Documented social engineering incidents targeting the defense & aerospace sector, sourced and fact-checked.
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to the theft of SecurID data later used to attack defense contractor Lockheed Martin.
ConfirmedA small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.
ConfirmedGoogle's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging Face API) at runtime to dynamically generate the Windows recon and data-theft commands it then executes against Ukrainian government targets, the first publicly documented malware to call an LLM live in operations.
ConfirmedChinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.
ConfirmedRussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.
ConfirmedFIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.
ConfirmedDOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.
ConfirmedFraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project; EUR 41.9M was lost and both the CEO and CFO were later fired.
ConfirmedTreasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China, and Vietnam for running fake-persona schemes that placed DPRK IT workers in remote jobs at hundreds of companies worldwide, generating hundreds of millions of dollars for weapons programs, in a scheme whose U.S.-facilitation side (Christina Chapman's laptop farm) generated over $17 million and led to a 102-month prison sentence.
ConfirmedTwo New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.
ConfirmedA single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.
ConfirmedA fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.