Sectors

Financial Services & Insurance

Documented social engineering incidents targeting the financial services & insurance sector, sourced and fact-checked.


46 Cases
Confirmed

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake crypto trading platform, NanoBit, wiring over $2 million to Hong Kong before the SEC secured a $5.5 million default judgment in one of its first pig-butchering enforcement actions.

Incident 2023Read →
Confirmed

Wells Fargo 'Alice Fries' Bank-Impersonation Vishing / 2FA-Bypass Wire Fraud (2022 fraud; 2023 lawsuit)

A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from customer Alice Fries, and a Wells Fargo representative then knowingly overrode the bank's own $50,000 wire-review threshold to release a $100,000 fraudulent wire, per a Los Angeles lawsuit built partly on the bank's own recorded verification call.

Incident 2022Read →
Confirmed

UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)

The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio of his German parent company's own CEO's voice, marking the first widely reported criminal use of AI voice-cloning technology, disclosed by insurer Euler Hermes.

Incident 2019Read →
Confirmed

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames behind a WebSocket-based backend that streamed victims' card data in real time and included an operator kill-switch, a concrete technical case of the package-delivery smishing wave USPS itself had flagged as rising in June 2025.

Incident 2026Read →
Confirmed

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to a "safe" Capitec account, with three transfers completed within 20 minutes; Standard Bank's own investigation attributed the loss to vishing while denying any breach of its systems, and the case has been escalated to the National Financial Ombud and North West police.

Incident 2026Read →
Confirmed

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.

Incident 2013Read →
Confirmed

TD Bank Lost Unencrypted Backup Tapes - Multistate and Massachusetts AG Settlements

Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a roughly seven-month notification delay led to a $850,000 multistate AG settlement and a separate $825,000 Massachusetts settlement mandating encryption of all backup media going forward.

Incident 2012Read →
Confirmed

Singapore Anti-Scam Centre / Police Impersonation Scam: "Jane" Loses S$1.2 Million (2024-2025)

A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre officer and then police "Inspector Chong" convinced her she was linked to money laundering, coaching her to lie to the real Anti-Scam Centre and extracting funds via bank transfers and four in-person cash handoffs.

Incident 2024Read →
Confirmed

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake AI-generated Zoom "government meeting" that appeared to feature PM Lawrence Wong and other senior officials.

Incident 2026Read →
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Incident 2020Read →
Confirmed

SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)

SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South Africa's major banks: digital banking losses rose from roughly R1.08bn (2023, including R625.7m in banking-app fraud alone) to R1.888bn (2024, +74%), with SABRIC explicitly attributing the rise to social engineering rather than technical hacks, while a widely circulated "R3.9bn in 2025" figure and claim of a single four-bank joint alert could not be verified against any primary SABRIC or bank source.

Incident 2023Read →
Confirmed

Pune Italian Engineering Firm CFO Microsoft Teams Boss-Scam (Rs 56 Lakh Loss, 2026)

A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO's name and photo demanded an urgent transfer, then caught the fraud only when a follow-up Rs 1.5 crore ask prompted her to call the real CEO.

Incident 2026Read →
Confirmed

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes, letting attackers exploit Google Authenticator cloud sync to take over 27 crypto customer accounts and steal ~$15M.

Incident 2023Read →
Confirmed

Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms

Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.

Incident 2009Read →
Confirmed

Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025)

A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America, with a spoofed caller ID matching the real number on the back of her bank card, convinced her a hacker was draining her account and that transferring the funds would "protect" them, a case the FBI cites as a textbook "Phantom Hacker" scam.

Incident 2024Read →
Confirmed

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.

Incident 2021Read →
Confirmed

NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case

A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into reading out authentication codes for a fake "safe account" transfer, stealing NZD 30,000 before the Banking Ombudsman recommended the bank reimburse her in full plus costs.

Incident 2024Read →
Confirmed

Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)

A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title company's open dumpster, and combined with a 2004 website hack, it triggered an FTC settlement over failed data-security safeguards.

Incident 2006Read →
Confirmed

Nirmala Sitharaman Deepfake Investment Scam (Bengaluru, 2026)

A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing a fake SBI/Finance-Ministry-linked investment scheme, with WhatsApp callers from a UK number then upselling him into repeated transfers.

Incident 2026Read →
Confirmed

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their late spouse's policy was "in arrears" and draining over $100,000 from them via prepaid gift cards, while separately hiding that income to keep collecting SSI, Medicaid, and HUD housing assistance.

Incident 2020Read →
Confirmed

Los Cyber Bank-Impersonation Vishing Network Dismantled in Colombia

A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers, talked mostly over-50 victims into sharing their phone screens, and drained COP 1.685 billion from 94 people across 10 departments before a joint Fiscalia-Policia Nacional operation captured the group, including alleged leader alias "Ralf."

Incident 2025Read →
Confirmed

MacEwan University BEC Fraud

A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders, tricked staff into redirecting $11.8 million CAD in construction payments to fraudulent bank accounts in Montreal and Hong Kong, one of the largest publicly documented BEC losses at a North American university.

Incident 2017Read →
Confirmed

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.

Incident 2021Read →
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.

Incident 2025Read →
Confirmed

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.

Incident 2024Read →
Confirmed

Lampion Banking Trojan ClickFix Campaign vs Portuguese Government, Finance and Transport Sectors

A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the Windows Run dialog, chaining through multiple obfuscated VBS stages before Unit 42 caught it with the final payload stage disabled.

Incident 2025Read →
Confirmed

NatWest "Vishing" Callback Fraud Costs Surrey Solicitor Karen Mackie £734,000 and Her Career

Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire £734,000 of client money to "safe" accounts, costing her nearly £512,000 unrecovered, her legal career, and ultimately her home and solvency.

Incident 2015Read →
Confirmed

Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)

A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1 million in bank wires (on top of stealing from his church, an investment club, and his own daughter) trying to chase fake returns, collapsing Heartland Tri-State Bank and drawing a 293-month federal sentence.

Incident 2022Read →
Confirmed

India-Based IRS/USCIS Impersonation Call-Center Takedown (U.S. v. HGlobal et al., 61 Defendants)

DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad, India call-center conglomerates for a 2012-2016 IRS/USCIS impersonation vishing scheme that threatened over 15,000 U.S. victims with arrest or deportation to extort payment via prepaid cards and wires.

Incident 2016Read →
Confirmed

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.

Incident 2020Read →
Confirmed

GootLoader SEO Poisoning of Legal Services Firms

GootLoader operators hijacked Google search rankings for legal-agreement phrases, luring law firm staff to fake forum "direct download" pages that delivered malicious JavaScript loaders, some of which escalated via Cobalt Strike into REvil ransomware attacks, a pattern CFC's Incident Response Team documented after seeing it hit multiple insured legal services firms.

Incident 2021Read →
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Incident 2015Read →
Confirmed

FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)

The FBI's 2025 Internet Crime Report introduced IC3's first-ever dedicated AI-fraud tracking section in its nearly 25-year history, logging 22,364 complaints and $893,346,472 in losses from scams using voice clones, deepfake video, fake AI-generated social profiles, and forged identification documents.

Incident 2025Read →
Confirmed

FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake video to make fraud schemes, including loved-one crisis scams and bank-account impersonation, more scalable and believable.

Incident 2024Read →
Confirmed

Crelan Bank CEO Fraud (Belgium, 2016)

Belgian bank Crelan lost close to EUR 70 million (~US$75.8M) after fraudsters impersonating its CEO induced internal staff to execute a series of unauthorized wire transfers, discovered via internal controls in January 2016.

Incident 2016Read →
Confirmed

DOJ files record $225.3M civil forfeiture against USDT laundered from pig-butchering crypto scams (2025)

In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a global pig-butchering money-laundering network, the largest crypto seizure in U.S. Secret Service history and the biggest tied to crypto confidence scams.

Incident 2025Read →
Confirmed

Deepfake Martin Lewis/Elon Musk Investment Scam Costs Brighton Man £76,000 via Fake Revolut Account "Carl"

A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out, after a Facebook ad using deepfaked video of Martin Lewis and Elon Musk lured him into a fake bitcoin investment run through a fraudulent Revolut account.

Incident 2023Read →
Confirmed

North Korea's 'Contagious Interview' ClickFix Fake Job-Assessment Campaign Targets Crypto Industry (2025)

Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms, then used a fabricated camera-driver error to trick applicants into pasting a 'fix' command into their terminal, installing backdoors like GolangGhost and FrostyFerret.

Incident 2025Read →
Confirmed

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.

Incident 2025Read →
Confirmed

GTG-1002: AI-Orchestrated Cyber-Espionage Campaign Run Through Claude Code (2025)

A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run 80-90% of an espionage campaign against roughly 30 global targets.

Incident 2025Read →
Confirmed

Anthem health-insurer breach (78.8M records)

A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that quietly stole personal data on 78.8 million people over the next 11 months.

Incident 2014Read →
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.

Incident 2025Read →
Confirmed

Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M

Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF, then pivoted to the Ronin bridge validator keys and drained roughly $540-625M in crypto.

Incident 2022Read →
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.

Incident 2022Read →
Confirmed

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.

Incident 2006Read →
Confirmed

Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.

Incident 2026Read →