Sectors

Defense & Aerospace

Documented social engineering incidents targeting the defense & aerospace sector, sourced and fact-checked.


12 Cases
Confirmed

RSA SecurID Breach: The "2011 Recruitment Plan" Spear-Phishing Email (2011)

A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to the theft of SecurID data later used to attack defense contractor Lockheed Martin.

Incident 2011Read →
Confirmed

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.

Incident 2026Read →
Confirmed

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging Face API) at runtime to dynamically generate the Windows recon and data-theft commands it then executes against Ukrainian government targets, the first publicly documented malware to call an LLM live in operations.

Incident 2025Read →
Confirmed

Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms

Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.

Incident 2009Read →
Confirmed

Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance

Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.

Incident 2024Read →
Confirmed

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.

Incident 2020Read →
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Incident 2015Read →
Confirmed

FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier

Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project; EUR 41.9M was lost and both the CEO and CFO were later fired.

Incident 2016Read →
Confirmed

OFAC Sanctions DPRK Ministry of National Defense Front Companies Behind Fake-Persona Remote IT-Worker Fraud

Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China, and Vietnam for running fake-persona schemes that placed DPRK IT workers in remote jobs at hundreds of companies worldwide, generating hundreds of millions of dollars for weapons programs, in a scheme whose U.S.-facilitation side (Christina Chapman's laptop farm) generated over $17 million and led to a 102-month prison sentence.

Incident 2025Read →
Confirmed

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.

Incident 2021Read →
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.

Incident 2025Read →
Confirmed

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.

Incident 2014Read →