over about 16 months. Tejay Fletcher personally received at least £1.3 million from the site per the CPS (Eurojust cites GBP 1.7-1.9 million in profit to the \"main administrator\"); he had spent proceeds on a £230,000 Lamborghini, two Range Rovers (£110,000), and an £11,000 Rolex. CPS intended to pursue confiscation proceedings.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/ispoof-caller-id-spoofing-fletcher-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "sysdig-jadepuffer-agentic-ransomware-2026",
            "title": "JADEPUFFER: The First Documented Fully Agentic Ransomware Operation (2026)",
            "victim": "An undisclosed organization running an internet-facing Langflow instance and a separate internet-exposed production server hosting a MySQL database and an Alibaba Nacos configuration/service-discovery platform. Sysdig did not name the victim.",
            "incident_date": "2026-06",
            "year": 2026,
            "country": "Unknown",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 75000,
            "loss_basis": "n/a (no confirmed ransom paid; a Bitcoin ransom was demanded but the amount was undisclosed. And recovery was impossible because the AES key was generated randomly, printed once, and never persisted or transmitted. Sysdig's follow-up cited model-rebuild costs of $75,000-$500,000 per AI model for the evolved ENCFORGE variant.)",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/sysdig-jadepuffer-agentic-ransomware-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "jaguar-land-rover-vishing-shutdown-2025",
            "title": "Jaguar Land Rover Vishing-Triggered Shutdown",
            "victim": "Jaguar Land Rover (JLR), the British luxury automotive manufacturer owned by Tata Motors (Tata Group, India); employs roughly 34,000 people in the UK and supports an estimated 120,000+ additional UK jobs through its supply chain.",
            "incident_date": "2025-08-31 (intrusion begins) to 2025-11-14 (production returns to normal); attribution/method dispute first reported 2026-06-26 (New York Times)",
            "year": 2025,
            "country": "United Kingdom",
            "attack_channels": "Help-Desk & MFA Manipulation; Vishing (Voice Phishing)",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "alleged",
            "loss_usd": 350000000,
            "loss_basis": "UK economy-wide modeled impact of £1.9 billion, per the Cyber Monitoring Centre. UK economy-wide modeled impact: £1.9bn (range £1.6bn-£2.1bn per the Cyber Monitoring Centre, using information as of 17 Oct 2025), equivalent to roughly $2.5bn per NYT reporting; CMC assessed it as a \"Category 3\" systemic event affecting 5,000+ UK organizations and likely the most economically damaging cyber event in UK history. JLR's own direct costs: £238m of exceptional items in Q2 FY26 results (14 Nov 2025), of which £196m was cyber-incident-related and £42m was voluntary-redundancy costs; NYT/Infosecurity separately cited a roughly $350m (fiscal-year) hit to JLR. UK government backed up to £1.5bn via an Export Development Guarantee (UK Export Finance, announced 28 Sep 2025) to support JLR's supply chain, structured as a guaranteed commercial loan (not direct government lending), repayable over 5 years. Production loss estimated at close to 5,000 vehicles/week over the ~5-week halt (roughly 25,000 vehicles, a modeled figure not a JLR-confirmed count). Supplier-side: a survey of 84 West Midlands businesses (nearly 30,000 employees) by the Greater Birmingham, Black Country and Coventry & Warwickshire Chambers of Commerce (reported by Reuters and BBC, 26 Sep 2025) found 35% had cut staff hours and 14% were making redundancies, with some suppliers reporting only 7-10 days of cash remaining; Unite union estimated up to 104,000 supply-chain jobs at risk. Bank of England cited the JLR shutdown as a contributor to weaker-than-expected UK GDP growth in its 6 Nov 2025 Monetary Policy Report / rate decision, widely reported 6-7 Nov 2025.",
            "source_count": 15,
            "url": "https://socialengineeringexamples.com/jaguar-land-rover-vishing-shutdown-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "je-cleantech-dtc-dividend-bec-2026",
            "title": "JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)",
            "victim": "JE Cleantech Holdings Limited (Nasdaq: JCSE), a Cayman Islands-incorporated, Singapore-headquartered manufacturer of cleaning systems and dishwashing equipment (subsidiaries JCS-Echigo Pte. Ltd. and Hygieia Warewashing Pte. Ltd.)",
            "incident_date": "2026-02-07 (discovered, Singapore time); disclosed via SEC Form 6-K on 2026-02-09; follow-up Form 6-K/A on 2026-02-25",
            "year": 2026,
            "country": "Singapore",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 794934,
            "loss_basis": "USD 794,934.04 (approximately S$1,009,000) lost to the fraudulent wire; funds never reached DTC. This was in addition to (not a discount off) the underlying dividend obligation; JCSE later paid the legitimate dividend separately via its transfer agent. No portion of the stolen USD 794,934.04 is disclosed as recovered or insured in the SEC filings reviewed.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/je-cleantech-dtc-dividend-bec-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "jeffrey-maas-pnc-bank-gold-conversion-vishing-2024",
            "title": "Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)",
            "victim": "Jeffrey Maas, 76-77-year-old retiree, West Orange, New Jersey (PNC Bank customer)",
            "incident_date": "2024-06-05 to 2024-06-06 (fraud); lawsuit filed 2026-03-10/11; motion-to-dismiss denied 2026-06-18",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation; Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance; Retail & E-commerce",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 390000,
            "loss_basis": "$390,000 total lost across two fraudulent bank wire transfers, converted to gold coins. $390,000 total (two fraudulent bank wire transfers to the gold dealer: $300,000 on June 5, 2024, and $90,000 on June 6, 2024), converted to gold coins purchased from American Coin & Stamp Co. and handed to couriers; described as roughly half the victim's life savings",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/jeffrey-maas-pnc-bank-gold-conversion-vishing-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "johnson-county-schools-pearson-vendor-bec-2024",
            "title": "Johnson County Schools $3.36M fake-Pearson vendor BEC",
            "victim": "Johnson County Board of Education (Johnson County Schools), a rural district of ~4,500 students based in Mountain City, Tennessee; finance director Tina Lipford initiated the wires.",
            "incident_date": "2024-03-18 to 2024-04-18 (attack); federal civil-forfeiture complaint filed 2024-09-05",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Education; Government & Public Sector",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 3362215,
            "loss_basis": "$3,362,215.55 fraudulently wired in two transfers ($2,000,000 and $1,362,215.55); $742,000 recovered as of the Sept. 5, 2024 affidavit; drawn from Tennessee Investment in Student Achievement (TISA) state education funds.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/johnson-county-schools-pearson-vendor-bec-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "johor-baru-retired-bank-manager-macau-scam-2026",
            "title": "Johor Baru Retired Bank Manager Macau Scam (RM936,000)",
            "victim": "60-year-old retired bank manager (woman), Johor Baru, Malaysia",
            "incident_date": "2026-04-01 (scam initiated) to 2026-05-15 (loss discovered); police statement issued 2026-05-20",
            "year": 2026,
            "country": "Malaysia",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "RM936,000 (~USD 200,000) in total losses; entire life savings of the victim transferred into a scammer-directed account and then withdrawn by the syndicate. No recovery or restitution reported at time of the police statement.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/johor-baru-retired-bank-manager-macau-scam-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "kaiser-permanente-medical-waste-dumping-settlement-2023",
            "title": "Kaiser Permanente Medical Waste and Patient Records Dumpster-Disposal Settlement",
            "victim": "Kaiser Permanente (and, derivatively, the more than 7,700 patients whose PHI was exposed in discarded paper records)",
            "incident_date": "2023-09-08 (settlement announced); final judgment signed 2023-10-13; underlying conduct/investigation spanned 2015-2023",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Healthcare",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 49000000,
            "loss_basis": "$49,000,000 total settlement liability, including $39,263,000 in civil penalties. $49,000,000 total settlement liability, broken out in the final judgment as $39,263,000 in civil penalties, $4,905,000 for supplemental environmental projects, and $4,832,000 for attorneys' fees/investigation/enforcement costs. Kaiser can earn a $1,750,000 credit against civil penalties if, within 5 years, it spends at least $3,500,000 on specified environmental compliance measures, which is why the AG's press release framed the immediate payment as $47.25 million plus a contingent $1.75 million.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/kaiser-permanente-medical-waste-dumping-settlement-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "mitnick-novell-netware-pretexting-1994",
            "title": "Kevin Mitnick’s Pretexting of Novell Tech Support (NetWare Source Code Theft)",
            "victim": "Novell, Inc., specifically its technical support and network administration staff, targeting support analyst Shawn Nunley",
            "incident_date": "Underlying pretext calls and theft: primarily Dec 1993 - Jan 1994 (federal indictment: Count 21 possession of 50+ Novell usernames/passwords dated 12/20/93; Count 22 possession of 900+ Novell usernames/passwords dated 12/24/93; Count 17 alleges a password-interception program installed on Novell computers \"in or around December 1993\"; Count 1 dates a call from Mitnick, using the alias \"Gabe Nault,\" from Colorado to San Jose to 1/4/94). Mitnick arrested Feb 15, 1995, in Raleigh, NC. Indicted in 1996 as U.S. v. Mitnick, CR 96-881 MRP (C.D. Cal.). Pleaded guilty March 26, 1999. Sentenced Aug 9, 1999.",
            "year": 1993,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Technology & Software",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Disputed and largely alleged rather than adjudicated as actual loss. In a letter to the FBI, Novell valued the stolen NetWare source code's development cost at \"well in excess of $75,000,000\"; prosecutors later cited loss figures above $80 million in bail and sentencing filings covering the case's multiple corporate victims (Novell, Nokia, Motorola, Fujitsu, NEC, Sun). Mitnick's defense argued these were sunk R&D costs, not losses actually caused by the disclosure, and the U.S. Probation Office's presentence report put total potential loss across all counts/victims at $1,143,129.00. At sentencing, Judge Mariana R. Pfaelzer ordered only $4,125 in restitution, explicitly calling it a token amount, and imposed no fine.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/mitnick-novell-netware-pretexting-1994",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "knowbe4-fake-north-korean-it-worker-2024",
            "title": "KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity",
            "victim": "KnowBe4, Inc.",
            "incident_date": "2024-07-15 (malware detected/contained); hiring process preceded this in mid-2024; publicly disclosed 2024-07-23",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Cybersecurity Industry",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No confirmed financial loss, data breach, or exfiltration at KnowBe4 itself. The company states explicitly this was not a data-breach event and no customer data, source code, or production systems were touched. The only public dollar figures relate to the broader North Korean IT-worker fraud ecosystem this incident is part of, not KnowBe4 specifically: DOJ/FBI describe a related May 2024 case (US v. Christina Chapman et al.) involving more than 60 stolen US identities, over 300 victim companies (some listed on the Fortune 500), and at least $6.8 million in fraudulent revenue generated for North Korea between roughly October 2020 and October 2023.",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/knowbe4-fake-north-korean-it-worker-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "lampion-clickfix-portugal-tax-authority-2025",
            "title": "Lampion Banking Trojan ClickFix Campaign vs Portuguese Government, Finance and Transport Sectors",
            "victim": "Dozens of Portuguese government, financial, and transportation-sector organizations",
            "incident_date": "2025-05-06 (Unit 42 publication date); campaign activity observed late 2024 through early 2025, with Microsoft confirming activity active into June 2025 and later spreading beyond Portugal",
            "year": 2025,
            "country": "Portugal",
            "attack_channels": "ClickFix & SEO Poisoning",
            "sectors": "Financial Services & Insurance; Government & Public Sector; Transportation & Logistics",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not disclosed. No confirmed dollar losses, victim names, or confirmed data exfiltration were reported publicly, because Unit 42 observed that the final Lampion payload download command was commented out in the code, meaning the observed run did not complete delivery of the banking-infostealer payload.",
            "source_count": 2,
            "url": "https://socialengineeringexamples.com/lampion-clickfix-portugal-tax-authority-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "lastpass-deepfake-voice-ceo-2024",
            "title": "LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)",
            "victim": "LastPass (password management company, owned by GoTo); the direct target was a LastPass employee, reported by press as a sales executive. The impersonated executive was CEO Karim Toubba.",
            "incident_date": "2024-04",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$0 (no loss; attempt blocked)",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/lastpass-deepfake-voice-ceo-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "leoni-ag-ceo-fraud-2016",
            "title": "Leoni AG CEO Fraud (2016)",
            "victim": "Leoni AG (German cable and wiring-systems manufacturer, MDAX-listed, headquartered in Nuremberg), via its Romanian subsidiary's finance/accounting department in Bistrița",
            "incident_date": "2016-08-12 (fraud realized/discovered); 2016-08-16 (public ad hoc disclosure); 2016-09-14 (follow-up ad hoc disclosure confirming EUR 40m impact on FY2016 earnings)",
            "year": 2016,
            "country": "Germany",
            "attack_channels": "Phishing; Vishing (Voice Phishing)",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 44,
            "loss_basis": "Approximately EUR 40 million (~US$44.6-45.1 million at contemporaneous exchange rates) wired out and lost, per Leoni's own ad hoc disclosures. Leoni's Q3/FY2016 EBIT forecast was cut from EUR 105 million to EUR 65 million specifically to absorb this loss (per the 14 September 2016 ad hoc disclosure). Note: the criminal complaint filed with the Bistrița-Năsăud prosecutor's office reportedly cited a more precise figure of EUR 37,380,250 (~EUR 37.38 million), per Evenimentul Zilei's anonymously-sourced account of the actual transfer request, versus Leoni's own rounder public disclosure of \"approximately EUR 40 million.\" This record uses Leoni's own ad hoc figure (~EUR 40m) as the primary, most authoritative source, but the ~37m/~40m variance across sources should be treated as a minor open discrepancy rather than a settled precise figure. Approximately EUR 5 million was later recovered from insurers (reported March 2017), leaving the large majority of the loss unrecovered as of the last public reporting found.",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/leoni-ag-ceo-fraud-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "levelblue-mtdr-quishing-mfa-setup-2023",
            "title": "LevelBlue MTDR SOC “Quishing” Case Study – Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)",
            "victim": "Unnamed LevelBlue (AT&T Cybersecurity) Managed Detection and Response (MDR/MTDR) customer",
            "incident_date": "2023-10-10",
            "year": 2023,
            "country": "Unknown",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not disclosed. The LevelBlue case study does not state any dollar figure, ransom, fraud loss, or breach-notification cost; impact is described only as compromised credentials for \"several users,\" with no confirmed data exfiltration.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/levelblue-mtdr-quishing-mfa-setup-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "los-cyber-bank-impersonation-vishing-colombia-2026",
            "title": "Los Cyber Bank-Impersonation Vishing Network Dismantled in Colombia",
            "victim": "94 documented victims (bank customers of unnamed Colombian financial institutions), the large majority adults over 50, spread across 10 Colombian departments (Risaralda, Bogota, La Guajira, Valle del Cauca, Cauca, Atlantico, Narino, Quindio, Meta, Bolivar per the most-repeated list; some outlets substitute Cesar/Cundinamarca/Tolima for a few of these)",
            "incident_date": "Fraud scheme active June 2025 to March 2026; coordinated raids captured all 16 alleged members on July 9-10, 2026, per the Fiscalia/Policia press conference and the majority of contemporaneous outlets (El Tiempo, Infobae, El Pais, Caracol Radio), with coverage published/announced July 9-11, 2026. One outlet, El Diario (published Jul 10, 2026), instead states the physical captures occurred \"el martes 7 de julio\" (Tuesday, July 7, 2026), a minor cross-source date discrepancy, possibly reflecting a gap between the raid-execution date and the public press-conference/announcement date. One of the original 16 detainees, footballer Mateo Ramirez Florez, was individually profiled in a later wave of coverage on July 22-24, 2026 after his football-family lineage became public; this was a profile piece about an existing detainee, not a separate or 17th arrest.",
            "year": 2025,
            "country": "Colombia",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "COP 1,685,000,000 (reported by Fiscalia/Policia as \"mas de $1.685 millones de pesos\"). Using the official Colombian TRM exchange rate prevailing around the July 9-11, 2026 reporting window (Superintendencia Financiera de Colombia TRM: ~COP 3,339.65/USD on Jul 9, ~3,305.38 on Jul 10, ~3,248.87 on Jul 11, independently confirmed against three separate TRM-tracking sources), this converts to approximately USD $505,000-$519,000, i.e. roughly USD $500,000-520,000 (not the $400,000-420,000 previously stated, which implied an inaccurate ~4,000-4,200 COP/USD rate). Some early wire reports rounded the peso figure down to \"more than COP 1.600 millones.\" Authorities stated the true total could be higher as the investigation continues and additional victims are identified.",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/los-cyber-bank-impersonation-vishing-colombia-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "macewan-university-bec-fraud-2017",
            "title": "MacEwan University BEC Fraud",
            "victim": "MacEwan University",
            "incident_date": "August 2017 (fraudulent transfers Aug. 10, Aug. 17, and Aug. 19, 2017; discovered Aug. 23, 2017; publicly disclosed Aug. 31, 2017)",
            "year": 2017,
            "country": "Canada",
            "attack_channels": "Phishing",
            "sectors": "Education; Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$11.8 million CAD total redirected across three fraudulent wire transfers tied to the Allard Hall construction project: Aug. 10, 2017 ($1.9M), Aug. 17, 2017 ($22,000), and Aug. 19, 2017 ($9.9M, the final holdback payment owed to contractor Clark Builders). Roughly $11.4M was traced to bank accounts in Montreal and Hong Kong; $6.3M was seized from the Montreal account and the Hong Kong funds were frozen pending civil recovery action. By April 4, 2018, MacEwan reported it had recovered $10.92 million, leaving $880,000 of principal permanently unrecovered, plus an estimated $250,000 in legal and banking fees incurred during recovery, a net cash impact of roughly $1.13 million against the original $11.8M exposure. (MacEwan's 2017/18 annual report rounded the recovery figure to $10.8M; this is a rounding/reporting-date difference, not a contradiction of the underlying facts.)",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/macewan-university-bec-fraud-2017",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "main-line-health-w2-phish-2016",
            "title": "Main Line Health W-2 Executive-Spoof Phishing Breach",
            "victim": "Main Line Health System (nonprofit health system operating Lankenau, Bryn Mawr, Paoli, and Riddle hospitals; roughly 11,000 employees affected)",
            "incident_date": "2016-02-16",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Healthcare",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not publicly disclosed. No breach-related dollar loss figure was released; all affected employees faced tax-refund-fraud and identity-theft risk. Main Line Health incurred unquantified costs for free credit monitoring and a support call center for all employees.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/main-line-health-w2-phish-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "manhattan-bec-zubaid-rebiga-mizrahi-2021",
            "title": "Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company",
            "victim": "Brownsville Community Development Corporation (named in court filings as 'Corporation-1') and an unnamed private-equity-owned portfolio company ('Corporation-2')",
            "incident_date": "Fraud occurred May-July 2021; indicted December 2, 2022 (superseded December 19, 2023); Mizrahi convicted by jury March 4, 2024, sentenced September 10, 2024; Rebiga sentenced April 17, 2024; Goran sentenced March 17, 2025; Zubaid died before sentencing (never sentenced)",
            "year": 2021,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Financial Services & Insurance; Nonprofit & NGO",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 3488000,
            "loss_basis": "~$3,488,000 wired from Corporation-1's account (May 12-June 1, 2021, with ~$1,570,000 routed to a 'Goran Account'); ~$2,008. 034.76 wired from Corporation-2 (July 1, 2021, to a 'Rebiga Account'). DOJ's press release cites BEC victims wiring more than $5.4 million total across the case. Mizrahi was separately ordered to forfeit $4,545,704 and pay a $50,000 fine at sentencing; Goran was ordered to forfeit $10,000 and pay a $10,000 fine.",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/manhattan-bec-zubaid-rebiga-mizrahi-2021",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "mattel-ceo-fraud-wire-recovered-2015",
            "title": "Mattel CEO-Fraud Wire ($3M, Recovered)",
            "victim": "Mattel, Inc. (Los Angeles-based maker of Barbie and Hot Wheels); an unnamed finance executive authorized to approve wire transfers.",
            "incident_date": "2015-04-30",
            "year": 2015,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Retail & E-commerce",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "$3 million wired; fully recovered on May 6, 2015 (net loss effectively $0).",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/mattel-ceo-fraud-wire-recovered-2015",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "medidata-solutions-ceo-fraud-wire-2014",
            "title": "Medidata Solutions $4.8M CEO-Fraud Wire Transfer (2014)",
            "victim": "Medidata Solutions, Inc. (cloud-based clinical trial software company, then NASDAQ-listed under ticker MDSO)",
            "incident_date": "2014-09-16",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Healthcare; Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 4800000,
            "loss_basis": "$4.8 million transferred and lost (first wire of $4,770,226 completed, a second attempted wire was stopped). Medidata later recovered the loss through litigation against its insurer, winning a $5.8M judgment (damages plus interest), affirmed on appeal in 2018.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/medidata-solutions-ceo-fraud-wire-2014",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "mgm-resorts-scattered-spider-vishing-2023",
            "title": "MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)",
            "victim": "MGM Resorts International (NYSE: MGM), a Las Vegas-based global casino and hospitality operator",
            "incident_date": "2023-09",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Help-Desk & MFA Manipulation; Vishing (Voice Phishing)",
            "sectors": "Hospitality, Gaming & Travel",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 100000000,
            "loss_basis": "~$100M negative impact to third-quarter Adjusted Property EBITDAR (lost revenue, not a fine), plus under $10M in one-time response costs. Per MGM's SEC 8-K; a later $45M class-action settlement (preliminarily approved Jan 2025) covers both the 2023 and an earlier 2019 breach. No ransom paid.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/mgm-resorts-scattered-spider-vishing-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "microsoft-lapsus-dev-0537-intrusion-2022",
            "title": "Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)",
            "victim": "Microsoft Corporation",
            "incident_date": "2022-03-22 (Microsoft blog confirmation; source-code leak surfaced 2022-03-20/21; UK arrests announced 2022-03-24, though Computer Weekly separately reports the actual arrests occurred 2022-03-25)",
            "year": 2022,
            "country": "United States",
            "attack_channels": "Help-Desk & MFA Manipulation; Smishing (SMS Phishing)",
            "sectors": "Technology & Software",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not publicly quantified by Microsoft. Microsoft characterized the exposure as low-severity, stating source-code secrecy is not a security control and that \"viewing source code does not lead to elevation of risk\"; no customer code or data was affected, and no dollar loss figure has ever been disclosed for the Microsoft intrusion specifically. (For scale/context only, not part of the Microsoft loss. These are unrelated victims, not Microsoft: BBC, Dec 2023, reported that LAPSUS$ member Arion Kurtaj's separate 2022 hacks of Uber, Nvidia, and Rockstar Games together cost the three firms combined \"nearly $10m,\" not $10M as a third figure alongside individual per-company totals. Individual figures are inconsistent across outlets: Reuters/BBC cite roughly $3M in Uber damage; BBC separately says the Rockstar hack \"cost it $5m to recover from,\" while Sky News instead attributes a $5m remedial-cost figure to Nvidia and gives Rockstar only $1.5m \"in external help alone\" plus unquantified marketing-related losses. Outlets do not agree on which company the $5M figure belongs to, and this record does not attempt to resolve that discrepancy.)",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/microsoft-lapsus-dev-0537-intrusion-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "naresh-gujral-whatsapp-ceo-fraud-2026",
            "title": "Naresh Gujral WhatsApp CEO-Impersonation Fraud (2026)",
            "victim": "Naresh Gujral (former Rajya Sabha MP, son of former Indian Prime Minister I.K. Gujral) and his family-run south Delhi textiles/garment export company",
            "incident_date": "2026-06-12 to 2026-06-16 (fraud window); FIR filed 2026-06-16; arrest 2026-06-22/23",
            "year": 2026,
            "country": "India",
            "attack_channels": "Smishing (SMS Phishing); Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Manufacturing & Industrial",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 920000,
            "loss_basis": "Rs 7.68 crore (~US $920,000 at prevailing rates) stolen via four RTGS transfers. Widely rounded in headlines to \"Rs 7.8 crore.\" Delhi Police later reported Rs 4.28 crore marked as lien/frozen across various banks (roughly 56% of the total). Gujral himself and several outlets (PTI/Business Today, Times of India, Outlook) quoted him and police sources describing the recovery as \"more than 70 per cent\" or \"almost 70%\"; that 70% figure does not reconcile with the quoted Rs 4.28 crore lien amount against Rs 7.68 crore stolen (which is ~55.7%, rounding to 56%), so the 70% figure should be treated as an optimistic/approximate figure from the victim and unnamed police sources rather than a reconciled final recovery rate. The precise, bank-confirmed lien figure (Rs 4.28 crore / ~56%) is the better-sourced number, attributed on record to IFSO commissioner Vinit Kumar.",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/naresh-gujral-whatsapp-ceo-fraud-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "nations-title-agency-dumpster-diving-ftc-2006",
            "title": "Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)",
            "victim": "Nations Title Agency, Inc. (NTA) and its parent Nations Holding Company (NHC), plus NHC president/sole owner Christopher M. Likens, individually",
            "incident_date": "2006-05-10",
            "year": 2006,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No civil monetary penalty was imposed in the 2006 FTC consent order (this was the FTC's usual first-offense data-security settlement structure at the time). The real cost to the company was compliance-related: a mandatory comprehensive information-security program plus independent third-party security assessments every two years for 20 years, plus 5-10 year recordkeeping and notification obligations for Likens personally. The FTC's press release and complaint do not quantify consumer financial losses or number of affected consumers from either the dumpster exposure or the 2004 hack.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/nations-title-agency-dumpster-diving-ftc-2006",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "toll-road-smishing-wave-2024-2025",
            "title": "Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)",
            "victim": "Toll customers of E-ZPass (Northeast/Mid-Atlantic), SunPass/Florida's Turnpike, Pennsylvania Turnpike, MassDOT/EZDriveMA (Massachusetts), NTTA (North Texas Tollway Authority), Peach Pass (Georgia), and per FCC guidance also FasTrak (California) and I-PASS (Illinois) customers, across dozens of U.S. states.",
            "incident_date": "2024-04 to 2025 (ongoing recurrence); FBI IC3 PSA issued 2024-04-12; Cisco Talos traces campaign activity to approximately October 2024; FBI Atlanta issued a Peach Pass-specific alert 2025-03-12; PA Turnpike issued a follow-up alert 2025-02-13; Google filed a civil RICO/Lanham Act/CFAA lawsuit against the 'Lighthouse' phishing-as-a-service platform (the kit tied to this campaign) on 2025-11-12",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Consumer / General Public; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "FBI IC3 2024 Annual Report lists the toll-smishing category at 59,271 complaints and $129,624 in total reported losses for 2024. FBI Atlanta's Peach Pass-specific alert (2025-03-12) reported 1,720 complaints (Jan 1, 2024 - Feb 28, 2025), including 1,573 in March 2025 alone, and $3,643.42 in losses for that Georgia-specific surge. These are reported/complaint-based figures, likely undercounts of true losses since not all victims file IC3 complaints. Separately, Google's November 2025 civil complaint against the Lighthouse phishing-as-a-service platform (used in this and other campaigns, e.g. USPS smishing) alleges the kit compromised an estimated 12.7 million to 115 million payment cards in the U.S. alone between July 2023 and October 2024 across all Lighthouse-enabled scams (not toll-scam-specific), and affected over 1 million victims in 120+ countries; this figure is from Google's civil pleading, not an adjudicated finding.",
            "source_count": 17,
            "url": "https://socialengineeringexamples.com/toll-road-smishing-wave-2024-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "karen-mackie-solicitor-vishing-fraud-2015",
            "title": "NatWest “Vishing” Callback Fraud Costs Surrey Solicitor Karen Mackie £734,000 and Her Career",
            "victim": "Karen Frances Mackie, sole-practitioner solicitor trading as Karen Mackie Solicitor (incorporating Keeping and Co), and the client funds held in her firm's NatWest client account",
            "incident_date": "Scam calls occurred at the end of April 2015; publicly reported by BBC News on 2 October 2015 and BBC Radio 4's Money Box on 3 October 2015",
            "year": 2015,
            "country": "Unknown",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Financial Services & Insurance; Legal Services",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Karen Mackie transferred £734,000 of client money into criminal-controlled safe accounts. Mackie transferred £734,000 of client money into criminal-controlled \"safe\" accounts in tranches of up to £99,000 (widely rounded to \"£750,000\" in headlines, but body reporting consistently cites £734,000). After she grew suspicious and alerted police and NatWest, the bank recovered nearly £222,000 (reported elsewhere as \"just over £220,000\"); the remaining roughly £512,000 had already been withdrawn by the criminals and was not recovered. Her professional indemnity insurer refused to pay her claim, telling BBC Money Box she \"represents a risk to the public and cannot be trusted with holding client money.\" No source found indicates NatWest or anyone else reimbursed Mackie personally. Her clients' losses were ultimately made whole via the Solicitors Compensation Scheme, triggered by her SRA suspension, not by a direct bank reimbursement. Mackie was declared bankrupt and said she faced losing her home.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/karen-mackie-solicitor-vishing-fraud-2015",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "new-haven-public-schools-bec-2023",
            "title": "New Haven Public Schools $6M COO-email vendor thread-hijack BEC",
            "victim": "City of New Haven, New Haven Public Schools Board of Education, Connecticut (vendor First Student and law firm Shipman & Goodwin were impersonated)",
            "incident_date": "2023-05 to 2023-06 (attack), disclosed 2023-08-10",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Education; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 6000000,
            "loss_basis": "~$6M diverted (about $5.9M in four transfers intended for bus contractor First Student. Plus ~$76K in two payments meant for law firm Shipman & Goodwin); ~$3.6M recovered via bank ACH hold-harmless, plus ~$1.187M seized via federal civil forfeiture (about $4.7M-4.8M total recovered/expected); roughly $1.2M remained missing",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/new-haven-public-schools-bec-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "nj-life-insurance-beneficiary-pretexting-widows-2025",
            "title": "New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers",
            "victim": "At least 17 identified elderly victims (many over age 70) whose spouses or close family members had recently died, located in New Jersey, Maryland, and elsewhere; one documented example is a 73-year-old Maryland widow whose husband, a Maryland state employee, had died about two weeks before Crosby's calls.",
            "incident_date": "Fraud scheme: at least January 2020 to January 2021. SSA OIG/DOJ joint investigation opened: February 2021 (criminal complaint filed June 16, 2021). Guilty plea to wire fraud: November 16, 2023. Sentencing: July 2025 (24 months prison, 3 years supervised release, restitution ordered).",
            "year": 2020,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation; Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 100000,
            "loss_basis": "At least 17 elderly victims paid over $100,000 combined via reloadable prepaid cards. Crosby caused at least 17 elderly victims to pay her over $100,000 combined via reloadable prepaid cards; DOJ's plea release states she received $110,380 into her bank account between January and December 2020 from the scheme. At sentencing (per SSA OIG Fall 2025 Semiannual Report to Congress) she was ordered to pay $106,639 in restitution to the fraud victims, plus separate restitution tied to her concealment of that income while receiving benefits: $9,057 to HUD, $86,689 to the New Jersey Division of Revenue, and $13,020 to SSA. One documented single-victim example: a 73-year-old Maryland widow was told she owed $3,498 in \"arrears\" on her late husband's life insurance policy, then talked into providing an additional $6,496 in reloadable card codes the next day after a purported \"supervisor\" call corrected the amount upward.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/nj-life-insurance-beneficiary-pretexting-widows-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "nirmala-sitharaman-deepfake-investment-scam-bengaluru-2026",
            "title": "Nirmala Sitharaman Deepfake Investment Scam (Bengaluru, 2026)",
            "victim": "Unnamed 66-year-old retiree, resident of Narayanapura, Bengaluru (individual financial victim); Union Finance Minister Nirmala Sitharaman impersonated via deepfake video; State Bank of India (SBI) name and brand misused without involvement",
            "incident_date": "2026-07 (reported); fraud occurred March-June 2026",
            "year": 2026,
            "country": "India",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Consumer / General Public; Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 8000,
            "loss_basis": "Approximately Rs 6.88 lakh (about $8,000 to $8,300) transferred by the victim in multiple installments. Approximately Rs 6.88 lakh (roughly INR 688,000, about USD 8,000-8,300) transferred by the individual victim in multiple installments between March and June 2026; some headlines round this to Rs 6.8 lakh. No recovery reported at time of coverage.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/nirmala-sitharaman-deepfake-investment-scam-bengaluru-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "contagious-interview-clickfake-crypto-2025",
            "title": "North Korea’s ‘Contagious Interview’ ClickFix Fake Job-Assessment Campaign Targets Crypto Industry (2025)",
            "victim": "Job applicants to cryptocurrency and tech companies worldwide; the fake interview sites impersonated real crypto brands including Coinbase, KuCoin, Kraken, Circle, Securitize, BlockFi, Tether, Bybit, Robinhood, and Archblock, with later reporting also naming Ripple, Chainalysis, and eToro among impersonated brands",
            "incident_date": "2025 (Sekoia identified the 'ClickFake Interview' branch in February 2025, notified customers March 21, 2025, and published its report March 31, 2025; it is a continuation of the broader 'Contagious Interview' campaign that Unit 42 first documented in November 2023 as active since at least December 2022)",
            "year": 2025,
            "country": "Unknown",
            "attack_channels": "ClickFix & SEO Poisoning",
            "sectors": "Cryptocurrency & Digital Assets; Financial Services & Insurance; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No verified campaign-wide dollar loss figure exists in public reporting. Silent Push documented one confirmed victim whose MetaMask wallet was compromised after running the malicious code, but the victim said losses were minor and no amount was disclosed. (Note: some secondary coverage mentions the unrelated $1.5 billion Bybit theft in the same general DPRK-crypto-crime context; that is a separate incident and not a loss figure for this campaign.)",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/contagious-interview-clickfake-crypto-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "nts-it-care-tech-support-scam-2020",
            "title": "NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam",
            "victim": "U.S. consumers, particularly older Americans and people unfamiliar with computer security, who encountered the fake pop-up while browsing",
            "incident_date": "Scheme operated from at least 2014 (per DOJ, conspiracy dated \"on or about March 2014\" through the present) and prior to 2020; FTC civil complaint filed under seal May 19, 2020; parallel DOJ criminal information against Jagmeet Singh Virk filed July 22, 2020, with a guilty plea entered May 14, 2020; stipulated FTC final order entered under seal December 4, 2020; Virk sentenced May 11, 2023 (self-surrender to BOP June 26, 2023); FTC case unsealed and refunds announced November 7, 2023.",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Retail & E-commerce; Technology & Software",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Civil: $4.9 million equitable monetary judgment entered jointly and severally against NTS IT Care. Inc. and Jagmeet Singh Virk (largely suspended based on documented inability to pay, with Virk required to pay $14,857 from escrow within 7 days; the full $4.9M becomes collectible if the underlying financial disclosures are later found false). In November 2023 the FTC mailed 272 refund checks totaling $255,046 (average ~$937.67, rounded by the FTC to $937) to consumers who lost money to the scheme; as of March 31, 2024, 226 of those checks (83.09%) had been cashed. Individual consumer losses in the underlying scam reportedly ran $99.99 to $499.99 per bogus multi-year tech-support package, with the FTC's complaint estimating Defendants took approximately $5 million from consumers since 2016 alone. Criminal: Jagmeet Singh Virk was separately prosecuted by DOJ and, per the criminal information's forfeiture allegation (18 U.S.C. §981(a)(1)(C) and 28 U.S.C. §2461(c)), was subject to forfeiture of a sum equal to the wire-fraud proceeds he obtained, in addition to a $250,000 statutory maximum fine exposure under 18 U.S.C. §1349 (actual fine/restitution amount as imposed at sentencing not independently detailed in public DOJ summary reviewed).",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/nts-it-care-tech-support-scam-2020",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "nz-bank-impersonation-spoofed-callback-vishing-2024",
            "title": "NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case",
            "victim": "\"Greer\" (pseudonym used in the published case note), a customer of an unnamed New Zealand retail bank; her husband \"Anton\" is also referenced",
            "incident_date": "December 2024 (Ombudsman case note published; underlying scam call occurred shortly before; RNZ reported it 12 January 2025)",
            "year": 2024,
            "country": "New Zealand",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 15000,
            "loss_basis": "NZD 30,000 stolen (used to buy goods at an Auckland merchant via the victim's credit card account); a second, larger fraudulent payment was blocked by the bank's security system. The bank initially offered to reimburse only half ($15,000); the Banking Ombudsman Scheme recommended full reimbursement of the $30,000 loss plus an additional NZD 1,000 for delays in handling the fraud case (total ~NZD 31,000 recommended).",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/nz-bank-impersonation-spoofed-callback-vishing-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "dprk-it-worker-front-company-ofac-sanctions-2025",
            "title": "OFAC Sanctions DPRK Ministry of National Defense Front Companies Behind Fake-Persona Remote IT-Worker Fraud",
            "victim": "Global employers (unspecified in Treasury designations); at least 309 U.S. companies plus 2 international businesses identified in the related DOJ Chapman case",
            "incident_date": "January 16, 2025 (OFAC designation of Department 53/Osong/Chonsurim network); July 23-24, 2025 (FBI PSA, OFAC designation of Sobaeksu network, and Christina Chapman sentencing)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media",
            "sectors": "Cross-Sector / Multiple Industries; Defense & Aerospace; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 17000000,
            "loss_basis": "The Christina Chapman-facilitated scheme alone generated more than $17 million in illicit revenue. DOJ: the Christina Chapman-facilitated scheme alone generated more than $17 million in illicit revenue by placing DPRK IT workers at 309 U.S. companies and 2 international businesses using 68 stolen identities. Treasury estimates the broader DPRK overseas IT-worker program generates annual revenues of hundreds of millions of dollars for the regime's weapons programs (regime withholds up to 90% of workers' wages); this broader figure is a Treasury estimate, not an audited total tied to the specific January/July 2025 sanctioned network. The U.S. State Department separately offered rewards up to $3 million for information on two individuals (Kim Se Un, Myong Chol Min) tied to the July 2025 Sobaeksu designation.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/dprk-it-worker-front-company-ofac-sanctions-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "okunnu-bec-money-mule-ring-2021-2022",
            "title": "Okunnu BEC / Money-Mule Ring – Invoice-Redirect Fraud Across Five Companies and One NJ Township",
            "victim": "Six named-by-code victims per the superseding indictment: \"Victim VP\" (nutrition-products manufacturer, offices outside Texas), \"Victim MM\" (healthcare liability insurance company headquartered in Georgia), \"Victim BAD\" (Texas demolition-services company), \"Victim Township\" (a New Jersey township, widely reported as Edison Township), and \"Victim BEG\" (Oregon financial services company)",
            "incident_date": "2021-06-04 to 2022-02-03 (fraudulent wires); indictment filed 2023-05-18, superseding indictment 2024-10-02, pleas Jan-Sept 2025, sentencing 2026-02-09",
            "year": 2021,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Financial Services & Insurance; Government & Public Sector; Manufacturing & Industrial",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 2530000,
            "loss_basis": "At least six confirmed fraudulent wire transfers totaled roughly $2.53 million. At least six confirmed fraudulent wire transfers detailed in the superseding indictment: $531,319.60 (2021-06-04) and $554,246 (2021-07-02) from Victim VP (nutrition-products manufacturer); $400,000 (2021-06-07) from Victim MM (healthcare liability insurer); $340,500 (2021-08-24) from Victim BAD (Texas demolition company); $287,236.14 (2021-11-23) from Victim Township (New Jersey township, widely reported as Edison Township); $421,488.10 (2022-02-03) from Victim BEG (Oregon financial services company). That subset alone totals roughly $2.53 million; DOJ/IRS describe a broader nationwide BEC scheme (45+ people charged across multiple states, 9 in S.D. Texas) with restitution ordered against just two defendants at sentencing: Bolaji Okunnu ordered to pay $255,399.47 and Amber Bush ordered to pay $1,189,247.02 in restitution \"to victims nationwide.\"",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/okunnu-bec-money-mule-ring-2021-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "openai-scopecreep-crosshair-x-trojan-2025",
            "title": "OpenAI’s “ScopeCreep”: Russian-Speaking Actor Used Disposable ChatGPT Accounts to Build C2-Enabled Windows Malware Distributed via a Trojanized “Crosshair-X” Gaming Tool",
            "victim": "No named corporate, government, or individual victim was disclosed. The apparent targets were gamers/PC users who downloaded a public-repository tool impersonating the legitimate \"Crosshair-X\" crosshair/overlay utility; OpenAI treats this as a supply-chain-style malware distribution campaign rather than a targeted attack on a specific organization.",
            "incident_date": "Disclosed by OpenAI on 2025-06-05 (blog) / report PDF dated 2025-06 (metadata 2025-06-01), as part of the quarterly \"Disrupting malicious uses of AI\" report. The underlying ScopeCreep malware-development and C2 activity predates the disclosure; OpenAI does not give exact intrusion or campaign-start dates, only that it appeared to be caught in an early stage.",
            "year": 2025,
            "country": "Russia",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Consumer / General Public; Technology & Software",
            "threat_actors": "",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None disclosed. Neither OpenAI's report nor secondary coverage (The Record, GovInfoSecurity, Security Affairs) cites a dollar figure for losses, ransom, theft proceeds, or remediation cost. OpenAI frames the case as caught early with no confirmed evidence of widespread victimization.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/openai-scopecreep-crosshair-x-trojan-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "openai-rogue-agent-breach-huggingface-2026",
            "title": "OpenAI’s Rogue Benchmark Agents Breach Hugging Face to Cheat an Internal Cyber-Capability Test (2026)",
            "victim": "Hugging Face, Inc. (AI model, dataset, and Spaces hosting platform), with OpenAI as the originating party whose autonomous agents carried out the intrusion against Hugging Face's production infrastructure",
            "incident_date": "Hugging Face's own forensic timeline places the campaign from 2026-07-09 (02:28 UTC, establishing an external launchpad) through 2026-07-13 (14:14 UTC), with lateral movement into Hugging Face's own clusters concentrated around the weekend of 2026-07-11 to 2026-07-13; Hugging Face publicly disclosed the breach on 2026-07-16; OpenAI publicly attributed the incident to its own models on 2026-07-21, with a follow-up update on 2026-07-28",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Technology & Software",
            "threat_actors": "Autonomous AI System",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar figure, ransom, extortion demand, or loss estimate was disclosed by either OpenAI or Hugging Face, nor reported by BBC, NBC News, Computer Weekly, or The Register. Hugging Face said it was still assessing whether partner/customer data was affected and would notify any affected parties, but no financial impact figure has been made public.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/openai-rogue-agent-breach-huggingface-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "operation-aurora-google-adobe-2009-2010",
            "title": "Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms",
            "victim": "Google Inc.; Adobe Systems; and 20+ (publicly estimated as many as 34, possibly over 100) other US technology, defense, finance, media, and chemical companies, including confirmed targets Juniper Networks, Rackspace, and Akamai Technologies, plus media-reported targets Yahoo, Symantec, Northrop Grumman, Morgan Stanley, and Dow Chemical",
            "incident_date": "2009-12 (mid-December 2009 intrusion, per Google) to 2010-01-12 (public disclosure); Microsoft patch MS10-002 issued 2010-01-21",
            "year": 2009,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Defense & Aerospace; Financial Services & Insurance; Manufacturing & Industrial; Media & Entertainment; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar loss figure was disclosed by Google, Adobe, or any other confirmed victim in primary filings. Google's SEC Form 8-K (filed 2010-01-13, Exhibit 99.1) and blog post describe theft of intellectual property (source code) and reputational/strategic fallout (the decision to stop censoring Google.cn and review China operations) but state no quantified financial loss. Adobe said it found no evidence customer, financial, or employee data was compromised. Industry estimates of aggregate damage across the 20-34+ targeted firms were never officially quantified.",
            "source_count": 10,
            "url": "https://socialengineeringexamples.com/operation-aurora-google-adobe-2009-2010",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "buckshot-yankee-pentagon-usb-worm-2008",
            "title": "Operation Buckshot Yankee: Infected USB Flash Drive Breaches U.S. Central Command Networks",
            "victim": "U.S. Department of Defense, U.S. Central Command (CENTCOM) classified and unclassified networks, including SIPRNet",
            "incident_date": "2008 (infection first observed on non-U.S. systems June 2008; NSA discovered it on SIPRNet October 2008; publicly disclosed by DoD September 1, 2010)",
            "year": 2008,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Government & Public Sector",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 155000000,
            "loss_basis": "No authoritative public dollar figure exists for the Buckshot Yankee remediation itself. Reporting establishes only that cleanup took roughly 14 months and involved retrieving thousands of thumb drives, isolating and reformatting infected computers, and \"a lot of time, energy, and money\" per Deputy Secretary Lynn, without a published total. (Separately, U.S. Cyber Command's own stand-up budget was reported around $155 million with ~750 staff by late 2010, but that is the new command's budget, not a cleanup cost, and should not be conflated with incident losses.)",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/buckshot-yankee-pentagon-usb-worm-2008",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "optus-tpg-otp-interception-vishing-2024",
            "title": "Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)",
            "victim": "More than 100 Australian mobile customers of Optus and TPG Telecom, defrauded of high-end mobile devices via their own carrier accounts.",
            "incident_date": "Mar 2023 (investigation opened) to 27 Nov 2024 (arrest); charged 28 Nov 2024; bail refused 2 Dec 2024; next court date 29 Jan 2025 (case status: on remand, allegations not yet tried at time of research)",
            "year": 2023,
            "country": "United Kingdom",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Telecommunications",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "More than AUD $1,000,000 in cash found hidden in suitcases and Louis Vuitton bags at the offender's Auburn home, seized by AFP during the 27 Nov 2024 search. The AFP media release states this same search also recovered over 500 SIM cards and 21 electronic devices (laptops, phones) containing credit cards and financial documents; separately, the AAP court report of the 2 Dec 2024 bail hearing states the November search additionally turned up nine more mobile phones and 300 SIM cards (on top of 111 unauthorized credit reports found on a phone seized in August 2024). These two sets of figures are not clearly reconciled in the sources reviewed; they may describe the same search reported inconsistently by AFP comms versus the Crown prosecutor in court, rather than strictly additive totals. He was separately charged with dealing in proceeds of crime valued at $1,000,000+ under s400.3(1) of the Criminal Code. No aggregate victim-loss total (retail value of the \"hundreds\" of fraudulently obtained high-end mobile devices) was disclosed by AFP; ScamWatch data cited in the same release recorded ~34,000 phone-scam reports and ~$71 million in total 2024 losses to the Australian economy (not specific to this case).",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/optus-tpg-otp-interception-vishing-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "orion-sa-60m-bec-wire-fraud-2024",
            "title": "Orion S.A. $60M fraudulently induced wire transfers (2024)",
            "victim": "Orion S.A. (NYSE: OEC), a specialty chemicals company (carbon black producer), incorporated in Luxembourg with principal US offices in Spring, Texas.",
            "incident_date": "2024-08-10",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 60000000,
            "loss_basis": "Approximately $60 million in unrecovered fraudulent wire transfers; total losses plus related third-party investigation professional fees aggregated to $60.7 million (Q3 2024). Net loss impact of $42.5 million net of income tax benefit; Orion reported a Q3 2024 net loss of $20.2M versus $26.2M net income a year earlier.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/orion-sa-60m-bec-wire-fraud-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "orlando-parkmobile-qr-parking-meter-sticker-scam-2025",
            "title": "Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)",
            "victim": "City of Orlando parking division / drivers parking in downtown Orlando",
            "incident_date": "2025-06-02",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "Consumer / General Public; Government & Public Sector; Transportation & Logistics",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar loss figure was ever published. FOX 35 explicitly reported that as of its story, \"officials have not specified the total number of victims or the financial impact to date\" and that no suspects or arrests had been confirmed. No follow-up reporting with a final tally was found.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/orlando-parkmobile-qr-parking-meter-sticker-scam-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "procter-gamble-unilever-dumpster-diving-2001",
            "title": "P&G’s ‘Bad Hair Day’: Dumpster-Diving Corporate Espionage on Unilever’s Hair-Care Business",
            "victim": "Unilever (specifically its U.S. hair-care business, brands including Organics, Sunsilk, and ThermaSilk)",
            "incident_date": "Operation ran fall 2000 to spring 2001; P&G leadership discovered/self-disclosed to Unilever in April 2001; settlement publicly announced September 6, 2001",
            "year": 2000,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Consumer / General Public; Retail & E-commerce",
            "threat_actors": "Corporate / Competitive Intelligence",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar figure was ever officially confirmed by either company; terms of the September 6, 2001 settlement were explicitly not disclosed. Contemporaneous business press (New York Times, UPI, BBC) reported P&G agreed to pay Unilever approximately $10 million and to submit to a third-party/independent audit verifying the obtained intelligence was not used in P&G's hair-care business plans. Treat the $10M figure as press-reported, not primary-source-confirmed. Non-monetary costs: ~80 confidential Unilever documents returned/quarantined, three P&G employees terminated, reputational damage to P&G covered nationally (WSJ, Fortune, NYT, BBC, CNN).",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/procter-gamble-unilever-dumpster-diving-2001",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "pathe-fake-ceo-bec-2018",
            "title": "Pathé €19.2M fake-CEO cinema-chain fraud (2018)",
            "victim": "Pathé Theatres B.V. (Pathé Nederland), the Dutch subsidiary of French film group Pathé; ~1,900 employees, €209M 2017 revenue. Two executives, managing director/CEO Dertje Meijer and financial director/CFO Edwin Slutter, were suspended and fired.",
            "incident_date": "2018-03 (fraud executed March 8-27, 2018; disclosed via Amsterdam District Court ruling dated 2018-10-31, reported November 2018)",
            "year": 2018,
            "country": "France",
            "attack_channels": "Phishing",
            "sectors": "Media & Entertainment",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 21500000,
            "loss_basis": "€19,244,304 transferred in four-plus tranches (approx. US$21.5M), roughly 10% of the Dutch unit's annual revenue. No public confirmation any funds were recovered.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/pathe-fake-ceo-bec-2018",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "pge-barcode-qr-utility-shutoff-scam-2026",
            "title": "PG&E Utility Shutoff Barcode/QR Payment Scam",
            "victim": "PG&E customers, California (individuals and small/medium businesses)",
            "incident_date": "2025-2026 (ongoing; PG&E quantified losses through mid-2026 in a June 15, 2026 press release, updated July 2, 2026)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Critical Infrastructure, Energy & Utilities; Cross-Sector / Multiple Industries",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "PG&E customers lost over $211,000 to this and related utility-impersonation scams through mid-2026. PG&E reported customers lost over $211,000 to this and related utility-impersonation scams through mid-2026 (average loss $969/victim in H1 2026), on pace to exceed 2025's total of over $301,000 (average loss $590/victim, ~24,000 scam reports in 2025). Business customers were also targeted: 656 scam reports against businesses in the first half of 2026 vs. 846 for all of 2025. Regionally, Sonoma County reported 144 targeted customers and Napa County 21 in H1 2026. These are company-reported, self-disclosed figures (not independently audited or tied to a single adjudicated criminal case), and PG&E states the true total is likely higher since many incidents go unreported.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/pge-barcode-qr-utility-shutoff-scam-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "phantom-hacker-scam-milan-jackson-bank-of-america-2024",
            "title": "Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025)",
            "victim": "Milan Jackson, Chicago hairstylist",
            "incident_date": "2024 (exact date not publicly specified; reported by ABC7 Chicago on 2025-01-16)",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 20000,
            "loss_basis": "$20,000 wired by the victim to an account controlled by scammers. Publicly reported as not recovered (Bank of America told ABC7 it might attempt recovery but could not guarantee it once the client had authorized the transfer).",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/phantom-hacker-scam-milan-jackson-bank-of-america-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "pine-bluff-school-district-vendor-bec-2025",
            "title": "Pine Bluff School District $3.2M Construction-Payment BEC (Thread-Hijack via Lookalike Vendor Domain)",
            "victim": "Pine Bluff School District (Pine Bluff, Arkansas); its contractor East Harding Construction Co. and architect Lewis Architects Engineers had accounts/threads abused but East Harding stated its own systems were not breached.",
            "incident_date": "2025-12-17",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Education",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 3204639,
            "loss_basis": "$3,204,639.55 wired to fraudulent accounts on Dec. 17, 2025; approximately $1,120,051.51 recovered as of April 30, 2026 (net loss ~$2.08M). District filed a claim with the Arkansas Cyber Response Board (self-funded state program); the district said it does not carry separate cyber insurance.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/pine-bluff-school-district-vendor-bec-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "pivotal-labs-w2-ceo-phish-2016",
            "title": "Pivotal Labs W-2 Phishing (CEO-Spoof), 2016",
            "victim": "Pivotal Software, Inc. (Pivotal Labs), a software firm then jointly held by EMC and VMware, and its U.S. employees whose W-2 data was exposed.",
            "incident_date": "2016-03-22",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No direct wire-transfer loss; this was a data-disclosure incident, not a payment fraud. Number of affected employees was not disclosed (Pivotal had fewer than ~2,000 employees). Costs included three years of AllClear ID identity-protection services for affected staff plus incident response; downstream tax-refund fraud exposure for individuals was not quantified.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/pivotal-labs-w2-ceo-phish-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "promptlock-ai-ransomware-poc-2025",
            "title": "PromptLock: AI-Generated Ransomware Proof-of-Concept Discovered on VirusTotal",
            "victim": "None confirmed. No real organization or individual is known to have been attacked; the sample was a proof-of-concept found on the VirusTotal malware-analysis platform.",
            "incident_date": "Sample first identified by ESET on VirusTotal on/around August 25, 2025; ESET public disclosure August 27, 2025 (Bratislava press release and WeLiveSecurity writeup); ESET update confirming academic origin on September 3, 2025",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "",
            "threat_actors": "Authorized Tester or Researcher",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None confirmed. No ransom was paid and no real victim has come forward; the ransom note embedded in the sample references a Bitcoin address purportedly associated with Bitcoin creator Satoshi Nakamoto, which researchers read as a placeholder/demonstration detail rather than a functioning extortion demand.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/promptlock-ai-ransomware-poc-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "promptsteal-lamehug-apt28-ukraine-2025",
            "title": "PROMPTSTEAL/LAMEHUG: APT28’s LLM-Powered Malware Against Ukraine",
            "victim": "Ukrainian executive authorities, government officials, and security/defense-sector organizations",
            "incident_date": "2025-06 (first observed by GTIG in live operations); CERT-UA received incident reports 2025-07-10; CERT-UA advisory published 2025-07-17/28; GTIG report published 2025-11-05",
            "year": 2025,
            "country": "Ukraine",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); Phishing",
            "sectors": "Defense & Aerospace; Government & Public Sector",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No monetary loss has been publicly quantified. Public reporting (Google GTIG, CERT-UA, Cato Networks, Splunk) describes an espionage/data-theft operation without confirming successful large-scale exfiltration or measurable financial damage; CERT-UA did not publicly confirm whether the LLM-generated commands executed successfully in every observed case.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/promptsteal-lamehug-apt28-ukraine-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "pridco-bank-change-phishing-bec-2020",
            "title": "Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)",
            "victim": "Puerto Rico Industrial Development Company (PRIDCO), a government-owned corporation",
            "incident_date": "2020-01-17",
            "year": 2020,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 2600000,
            "loss_basis": "$2.6M wired by PRIDCO on Jan 17, 2020 (public pension remittance funds), the largest single loss in a broader scam that attempted more than $4M across Puerto Rico agencies. The Puerto Rico Tourism Company separately wired $1.5M in January. A $63,000 December payment is attributed inconsistently by AP: one AP article (citing police fraud-unit director Jose Ayala) attributes it to PRIDCO, while another AP article (citing PRIDCO's Manuel Laboy) attributes it to the Commerce and Export Company; sources conflict, so it is not confirmed to be PRIDCO's. Authorities reportedly froze at least $2.9M. Net unrecovered loss not publicly confirmed.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/pridco-bank-change-phishing-bec-2020",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "pune-teams-boss-scam-cfo-2026",
            "title": "Pune Italian Engineering Firm CFO Microsoft Teams Boss-Scam (Rs 56 Lakh Loss, 2026)",
            "victim": "CFO (49, female) of the Pune office/subsidiary of an Italy-headquartered engineering company (company name not publicly disclosed in reporting)",
            "incident_date": "2026-07-13",
            "year": 2026,
            "country": "India",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Financial Services & Insurance; Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Approximately Rs 56 lakh (roughly USD 65,000-67,000 at mid-2026 exchange rates) transferred and lost across two bank accounts on the first fraudulent instruction. A second demand for Rs 1.5 crore (~USD 175,000-180,000) the following morning was not paid because the CFO grew suspicious and verified with the real CEO first; total attempted exposure across both asks was roughly Rs 2.06 crore (~USD 240,000), of which only the initial Rs 56 lakh was actually lost.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/pune-teams-boss-scam-cfo-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "quebec-ai-grandparent-vishing-teodor-condurache-saskatchewan-2025",
            "title": "Quebec AI-Assisted “Grandparent Scam” Ring: Teodor/Condurache Sentenced After Targeting Saskatchewan Seniors",
            "victim": "Multiple seniors in Saskatoon, Regina, and the White Butte area, Saskatchewan, including named victims Jill Finn (79) and her husband Ian Finn (78) of Regina, plus at least ten other victim households across the two cities (five in Saskatoon, five in Regina, one in White Butte) in late November-early December 2025",
            "incident_date": "Scam calls and losses: November 24 - December 2, 2025 (Saskatoon reports Nov. 24-27; Regina/White Butte reports Dec. 1-2). Arrests: December 2, 2025. First court appearance: December 3, 2025. Sentencing: July 9, 2026, Regina Provincial Court.",
            "year": 2025,
            "country": "Canada",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 46350,
            "loss_basis": "Restitution ordered at sentencing totaled $46,350 for the Saskatchewan offences. Restitution ordered at sentencing: $46,350 total for the Saskatchewan offences (Teodor solely responsible for $28,100; Teodor and Condurache jointly responsible for a further $18,250), described by the Crown as the amount never recovered by victims. Separately reported raw loss figures: Saskatoon victims (5 reports, Nov. 24-27, 2025) lost a total of more than $45,000, with individual losses of roughly $5,000-$26,000; Regina/White Butte victims (Dec. 1-2, 2025) lost in excess of $40,000, of which about $20,000 was later recovered by police. One couple alone lost over $25,000 through multiple payments (first handed to a courier in person, then sent via Purolator). Most other individual instances involved losses under $10,000. Teodor's overall 18-month sentence also incorporated a separate Quebec bank-card-retrieval fraud operation (200+ victims, over $1 million in total losses) in which he played a limited role as a driver in five card pickups; six months of his sentence was attributed to that role.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/quebec-ai-grandparent-vishing-teodor-condurache-saskatchewan-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "rapid7-blank-badge-pentest-2018",
            "title": "Rapid7 ‘Blank Badge’ Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext",
            "victim": "Unnamed enterprise client of Rapid7, referred to in the published account only as a \"client partner\"; company name, sector, and city are not disclosed",
            "incident_date": "2018-10-02 (blog publication date); the physical assessment itself occurred at an unspecified earlier date in 2018, with a follow-up internal network penetration test roughly seven months later at the same client site",
            "year": 2018,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "",
            "threat_actors": "Authorized Tester or Researcher",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None disclosed / not applicable. This was a contracted, authorized penetration-testing engagement for a paying Rapid7 client; no financial loss, theft, or breach cost is reported. The value at stake was security-control validation, not money.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/rapid7-blank-badge-pentest-2018",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "red-wheeling-bec-solar-panel-vendor-fraud-2024",
            "title": "RED (Regional Economic Development Partnership) Wheeling, WV – BEC Solar-Panel Vendor Invoice Fraud",
            "victim": "Ohio Valley Industrial & Business Development Corporation, doing business as Regional Economic Development Partnership (RED), a private nonprofit economic development corporation based in Wheeling, West Virginia",
            "incident_date": "October 2024 (fraudulent payment occurred); guilty plea entered/announced July 14-15, 2026; sentencing pending as of research date",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Critical Infrastructure, Energy & Utilities; Government & Public Sector; Nonprofit & NGO",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 30750,
            "loss_basis": "$30,750 paid directly on the fraudulent invoice, part of roughly $220,000 in total loss. $30,750 paid directly on the fraudulent solar-panel-installation invoice request; approximately $220,000 in total actual/intended loss once investigators traced Pierce's broader fraudulent activity (figures per DOJ-sourced reporting, not independently itemized in available sources)",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/red-wheeling-bec-solar-panel-vendor-fraud-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "retool-smishing-vishing-deepfake-2023",
            "title": "Retool smishing + deepfake vishing breach (2023)",
            "victim": "Retool, Inc. (San Francisco-based developer/internal-tools platform); 27 of its cloud customers, all cryptocurrency firms. The largest identified downstream victim was Fortress Trust (a Nevada crypto custody/trust company), whose customers lost roughly $15M in cryptocurrency.",
            "incident_date": "2023-08",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Phishing; Smishing (SMS Phishing); Vishing (Voice Phishing)",
            "sectors": "Cryptocurrency & Digital Assets; Financial Services & Insurance; Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 15000000,
            "loss_basis": "~$15M USD in cryptocurrency stolen from Fortress Trust customers (reported by CoinDesk/Fortune, range cited $12M-$15M). Retool reverted the 27 account takeovers; affected Fortress Trust customers were made whole primarily from Fortress's own balance sheet, with a $15M down payment from Ripple during acquisition talks. Ripple ultimately canceled the outright Fortress Trust acquisition on September 28, 2023, while remaining an investor in Fortress.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/retool-smishing-vishing-deepfake-2023",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "rite-aid-dumpster-diving-2010",
            "title": "Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records",
            "victim": "Rite Aid Corporation (and, downstream, the patients and employees whose prescription, personal, and application records were exposed to the public)",
            "incident_date": "Conduct discovered/reported 2006-2008 (originating with WTHR's 2006 Indianapolis investigation and continuing media exposes through 2007-2008); joint FTC/HHS settlement announced July 27, 2010; FTC final order issued November 12, 2010, approved November 22, 2010",
            "year": 2006,
            "country": "United States",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Healthcare; Retail & E-commerce",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 1000000,
            "loss_basis": "$1,000,000 paid by Rite Aid Corporation to HHS/OCR under the HIPAA resolution agreement (July 27, 2010). The FTC consent order imposed no separate civil monetary penalty but required a 20-year compliance program with independent biennial third-party security assessments (through at least November 12, 2030), a substantial ongoing compliance cost not separately quantified in public filings.",
            "source_count": 13,
            "url": "https://socialengineeringexamples.com/rite-aid-dumpster-diving-2010",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "robertson-smith-kempson-refuse-sack-data-exposure-2014",
            "title": "Robertson, Smith & Kempson Estate Agent Refuse Sack Data Exposure (2013-2014)",
            "victim": "Robertson, Smith & Kempson (RSK), a trading brand of Thamesview Estate Agents Ltd (the data controller that signed the 2014 undertaking, Companies House no. 04160511) - customers of the branch involved (specific branch not identified in ICO records; RSK's documented offices are in Acton, Ealing, Hanwell and Northfields, West London). No primary source supports the previously stated claim that the company was \"part of the LSL Property Services / LSL Estate Agency group\" - that claim is unsupported and has been removed. Per Companies House, company no. 04160511 - which traded as \"Thamesview Estate Agents Limited\" from 2003 until it was renamed \"Dexters London Limited\" on 19 May 2016 - is the entity that signed the 2014 undertaking. A separate, dormant company also named \"Thamesview Estate Agents Limited\" (no. 10195598, registered office 3 Park Road, Teddington - the address on the undertaking) was incorporated days later, on 24 May 2016, and is now 75%+ owned by Dexters London Limited. This indicates a corporate/naming link to Dexters that dates from 2016, after the incident, and should not be read as confirming Dexters (or any other parent) owned or controlled the business in 2013-14.",
            "incident_date": "2013-12-11 (first report to ICO); 12 Mar 2014 (repeat incident observed, per ICO undertaking); 13 Mar 2014 (repeat incident reported to ICO, per ICO press release); 11 Aug 2014 (ICO undertaking signed)",
            "year": 2013,
            "country": "United Kingdom",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Real Estate",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No fine or monetary penalty was imposed; the ICO resolved the matter via an undertaking in lieu of exercising its power to serve. Enforcement Notice under section 40 of the Data Protection Act 1998. No financial loss to customers was confirmed in the primary sources (the concern was elevated identity-fraud risk, not a realized loss).",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/robertson-smith-kempson-refuse-sack-data-exposure-2014",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "roger-roger-costa-rica-sweepstakes-scheme-2024",
            "title": "Roger Roger’s Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+",
            "victim": "Hundreds of U.S. victims, predominantly elderly (at least 10 confirmed victims over age 55, per jury finding)",
            "incident_date": "Scheme active January 2014 to November 2017 per the indictment; sealed indictment filed Sept. 19, 2018 and unsealed Oct. 2, 2018; trial conviction Sept. 20, 2024; sentencing July 15, 2025",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Professional & Business Services",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Over $4 million stolen from hundreds of victims (per trial evidence). Roger ordered at sentencing to pay more than $3.3 million in restitution and to forfeit more than $4.2 million.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/roger-roger-costa-rica-sweepstakes-scheme-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "rsa-securid-spearphish-2011",
            "title": "RSA SecurID Breach: The “2011 Recruitment Plan” Spear-Phishing Email (2011)",
            "victim": "RSA Security (RSA, the Security Division of EMC Corporation), maker of the SecurID two-factor authentication tokens; downstream victim Lockheed Martin, with Northrop Grumman and L-3 Communications alleged but unconfirmed.",
            "incident_date": "2011-03",
            "year": 2011,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Defense & Aerospace; Technology & Software",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 66000000,
            "loss_basis": "$66M USD (EMC's disclosed Q2 2011 remediation cost: token replacement, transaction monitoring, and investigation; excludes Q1 costs and downstream victim losses)",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/rsa-securid-spearphish-2011",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "sabric-vishing-sim-swap-banking-fraud-surge-2023-2025",
            "title": "SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)",
            "victim": "Customers of South Africa's major retail banks, collectively Absa, First National Bank (FNB), Nedbank, and Standard Bank, plus other SABRIC member banks, targeted individually at scale rather than the banks' own IT infrastructure being breached.",
            "incident_date": "2023-01-01 to 2025 (ongoing); SABRIC 2023 Annual Crime Statistics report published Oct 2024; Standard Bank vishing warning/app feature launched 6 Aug 2024; SABRIC 2024 Annual Crime Statistics published 28 Aug 2025; individual bank vishing/SIM-swap alerts continued through Nov 2025 and into 2026",
            "year": 2023,
            "country": "South Africa",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "South African digital banking fraud rose from R1.08 billion in 2023 to R1.89 billion in 2024, per SABRIC. Per SABRIC's own primary Annual Crime Statistics reports: in 2023, digital banking fraud totalled R1,082,393,109 in gross losses across 52,584 incidents (+45% incidents / +47% losses vs. 2022); within that, banking-app fraud specifically was R625,712,552 across 31,612 incidents (60% of digital banking crime, +74% YoY); this is the \"R625m\" figure referenced in the case brief. In 2024 (per the SABRIC report published 28 Aug 2025), digital banking fraud rose to R1.888 billion across 97,975 incidents (+86% incidents / +74% losses vs. 2023); banking apps accounted for 65.3% of incidents. Confusingly, SABRIC's headline TOTAL financial-crime figure (which includes non-digital categories like cash-in-transit and branch robbery, where losses fell sharply) actually dropped from R3.3bn (2023) to R2.7bn (2024) even as digital/vishing-driven fraud kept climbing; both figures are real but describe different scopes, and press coverage sometimes conflates them. The R1.9bn figure in the case brief matches the confirmed 2024 digital banking fraud total. The claimed \"R3.9 billion banking fraud in 2025\" figure in the case brief could NOT be verified: SABRIC's own published Annual Crime Statistics report set (as listed on sabric.co.za/resources) runs only through the 2024 report (published Aug 2025); a 2025 annual report, following SABRIC's own ~8-9 month publication lag, would not be expected until roughly Aug-Sept 2026. The R3.9bn/\"+23%\" figure appears only in a handful of lower-tier or unverified outlets (e.g., an EBNewsDaily.co.za piece dated April 2026 and a LinkedIn post citing it) with no primary SABRIC report, media statement, or bank disclosure behind it, and R3.9bn also independently appears in the same period attached to an unrelated South African story (government \"ghost employee\" payroll fraud), raising the possibility of a garbled/misattributed statistic circulating online rather than a genuine, sourced SABRIC figure. This specific 2025 figure and the \"rare joint public alert\" issued jointly by all four major banks together (as opposed to each bank issuing its own separate, frequent vishing/SIM-swap warnings, which is well documented) should be treated as unconfirmed pending a genuine SABRIC 2025 report or a verifiable joint press release.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/sabric-vishing-sim-swap-banking-fraud-surge-2023-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "san-diego-scam-compound-takedown-ko-thet-sanduo-giant-2026",
            "title": "San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)",
            "victim": "US citizens and international individuals (other countries also affected per DOJ) targeted for cryptocurrency investment fraud through pig-butchering; victims were identified nationally through complaints filed with the FBI's Internet Crime Complaint Center (IC3), supplemented by victim interviews and financial/cryptocurrency-ledger analysis. No victims are individually named in the public record reviewed.",
            "incident_date": "2026-04-29 (DOJ/FBI public announcement); Thet Min Nyi indictment returned by SDCA grand jury March 2026; two criminal complaints (Awang/Chandra/fugitive; Mariam) filed SDCA April 2026; Dubai-led arrests conducted the week prior to the announcement (on/around 2026-04-20 to 2026-04-24)",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Cryptocurrency & Digital Assets",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "DOJ's press release states the scam centers \"targeted Americans who have suffered millions of dollars in losses\" but does not itemize. Case-specific total loss figure or name individual victims. Separately (and not specific to these three named companies), the release notes that the FBI's broader \"Operation Level Up\" initiative, a proactive victim-identification program running since 2024, had by April 2026 notified almost 9,000 victims and saved an estimated $562 million; that figure should not be read as the loss total for Ko Thet Company/Sanduo Group/Giant Company specifically. One lower-tier secondary source (thefinancialstandard.com) cites larger aggregate figures ($701M restrained, 20,000+ victims across 30 countries) and a conflicting Nyi arrest date of May 7, 2026 that contradicts the primary release's own timeline (\"last week\" of arrests before the April 29 announcement); those unconfirmed figures/dates are not relied upon in this record and are flagged as discrepant.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/san-diego-scam-compound-takedown-ko-thet-sanduo-giant-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "saudi-aramco-badge-surfing-shamoon-2012",
            "title": "Saudi Aramco “Badge Surfer” Claim in the 2012 Shamoon Attack – A Security-Awareness Narrative Without Primary-Source Corroboration",
            "victim": "Saudi Aramco (Saudi Arabian Oil Company)",
            "incident_date": "2012-08-15 (Shamoon detonation, confirmed); the badge-surfing/password-photo claim itself is undated and first traceable to a NINJIO training blog post published 2016-12-27",
            "year": 2012,
            "country": "Saudi Arabia",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Critical Infrastructure, Energy & Utilities",
            "threat_actors": "Hacktivist",
            "case_type": "real-world-incident",
            "status": "alleged",
            "loss_usd": 0,
            "loss_basis": "Not publicly confirmed as a total dollar figure in any primary source. Contemporaneous Reuters reporting put the toll at roughly 30,000 infected/wiped workstations; Defense Secretary Leon Panetta's October 2012 public remarks and later retrospectives (CNN/Chris Kubecka, 2015) round this up to ~35,000 machines (~85% of Aramco's IT infrastructure) and add that Aramco purchased roughly 50,000 replacement hard drives at a premium, briefly tightening world HDD supply. Corporate email and internet access were down for an extended period, with staff reportedly reduced to paper, typewriters, and fax machines during recovery. Aramco stated its oil exploration, production, and distribution systems were unaffected because they sit on a network segregated from the corporate IT systems Shamoon hit, meaning the core revenue-generating operations were not directly disrupted, whatever the ultimate cleanup cost was.",
            "source_count": 13,
            "url": "https://socialengineeringexamples.com/saudi-aramco-badge-surfing-shamoon-2012",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "save-the-children-federation-charity-bec-2017",
            "title": "Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)",
            "victim": "Save the Children Federation, Inc. (Save the Children US), the Fairfield, Connecticut-based US affiliate of the international charity (EIN 06-0726487).",
            "incident_date": "2017 (fraud committed ~April to May 2017; discovered May 2017; disclosed in IRS Form 990 filed August 2018, first reported December 2018)",
            "year": 2017,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Nonprofit & NGO",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 997400,
            "loss_basis": "Primary incident: $997,400 wired to a fraudulent entity in Japan; insurance reimbursed $885,784, leaving a net loss of about $111,616 (~$112,000). Second incident: $9,210 diverted to a hacked vendor's fraudulent account in Benin, West Africa; all but $120 recovered.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/save-the-children-federation-charity-bec-2017",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "philadelphia-school-district-vendor-ach-bec-2024",
            "title": "School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)",
            "victim": "School District of Philadelphia (and two of its contracted vendors, who completed work but were not paid)",
            "incident_date": "2024-02 to 2024-03 (fraud); disclosed 2025-05-22",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Education; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 689207,
            "loss_basis": "Approximately $689,207 diverted across four fraudulent ACH transfers. Approximately $689,207 diverted across four ACH transfers (a $563,151 payment for flood-damage repair on March 12, 2024, plus $126,056 for special-education compensatory services across Feb. 6, Feb. 27, and March 8, 2024). Funds not recovered as of the May 2025 disclosure; district stated it did not pay more than contractually owed.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/philadelphia-school-district-vendor-ach-bec-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "sci-engineered-materials-imposter-scam-2026",
            "title": "SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)",
            "victim": "SCI Engineered Materials, Inc. (OTCQB: SCIA), a Columbus, Ohio-based global supplier and manufacturer of advanced materials for physical vapor deposition (PVD) thin-film applications serving aerospace, defense, automotive, semiconductor, and solar customers.",
            "incident_date": "2026-02-10",
            "year": 2026,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Defense & Aerospace; Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 898325,
            "loss_basis": "$898,325 gross loss disclosed February 10, 2026 (\"imposter scam ... executed in conjunction with bank fraud\"). SCI's Q1 2026 Form 10-Q reports $336,299 recovered as of April 30, 2026, leaving a net fraud expense of $562,026 recognized in Q1 2026 operating expenses. No insurance payout amount, additional recovery, or final loss figure has been publicly disclosed as of the most recent filing reviewed.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/sci-engineered-materials-imposter-scam-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "scoular-ceo-fraud-bec-2014",
            "title": "Scoular Company $17.2M grain-trader wire fraud (2014)",
            "victim": "The Scoular Company, a privately held (employee-owned) grain-trading and commodities handling firm; the individual target was corporate controller Keith McMurtry.",
            "incident_date": "June 2014 (discovered June 2014; publicly reported Feb 2015)",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 17200000,
            "loss_basis": "$17.2 million lost across three wire transfers ($780,000; $7 million; $9.4 million). Funds not recovered; the Shanghai account was closed and money moved before an FBI seizure order could be executed.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/scoular-ceo-fraud-bec-2014",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "seagate-w2-ceo-spoof-phishing-2016",
            "title": "Seagate CEO-Spoof W-2 Phishing Breach (2016)",
            "victim": "Seagate Technology (data storage manufacturer, then HQ Cupertino, CA), and its several thousand current and former US-based employees whose 2015 W-2 data was exposed.",
            "incident_date": "2016-03-01",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial; Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No dollar figure publicly disclosed. Direct exposure: full W-2 data (names, addresses, SSNs, earnings) for several thousand (fewer than 10,000) US employees, creating tax-refund-fraud and identity-theft risk. Seagate paid for two years of Experian ProtectMyID credit monitoring (with $1,000,000 identity-theft insurance) for those affected; the incident also led to employee class-action litigation (Castillo et al. v. Seagate Technology LLC, N.D. Cal., settled 2018).",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/seagate-w2-ceo-spoof-phishing-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "sec-21a-report-nine-issuers-bec-2018",
            "title": "SEC Section 21(a) Report on Nine Issuers’ Business Email Compromise Losses",
            "victim": "Nine unnamed U.S. public companies (aggregate), spanning technology, machinery, real estate, energy, financial, and consumer-goods sectors",
            "incident_date": "2018-10-16 (SEC report release date; underlying frauds occurred in prior years)",
            "year": 2018,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Cross-Sector / Multiple Industries",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Aggregate losses across the nine issuers were nearly $100 million. Per the SEC report: each of the nine issuers lost at least $1 million; two lost more than $30 million each; one lost more than $45 million; almost all losses were unrecovered. The report's two detailed examples: a fake-executive scheme with 14 wire payments over several weeks causing over $45 million in losses (closely matching Ubiquiti Networks' disclosed $46.7 million 2015 loss), and a fake-vendor scheme with eight fraudulent invoices totaling $1.5 million paid over several months.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/sec-21a-report-nine-issuers-bec-2018",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "whatsapp-pig-butchering-nanobit-sec-2024",
            "title": "SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals",
            "victim": "At least 18 U.S. retail investors solicited and defrauded through WhatsApp investment groups",
            "incident_date": "Scheme ran ~September/October 2023 to June 2024 (the SEC's two litigation releases give slightly different start-date estimates); SEC complaint filed September 17, 2024; default judgment entered June 16, 2026 (SEC announced June 29, 2026)",
            "year": 2023,
            "country": "United States",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Cryptocurrency & Digital Assets; Financial Services & Insurance; Retail & E-commerce",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 967835,
            "loss_basis": "SEC complaint alleged at least 18 investors lost a combined ~$967,835 in crypto assets and fiat currency; of this. Scheme participants allegedly wired more than $2 million (aggregate, including co-mingled funds beyond the 18 named victims) to bank accounts in Hong Kong and moved roughly $725,335 in crypto to three unhosted wallet addresses, with about $242,500 in fiat received by \"money mule\" corporate defendants. The June 16, 2026 default judgment ordered a combined $5,518,902 in disgorgement, prejudgment interest, and civil penalties across six defendants (NanoBit Limited: $1,796,857; Radiant Horizons Limited: $1,182,251; Zhao Tropical Deli Inc.: $1,182,251; Sweet Karma Fashion Inc.: $1,182,251; Jiajie Liu: $120,088; Hua Zhao: $55,204). This is a court-ordered judgment amount, not confirmed actual recovery/collection from defendants believed to be overseas.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/whatsapp-pig-butchering-nanobit-sec-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "shredit-iron-mountain-gsa-shredding-settlement-2013",
            "title": "Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)",
            "victim": "U.S. federal government agencies purchasing document-shredding services under GSA Schedule 36 contracts, including the Department of Defense, Department of Homeland Security, Department of Justice, Social Security Administration, Department of the Treasury, and Department of Veterans Affairs",
            "incident_date": "2013-07-09 (DOJ settlement announced); underlying conduct alleged from at least 2006; qui tam complaint filed 2010 in U.S. District Court, E.D. Pennsylvania",
            "year": 2013,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting); Pretexting & Impersonation",
            "sectors": "Government & Public Sector; Professional & Business Services",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 1100000,
            "loss_basis": "$1,100,000 total settlement: Iron Mountain paid $800,000 plus the relator's attorneys' fees; Shred-It paid $300,000 plus attorneys' fees. Under the False Claims Act, relator Douglas Knisely was entitled to a statutory 15%-25% share of the government's recovery (exact dollar amount not publicly disclosed in the sources reviewed). A third named defendant, Cintas Corporation, did not settle and continued to contest the allegations, so no payment from Cintas is reflected in this $1.1M figure. Separately and unrelated in mechanism (a pricing/overcharging issue, not shred-size fraud), Iron Mountain later paid $44.5 million in a 2014 GSA storage-contract False Claims Act settlement; this should not be conflated with this shredding case.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/shredit-iron-mountain-gsa-shredding-settlement-2013",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "singapore-anti-scam-centre-impersonation-2025",
            "title": "Singapore Anti-Scam Centre / Police Impersonation Scam: “Jane” Loses S$1.2 Million (2024-2025)",
            "victim": "Individual Singaporean woman, referred to by the pseudonym \"Jane,\" a financial-sector professional in her 50s; her real identity was not disclosed by police or media",
            "incident_date": "2024-12-11 to 2025-01-24 (scam period); police report filed 2025-02-06; case publicized by Singapore Police Force at a media briefing on 2025-03-14, reported by CNA/Straits Times 2025-03-17/18",
            "year": 2024,
            "country": "Singapore",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 900000,
            "loss_basis": "Total reported loss: S$1.2 million (~US$900,000), described by the victim as her life savings intended for a new home and retirement. Reported breakdown: S$500,000 initially withdrawn from her own bank and moved into a new account she was told to open at a Chinese bank; of that, S$180,000 (~US$135,000) was sent out in nine transfers between 18-19 Dec 2024, each just under S$20,000 (apparently structured to stay under reporting/scrutiny thresholds); after the Chinese bank suspended the account over suspicious activity, she withdrew the remaining balance in S$100 notes and handed cash to in-person \"couriers\" across four separate meetups in central Singapore (the last on 3 Jan 2025), with cumulative withdrawals and handovers over the full two-month period totaling the reported S$1.2 million. No recovery or restitution was reported in connection with this case as of the March 2025 media briefing.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/singapore-anti-scam-centre-impersonation-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "singapore-pm-wong-deepfake-zoom-scam-2026",
            "title": "Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong",
            "victim": "Unnamed Singaporean businessman / business professional",
            "incident_date": "2026-05-14",
            "year": 2026,
            "country": "Singapore",
            "attack_channels": "Deepfake & Synthetic Media; Pretexting & Impersonation; Smishing (SMS Phishing); Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance; Government & Public Sector",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 3800000,
            "loss_basis": "Victim lost at least S$4.9 million (approximately US$3.8 million; reported by some outlets as roughly RM15.3 million). Transferred via a series of transactions to a corporate bank account supplied by the scammers. This is described by police as a minimum (\"at least\") figure.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/singapore-pm-wong-deepfake-zoom-scam-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "mexico-gov-agentic-ai-breach-2026",
            "title": "Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies",
            "victim": "Gambit Security's own technical report enumerates exactly nine named Mexican government organizations: Servicio de Administración Tributaria (SAT, federal tax authority), Instituto Nacional Electoral (INE), Mexico City's civil registry (Registro Civil) and health department (Salud CDMX), and the state governments of México (Estado de México), Jalisco, Michoacán, and Tamaulipas, plus SADM Monterrey (municipal water/drainage utility). Press coverage (SecurityWeek, Security Affairs) additionally cites an unnamed financial institution as a tenth victim per Gambit's statements to reporters, but that financial-institution victim is not itemized in Gambit's own published report.",
            "incident_date": "Campaign ran approximately December 27, 2025 - mid-February 2026 (~7 weeks); initial findings disclosed ~February 25-26, 2026 (Bloomberg/LA Times/NDTV); SecurityWeek coverage March 1, 2026; Gambit's full 37-page technical report published April 10, 2026 after a coordinated disclosure delay; Dragos published a follow-on OT-focused report on the Monterrey water utility intrusion in May 2026",
            "year": 2025,
            "country": "Israel",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); Phishing; Pretexting & Impersonation",
            "sectors": "Critical Infrastructure, Energy & Utilities; Financial Services & Insurance; Government & Public Sector; Healthcare",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not quantified in dollar terms; no ransom or direct monetary theft was reported. Impact is measured in data scale: ~150GB exfiltrated, ~195 million individual records exposed (taxpayer, civil registry, voter, employee-credential, and health data), plus a live forged-document service (fake \"Constancia de Situación Fiscal\" tax certificates) that reportedly had external clients within hours of deployment. Gambit notes remediation/recovery costs for a breach of this scale are typically \"long, disruptive, and expensive\" but does not provide a dollar figure.",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/mexico-gov-agentic-ai-breach-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "snapchat-w2-payroll-phishing-2016",
            "title": "Snapchat W-2 Payroll Phishing Breach (2016)",
            "victim": "Snap Inc. (Snapchat), approximately 700 current and former employees",
            "incident_date": "2016-02-26 (attack); disclosed 2016-02-28",
            "year": 2016,
            "country": "United States",
            "attack_channels": "Phishing; Vishing (Voice Phishing)",
            "sectors": "Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No direct financial theft of company funds was reported (unlike wire-transfer BEC scams). The loss was data exposure of an estimated ~700 current and former employees' PII, creating downstream identity-theft and fraudulent tax-return risk. Snap incurred costs for two years of identity-theft monitoring/insurance (via ID Experts/MyIDCare) for all affected individuals, incident response, and reputational/legal exposure (California AG data-breach notification filing). No dollar figure for the monitoring program cost or total incident cost has ever been publicly disclosed; this is a genuine absence of data, not an unverified claim.",
            "source_count": 9,
            "url": "https://socialengineeringexamples.com/snapchat-w2-payroll-phishing-2016",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "sony-pictures-guardians-of-peace-2014",
            "title": "Sony Pictures ‘Guardians of Peace’ hack: fake Apple ID emails to admins",
            "victim": "Sony Pictures Entertainment (SPE), the U.S. film/TV subsidiary of Sony Corp.; executives and employees with network/root access were the initial phishing targets.",
            "incident_date": "Sept-Nov 2014 (spear-phishing ~Oct 3-Nov 3, 2014; destructive attack revealed Nov 24, 2014)",
            "year": 2014,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Media & Entertainment",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 15000000,
            "loss_basis": "Sony reported roughly $15M in investigation and remediation costs in its Feb 2015 results; total impact widely estimated in the tens of millions. Plus significant reputational and operational harm. Exact all-in figure not definitively established.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/sony-pictures-guardians-of-peace-2014",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "southern-california-edison-utility-disconnection-scam-2025",
            "title": "Southern California Edison Utility Disconnection Threat Scam (2025)",
            "victim": "Southern California Edison (SCE) customers across its ~15 million-person service territory (Central, Coastal, and Southern California); disproportionately elderly customers, non-native English speakers, and small-business owners (restaurants, salons, auto shops, dental offices, churches, retail) per SCE's own risk profiling",
            "incident_date": "2024-2025 (statistics covering calendar year 2025 vs. 2024 baseline); publicly disclosed by SCE during National Consumer Protection Week, March 1-7, 2026, with local news coverage March 3-6, 2026",
            "year": 2024,
            "country": "United States",
            "attack_channels": "Pretexting & Impersonation",
            "sectors": "Consumer / General Public; Critical Infrastructure, Energy & Utilities",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 806000,
            "loss_basis": "SCE customers filed 1,750 fraud complaints in 2025 involving over $806,000 demanded by scammers. SCE reported that in 2025, customers filed 1,750 fraud complaints (rounded to \"1,700+\" in some coverage) involving over $806,000 in total funds demanded by scammers, of which fraudsters actually collected $131,464 (rounded to \"$130,000+\" in broadcast coverage), a decline of nearly 72% (reported as \"more than 70%\") compared to 2024 losses. This continues a multi-year pattern SCE has publicly tracked: prior disclosures cited more than $667,000 lost in 2021 (a 57% jump from more than $426,000 in 2020, per SCE's own energized.edison.com recap) and $229,000 lost from January through October of 2023 across more than 2,700 reports (also per SCE's own recap), indicating losses have fluctuated but trended down sharply into 2025 even as complaint volume (1,750) stayed comparable to prior years.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/southern-california-edison-utility-disconnection-scam-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "standard-bank-capitec-education-fund-vishing-2026",
            "title": "Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam",
            "victim": "Reabetswe Modisane, 18, of North West, South Africa: a Standard Bank retail customer whose late father had set up a trust account to fund her university education; Capitec Bank was the receiving/beneficiary institution used to move the stolen funds.",
            "incident_date": "23 May 2026 (vishing call and fraudulent transfers); Capitec beneficiary account created on victim's Standard Bank digital profile 13 May 2026; case publicly reported by TimesLive on 20 July 2026",
            "year": 2026,
            "country": "South Africa",
            "attack_channels": "Phishing; Smishing (SMS Phishing); Vishing (Voice Phishing)",
            "sectors": "Consumer / General Public; Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 23000,
            "loss_basis": "R438,900 (~US$23,000-24,000) moved in three transfers (R48,900, R190,000 and R200,000) to a Capitec account within roughly 20 minutes. By the time the fraud was flagged (about a day later) the receiving Capitec account held only R406. Standard Bank denied liability for a systems breach and offered the family an undisclosed \"goodwill\" settlement rather than a full refund; Capitec's internal investigation also found no fault on its side. The family's claim was, as of the 20 July 2026 report, still pending before the National Financial Ombud.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/standard-bank-capitec-education-fund-vishing-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "stuxnet-natanz-usb-2010",
            "title": "Stuxnet: USB-borne sabotage of Iran’s air-gapped Natanz enrichment plant",
            "victim": "Islamic Republic of Iran / Atomic Energy Organization of Iran; specifically the Fuel Enrichment Plant (FEP) at Natanz and its IR-1 centrifuges (Siemens S7-315 PLCs driving frequency converters).",
            "incident_date": "2010",
            "year": 2010,
            "country": "Iran",
            "attack_channels": "Phishing; Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Critical Infrastructure, Energy & Utilities; Government & Public Sector",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "n/a (nation-state sabotage; no direct monetary figure). Impact measured in destroyed hardware and program delay: ~1,000 IR-1 centrifuges wrecked; US officials estimated Iran's enrichment progress was set back roughly 1.5 to 2 years, an estimate others dispute as overstated.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/stuxnet-natanz-usb-2010",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "susie-wiles-ai-voice-impersonation-2025",
            "title": "Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)",
            "victim": "Susie Wiles, White House Chief of Staff, and by extension the senators, governors, business executives, and other prominent Republicans/well-known figures in her personal contact list who received the fraudulent texts and calls",
            "incident_date": "2025-05 (campaign active weeks before public disclosure on 2025-05-29/30, FBI PSA on broader related campaign issued 2025-05-15)",
            "year": 2025,
            "country": "United States",
            "attack_channels": "Deepfake & Synthetic Media; Pretexting & Impersonation; Smishing (SMS Phishing)",
            "sectors": "Cross-Sector / Multiple Industries; Government & Public Sector",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No financial loss has been publicly confirmed. WSJ reported that in at least one instance the impersonator asked a recipient for a cash transfer, but no source confirms any funds were actually sent or any monetary loss occurred. The primary confirmed harms are reputational/operational: disruption to Wiles's network of contacts, engagement by some recipients before they realized the deception, and the launch of an FBI investigation.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/susie-wiles-ai-voice-impersonation-2025",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "target-fazio-hvac-vendor-phishing-breach-2013",
            "title": "Target’s 2013 Data Breach: A Phished HVAC Vendor as the Way In",
            "victim": "Target Corporation (retailer); initial victim: Fazio Mechanical Services, a refrigeration/HVAC contractor in Sharpsburg, Pennsylvania",
            "incident_date": "2013-11 to 2013-12 (breach window; POS card capture ~Nov 27-Dec 15, 2013; vendor phishing began at least ~2 months earlier; publicly disclosed Dec 19, 2013)",
            "year": 2013,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Financial Services & Insurance; Manufacturing & Industrial; Retail & E-commerce",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 292000000,
            "loss_basis": "~40M payment card accounts and ~70M customer PII records exposed (as many as ~110M consumers affected in total, per the Senate report). By its 2016 Form 10-K, Target had incurred ~$292M in cumulative gross breach-related expenses, offset by ~$90M in insurance recoveries, for net costs of about $202M. Settlements included an $18.5M multistate settlement with 47 states and DC (2017, the largest multistate data-breach settlement at the time), a $10M federal consumer class-action settlement (2015), and separate settlements with payment-card networks and banks.",
            "source_count": 8,
            "url": "https://socialengineeringexamples.com/target-fazio-hvac-vendor-phishing-breach-2013",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "td-bank-lost-backup-tapes-2012",
            "title": "TD Bank Lost Unencrypted Backup Tapes – Multistate and Massachusetts AG Settlements",
            "victim": "TD Bank, N.A. and its customers (260,000 affected nationwide, including over 90,000 in Massachusetts and 31,407 in New York)",
            "incident_date": "Loss: late March 2012. Confirmed/reported to federal regulators: May 16, 2012. Notice to Massachusetts AG: October 5, 2012. Customer notification began: on or about October 12, 2012. Multistate settlement announced: October 15, 2014. Massachusetts settlement filed: December 8, 2014.",
            "year": 2012,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 1675000,
            "loss_basis": "Combined $1.675M in regulatory settlements, no confirmed direct fraud losses. Multistate Assurance of Voluntary Compliance (Oct 15, 2014, led by NY AG Eric Schneiderman, joined by CT, FL, ME, MD, NJ, NC, PA, VT, 9 states total): $850,000, of which New York's share was $114,106.11. Separate Massachusetts AG settlement (Dec 8, 2014): $825,000 total value, consisting of $625,000 cash ($325,000 civil penalties, $75,000 attorneys' fees/costs, and $225,000 to the AG's local consumer aid fund) plus a $200,000 credit TD Bank received for security upgrades it had already implemented. TD Bank stated it had no evidence the tapes fell into unauthorized hands and no evidence of resulting fraud; it did not admit wrongdoing in the Massachusetts filing.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/td-bank-lost-backup-tapes-2012",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "tecnimont-spa-bec-fake-conference-call-fraud-2018",
            "title": "Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls",
            "victim": "Tecnimont Private Limited (Tecnimont Pvt Ltd), the Indian subsidiary of Tecnimont SpA, part of the Milan-headquartered, publicly traded Maire Tecnimont Group",
            "incident_date": "2018-11 (three fraudulent wire transfers made over one week in November 2018. An initial spoofed email is reported by Italian press outlet Corriere della Sera to have arrived 2018-11-13. Economic Times and Reuters, drawing on the Mumbai police complaint, report the fraud was discovered when group chairman Franco Ghiringhelli visited India in December 2018; Corriere della Sera's own account instead describes the chairman learning of the scheme roughly nine days after the initial email, i.e. around late November 2018, so sources conflict on the exact discovery date. Publicly reported by Economic Times/Reuters on 2019-01-10)",
            "year": 2018,
            "country": "India",
            "attack_channels": "Phishing",
            "sectors": "Construction & Engineering; Critical Infrastructure, Energy & Utilities; Manufacturing & Industrial",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 18600000,
            "loss_basis": "$18.6 million (~Rs 130 crore) per Economic Times and CARE Ratings; Reuters reported a closely aligned figure (~$18.45-18.5 million from 1.3 billion rupees). Sent in three tranches: $5.6 million, $9.4 million, and $3.6 million, from India to Hong Kong bank accounts opened with fake documents; funds were withdrawn within minutes of each transfer. A fourth transfer attempt was stopped once the fraud was discovered. No source reviewed confirms recovery of the stolen funds; CARE Ratings' March 2019 note says the impact was only \"partially mitigated\" by the company's cash reserves, implying the loss was largely absorbed, not recovered.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/tecnimont-spa-bec-fake-conference-call-fraud-2018",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "tennant-v-advance-machine-dumpster-diving-1984",
            "title": "Tennant Co. v. Advance Machine Co. – Dumpster Diving / Conversion Punitive Damages Verdict",
            "victim": "Tennant Company",
            "incident_date": "Conduct: fall 1978 through spring 1979. Lawsuit commenced early 1980. Jury verdict: 1983 (secondary reporting places it April 1983; exact day not found in primary source). Minnesota Court of Appeals decision: September 18, 1984 (355 N.W.2d 720).",
            "year": 1978,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Manufacturing & Industrial; Professional & Business Services",
            "threat_actors": "Corporate / Competitive Intelligence",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 100000,
            "loss_basis": "Jury awarded Tennant $100,000 compensatory (actual) damages plus $400,000 punitive damages (total $500,000). Trial court granted Advance's motion for judgment notwithstanding the verdict (JNOV) striking the punitive award; the Minnesota Court of Appeals affirmed the $100,000 compensatory award and reversed the JNOV, reinstating the full $400,000 punitive award, restoring the $500,000 total.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/tennant-v-advance-machine-dumpster-diving-1984",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "toyota-boshoku-europe-bec-37m-2019",
            "title": "Toyota Boshoku European Subsidiary $37M BEC (2019)",
            "victim": "Toyota Boshoku Corporation (unnamed European subsidiary), automotive seating and interior components maker, part of the Toyota Group; HQ Kariya, Japan (TSE:3116)",
            "incident_date": "2019-08-14",
            "year": 2019,
            "country": "Japan",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 37500000,
            "loss_basis": "Expected loss of up to approximately 4 billion yen (~$37.5M / EUR33.9M) as of 5 September 2019; recovery efforts underway, amount recovered not disclosed",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/toyota-boshoku-europe-bec-37m-2019",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "twitter-vishing-account-takeover-2020",
            "title": "Twitter July 2020 Account Hijack via Phone Spear Phishing (Vishing)",
            "victim": "Twitter, Inc. (its employees and internal systems); ~130 targeted high-profile account holders (Obama, Biden, Musk, Bezos, Gates, Kim Kardashian West, Apple, Uber, and crypto accounts incl. Coinbase, Gemini, Binance); and the public who sent bitcoin to the scam. Per the NY DFS report, NY-DFS-regulated firms Coinbase, Square, Gemini, and Bitstamp blocked the scam address (Binance is not NY-DFS-regulated).",
            "incident_date": "2020-07",
            "year": 2020,
            "country": "United States",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Cryptocurrency & Digital Assets; Technology & Software",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 118000,
            "loss_basis": "~$118,000 USD in bitcoin stolen from the public; a further ~$1.5M in ~6,000 attempted transfers was blocked by regulated crypto companies",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/twitter-vishing-account-takeover-2020",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "uac-0050-clickfix-recaptcha-lucky-volunteer-2024",
            "title": "UAC-0050 ClickFix Fake-reCAPTCHA Campaign Deploys ‘Lucky Volunteer’ Infostealer Against Ukrainian Organizations",
            "victim": "Unnamed organizations in Ukraine, per Proofpoint's telemetry for this specific campaign. UAC-0050 as a group has historically concentrated on Ukrainian state bodies and on accountants at Ukrainian enterprises/sole proprietorships. A closely related fake-reCAPTCHA/ClickFix technique documented by CERT-UA in the same period specifically hit Ukrainian local government bodies, but that advisory (CERT-UA#11689) attributes the activity to UAC-0001/APT28, not UAC-0050.",
            "incident_date": "2024-10-31 (Proofpoint-observed wave); part of UAC-0050 activity CERT-UA tracked through September-October 2024",
            "year": 2024,
            "country": "Ukraine",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering); ClickFix & SEO Poisoning",
            "sectors": "Government & Public Sector",
            "threat_actors": "Nation-State / APT",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not disclosed for this specific ClickFix/Lucky Volunteer sub-campaign: no ransom, breach-cost, or theft figure was published. (Separately, in the same Sept-Oct 2024 window, CERT-UA reported UAC-0050 made at least 30 attempted fraudulent bank transfers against Ukrainian companies and sole proprietors via a different intrusion vector (REMCOS/TEKTONITRMS remote-access tools, not this ClickFix chain), with individual theft amounts ranging from tens of thousands to several million hryvnias, later laundered through cryptocurrency. That figure should not be conflated with the ClickFix/Lucky Volunteer campaign itself.)",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/uac-0050-clickfix-recaptcha-lucky-volunteer-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "uber-mfa-fatigue-breach-2022",
            "title": "Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor",
            "victim": "Uber Technologies, Inc. (initial victim: an external \"EXT\" contractor with VPN access)",
            "incident_date": "2022-09",
            "year": 2022,
            "country": "United States",
            "attack_channels": "Help-Desk & MFA Manipulation; Phishing",
            "sectors": "Technology & Software; Transportation & Logistics",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 3000000,
            "loss_basis": "~$3M USD (UK prosecutors stated the intrusion caused nearly $3 million in damage to Uber; no customer-facing financial loss was reported)",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/uber-mfa-fatigue-breach-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "ubiquiti-networks-bec-2015",
            "title": "Ubiquiti Networks $46.7M business email compromise (2015)",
            "victim": "Ubiquiti Networks, Inc. (San Jose, CA; NASDAQ: UBNT) via its indirect wholly-owned Hong Kong subsidiary, Ubiquiti Networks International Limited",
            "incident_date": "2015-05-20 to 2015-06-05 (discovered 2015-06-05; disclosed 2015-08-06)",
            "year": 2015,
            "country": "Poland",
            "attack_channels": "Phishing",
            "sectors": "Technology & Software",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 46703232,
            "loss_basis": "$46,703,232 fraudulently transferred in 14 wires; $8.1M recovered by June 30, 2015, with further court-ordered recoveries thereafter. A $39.1M net BEC fraud loss charge recorded in Q4 FY2015. Company continued pursuing roughly $30M that was likely unrecoverable.",
            "source_count": 6,
            "url": "https://socialengineeringexamples.com/ubiquiti-networks-bec-2015",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "uiuc-usb-drop-field-experiment-2015",
            "title": "UIUC USB Drive Drop Field Experiment (2015)",
            "victim": "University of Illinois at Urbana-Champaign community members (students, faculty, and staff), all anonymous, unwitting study participants who found and connected the dropped drives",
            "incident_date": "2015-04-27",
            "year": 2015,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Cross-Sector / Multiple Industries; Education",
            "threat_actors": "Authorized Tester or Researcher",
            "case_type": "research-advisory",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None. This was a controlled academic research study, not a criminal attack; no financial loss occurred. The paper's significance is as an empirical baseline proving the real-world efficacy of the USB-baiting technique that criminal actors (e.g., FIN7's \"BadUSB\" mailer campaigns) also use.",
            "source_count": 7,
            "url": "https://socialengineeringexamples.com/uiuc-usb-drop-field-experiment-2015",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "uk-council-car-park-qr-quishing-2024-2026",
            "title": "UK Council Car Park QR Code (“Quishing”) Scams – Cheltenham, Swindon & Somerset",
            "victim": "Multiple UK local councils and their car park users: Cheltenham Borough Council, Swindon Borough Council, Somerset Council, plus other councils nationwide (Castleford/Wakefield area, Southampton, Aberdeen); PayByPhone (the parking-payment provider whose branding was spoofed) and individual motorists who scanned fake codes",
            "incident_date": "First confirmed sighting: week of 28 June 2024 (Cheltenham); Somerset Council warning 14 Aug 2024; Swindon investigation reported 10 Mar 2025; Watchet, Somerset incident reported May 2025; scam recurring/ongoing through BBC reports of 15 Oct 2025 and 21 May 2026. National Action Fraud figures cited span 2019-2025.",
            "year": 2024,
            "country": "United Kingdom",
            "attack_channels": "Quishing (QR Code Phishing)",
            "sectors": "Consumer / General Public; Government & Public Sector; Transportation & Logistics",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No single confirmed total for the Cheltenham/Swindon/Somerset incidents specifically. National context (Action Fraud): 784 quishing reports between April 2024-April 2025 with nearly £3.5 million lost (Action Fraud press release, corroborated by BBC Shared Data Unit reporting and The Independent, 10 Sep 2025); separately, BBC reported Action Fraud figures of 1,386 quishing reports in \"2025\" versus 100 in 2019 (a figure BBC's own April 2025 and May 2026 articles apply slightly inconsistently to the exact year, so treat the year-attribution as approximate rather than precisely dated). Action Fraud also noted total reports more than doubled between 2023 and 2024, with roughly 3,000 reports total over five years and a fifth tied to the Metropolitan Police area. Documented individual losses: a Watchet, Somerset victim was charged £50 for parking via a fraudulent site sitting atop a genuine PayByPhone code; a Castleford, West Yorkshire victim (Milton Haworth) was tricked into an unauthorized 90p \"verification\" fee that enrolled him in a £39 subscription charge with no refund. BBC's original 30 Oct 2024 report quotes Finda's own email to Haworth stating a monthly fee would be automatically taken if the subscription was not cancelled, indicating a recurring monthly charge (a later BBC article, 11 Apr 2025, describes it instead as a \"£39 yearly fee,\" an inconsistency across BBC's own reporting; the primary Oct 2024 account is treated as authoritative here). Chartered Trading Standards Institute officer Katherine Hart said the broader quishing pattern often starts with small charges (90p-£2.99) used to harvest card data for follow-on \"secondary scams\" (bogus bank/police impersonation calls), and that \"we've seen huge amounts lost this way... people have seen their life savings gone.\"",
            "source_count": 14,
            "url": "https://socialengineeringexamples.com/uk-council-car-park-qr-quishing-2024-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "uk-energy-firm-ai-voice-clone-ceo-fraud-2019",
            "title": "UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)",
            "victim": "Unnamed UK-based energy firm, a subsidiary of an unnamed German parent company (both companies were not publicly named in reporting; insurer Euler Hermes disclosed the case on the client's behalf). The individual deceived was the CEO/managing director of the UK subsidiary, not a rank-and-file employee.",
            "incident_date": "2019-03 (incident occurred on a Friday afternoon in March 2019, per Euler Hermes; first publicly disclosed by the Wall Street Journal on August 30, 2019, with broader media coverage, including the Washington Post, Forbes, and others, following in the first week of September 2019)",
            "year": 2019,
            "country": "United Kingdom",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Critical Infrastructure, Energy & Utilities; Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 243000,
            "loss_basis": "€220,000 wired to the Hungarian supplier account (reported in US press as approximately $243,000 and in UK press as approximately £198,600/£200,000). Funds were reportedly moved on from the Hungarian account through further accounts (reported destinations included Mexico) and were not recovered. A second transfer attempt was stopped before completion; sources describe it only as an \"additional\" or \"further\" transfer and do not confirm it was for a larger amount than the first. Euler Hermes, the parent company's crime/fraud insurer, covered the loss under the company's insurance policy.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/uk-energy-firm-ai-voice-clone-ceo-fraud-2019",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "unatrac-caterpillar-cfo-bec-2018",
            "title": "Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise",
            "victim": "Unatrac Holding Limited, a UK-based export sales office/dealer for Caterpillar heavy equipment",
            "incident_date": "2018-04-01 (initial phishing/compromise); 2018-04-11 to 2018-04-19 (fraudulent wire requests); 2020-06-18 (Okeke guilty plea); 2021-02-16 (sentencing)",
            "year": 2018,
            "country": "United States",
            "attack_channels": "Phishing",
            "sectors": "Manufacturing & Industrial",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 11000000,
            "loss_basis": "Approximately $11 million lost, per DOJ sentencing materials. Approximately $11 million (three documented Pak Fei Trade Limited wires alone totaled $278,270.66 + $898,461.17 + $1,957,100.00 = $3,133,831.83; total across ~15 fraudulent payments reached nearly $11,000,000); DOJ's sentencing materials describe the loss as \"approximately $11 million.\" Per the FBI affidavit, Unatrac was able to recover very little of the transferred funds.",
            "source_count": 5,
            "url": "https://socialengineeringexamples.com/unatrac-caterpillar-cfo-bec-2018",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "usps-ups-package-awaiting-action-smishing-kit-censys-2026",
            "title": "USPS/UPS “Package Awaiting Action” Smishing Kit Exposed via Censys DNS Investigation",
            "victim": "USPS and UPS customers targeted via smishing text messages (mass consumer targeting); secondarily, USPS itself was affected in that the phishing kit reused USPS's production web assets and triggered USPS's own analytics tracking without authorization",
            "incident_date": "Censys technical investigation published 2026-06-12 (based on a Censys DNS snapshot dated 2026-05-20); the corroborating USPS/USPIS press briefing on rising smishing/brushing scams was held June 12, 2025 in Tampa, FL",
            "year": 2026,
            "country": "Unknown",
            "attack_channels": "Smishing (SMS Phishing)",
            "sectors": "Financial Services & Insurance; Government & Public Sector; Retail & E-commerce; Transportation & Logistics",
            "threat_actors": "Organized Crime",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "Not quantified. Neither Censys nor USPS disclosed a victim count or dollar loss figure specific to this smishing kit/cluster. USPS's June 2025 material cites broader Project Safe Delivery program figures (2,800+ arrests related to mail theft and related crimes program-wide, a 27% YoY reduction in letter-carrier robberies FY23 to FY24) that are not attributed to this specific smishing/card-skimming operation.",
            "source_count": 3,
            "url": "https://socialengineeringexamples.com/usps-ups-package-awaiting-action-smishing-kit-censys-2026",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "wells-fargo-alice-fries-bank-impersonation-vishing-2fa-wire-fraud-2022",
            "title": "Wells Fargo ‘Alice Fries’ Bank-Impersonation Vishing / 2FA-Bypass Wire Fraud (2022 fraud; 2023 lawsuit)",
            "victim": "Alice Fries, Wells Fargo retail/premier banking customer",
            "incident_date": "2022-10-24 (fraud occurred); lawsuit filed 2023-08-03 (LA Superior Court, case 23STCV18422) / removed to federal court C.D. Cal. as 2:23-cv-07321-SPG-PD (complaint dated 2023-11-22); reporting on the case surfaced in 2024",
            "year": 2022,
            "country": "United States",
            "attack_channels": "Vishing (Voice Phishing)",
            "sectors": "Financial Services & Insurance",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 100000,
            "loss_basis": "$100,000 fraudulent wire transfer alleged, with Wells Fargo refunding only $50. $100,000 fraudulent wire transfer alleged; Wells Fargo refunded only $50 as a \"courtesy,\" leaving Alice Fries with an alleged net loss of $99,950 (all figures per the civil complaint; not independently adjudicated as of the last public record found)",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/wells-fargo-alice-fries-bank-impersonation-vishing-2fa-wire-fraud-2022",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "wpp-deepfake-ceo-scam-attempt-2024",
            "title": "WPP Deepfake CEO Scam Attempt",
            "victim": "WPP plc (world's largest advertising and public relations holding company); the specific target was an unnamed senior WPP \"agency leader\"/\"agency head,\" with CEO Mark Read and a second unnamed senior WPP executive impersonated as part of the pretext",
            "incident_date": "Disclosed internally and publicly reported 2024-05-10; exact date of the attack itself was not disclosed by WPP",
            "year": 2024,
            "country": "United Kingdom",
            "attack_channels": "Agentic AI Attacks (AI-Powered Social Engineering)",
            "sectors": "Media & Entertainment; Professional & Business Services",
            "threat_actors": "",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "None disclosed: no money or personal data was obtained; the attempt was stopped before any transfer occurred. No specific dollar figure was ever reported as having been demanded or discussed publicly.",
            "source_count": 4,
            "url": "https://socialengineeringexamples.com/wpp-deepfake-ceo-scam-attempt-2024",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        },
        {
            "case_id": "yujing-zhang-mar-a-lago-intrusion-2019",
            "title": "Yujing Zhang Mar-a-Lago Intrusion",
            "victim": "Mar-a-Lago Club (Trump property) / U.S. Secret Service perimeter security, Palm Beach, FL",
            "incident_date": "2019-03-30",
            "year": 2019,
            "country": "United States",
            "attack_channels": "Physical Social Engineering (Tailgating & Baiting)",
            "sectors": "Government & Public Sector; Hospitality, Gaming & Travel",
            "threat_actors": "Unaffiliated Individual",
            "case_type": "real-world-incident",
            "status": "confirmed",
            "loss_usd": 0,
            "loss_basis": "No direct monetary loss to the victim organization was reported or alleged. Impact was a security-perimeter breach at a residence used by a sitting U.S. President, plus the cost of federal investigation, prosecution, ~8-month incarceration, and roughly two years of subsequent ICE immigration detention. No dollar figure was assigned in DOJ materials.",
            "source_count": 12,
            "url": "https://socialengineeringexamples.com/yujing-zhang-mar-a-lago-intrusion-2019",
            "attribution": "Social Engineering Examples / Diopter AI",
            "license": "CC BY 4.0"
        }
    ]
}