Documented social engineering incidents targeting the healthcare sector, sourced and fact-checked.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.
ConfirmedA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.
ConfirmedA spoofed email impersonating a company executive tricked a Main Line Health employee into emailing the W-2 and personal data of all ~11,000 staff to criminals.
ConfirmedSpoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.
ConfirmedCalifornia's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured, publicly accessible dumpsters at 16 Kaiser Permanente facilities statewide, resulting in a $49 million settlement.
ConfirmedCVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities led to a $2.25M HHS settlement and a separate FTC consent order in 2009.
ConfirmedAn MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.
ConfirmedA single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that quietly stole personal data on 78.8 million people over the next 11 months.
ConfirmedA single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.
ConfirmedFraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank account under a bogus tax-refund pretext; Rs 22.31 crore was never recovered, and a second, separate business-email-compromise hit Alkem's Enzene Biosciences US subsidiary roughly 18 months later.