Documented social engineering incidents targeting the government & public sector sector, sourced and fact-checked.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting, and the resulting exposé triggered FTC enforcement, congressional hearings, and the 2006 federal law criminalizing pretexting for phone records.
ConfirmedA Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified family-tie claim, then was found carrying a USB drive initially flagged as containing malware, a determination prosecutors later said may have been a false positive, along with four phones, over $7,600 cash, and a hidden-camera detector.
ConfirmedA Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running PowerShell themselves, deploying a rarely-seen infostealer Proofpoint dubbed suspected "Lucky Volunteer" in activity assessed to overlap with the Russia-linked espionage actor UAC-0050.
ConfirmedFraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset, tricking drivers into paying "parking fees" on cloned sites that harvested full card details or signed them up for hidden subscriptions.
ConfirmedCensys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames behind a WebSocket-based backend that streamed victims' card data in real time and included an operator kill-switch, a concrete technical case of the package-delivery smishing wave USPS itself had flagged as rising in June 2025.
ConfirmedA nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors, then physically destroyed roughly 1,000 uranium centrifuges.
ConfirmedAn unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles, texting and calling senators, governors and business leaders with requests including a pardon list and a cash transfer, triggering an FBI investigation.
ConfirmedA mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and personal data, drawing 2,000+ FBI complaints within weeks of an April 2024 IC3 alert and continuing into 2025; the underlying 'Lighthouse' phishing kit was targeted by a Google civil lawsuit in November 2025.
ConfirmedA Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.
ConfirmedA Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake AI-generated Zoom "government meeting" that appeared to feature PM Lawrence Wong and other senior officials.
ConfirmedGoogle's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging Face API) at runtime to dynamically generate the Windows recon and data-theft commands it then executes against Ukrainian government targets, the first publicly documented malware to call an LLM live in operations.
ConfirmedA compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.
ConfirmedScammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned them to a phishing site that harvested personal and payment information.
ConfirmedImpersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000 into fraud accounts; the loss surfaced only during the annual city audit.
ConfirmedA forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account in January 2020.
ConfirmedAttackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to swap in their own bank account, and diverted about $6M in city funds.
ConfirmedA Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing a fake SBI/Finance-Ministry-linked investment scheme, with WhatsApp callers from a UK number then upselling him into repeated transfers.
ConfirmedAn Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their late spouse's policy was "in arrears" and draining over $100,000 from them via prepaid gift cards, while separately hiding that income to keep collecting SSI, Medicaid, and HUD housing assistance.
ConfirmedA Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.
ConfirmedA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.
ConfirmedA spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders, tricked staff into redirecting $11.8 million CAD in construction payments to fraudulent bank accounts in Montreal and Hong Kong, one of the largest publicly documented BEC losses at a North American university.
ConfirmedA Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike "pearson.quest" domain.
ConfirmedA revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the Windows Run dialog, chaining through multiple obfuscated VBS stages before Unit 42 caught it with the final payload stage disabled.
ConfirmedDOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad, India call-center conglomerates for a 2012-2016 IRS/USCIS impersonation vishing scheme that threatened over 15,000 U.S. victims with arrest or deportation to extort payment via prepaid cards and wires.
ConfirmedTejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.
ConfirmedBetween 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.
ConfirmedRussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.
ConfirmedThe FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes to steal credentials or install malware.
ConfirmedFTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.
ConfirmedBetween 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.
ConfirmedCriminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district; the FBI and U.S. Attorney's Office later seized about $4.86M.
ConfirmedRussian GRU officers spoofed Google security-alert emails with Bitly-masked links to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails after an IT aide's fateful 'legitimate' typo.
ConfirmedA malware-laden USB flash drive plugged into a laptop at a U.S. military base in the Middle East in 2008 let the agent.btz worm crawl onto classified SIPRNet systems, triggering the Pentagon's largest-ever cleanup and helping spur creation of U.S. Cyber Command.
ConfirmedScammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County, NC wired $2.5M to the fraud account, losing $1.73M net.
ConfirmedA long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens of thousands of Canadians with arrest or deportation over fake tax debts, stealing tens of millions of dollars before RCMP's Project OCTAVIA and Indian police raids on roughly 39-40 call centres, plus Canadian money-mule prosecutions, disrupted the operation.
ConfirmedDOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.
ConfirmedA compromised Constant Contact mass-mailing account let Russia-linked Nobelium (APT29) send USAID-spoofed phishing emails that funneled roughly 3,000-7,000 accounts across 150-350 government, IGO, and NGO organizations toward an ISO-file/Cobalt Strike infection chain, prompting a joint CISA/FBI advisory (AA21-148A) and a DOJ domain seizure.
ConfirmedIn late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and drop malware on the browsers of its policy-elite visitors.
ConfirmedA suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run 80-90% of an espionage campaign against roughly 30 global targets.
ConfirmedA single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.
ConfirmedAn interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.
ConfirmedHours before Maharashtra's 2024 assembly election polling, BJP-amplified audio clips purporting to catch opposition leaders Supriya Sule and Nana Patole discussing a bitcoin-funded election bribery scheme were independently forensically confirmed as substantially AI-generated voice clones.