Social Engineering Examples

Help-Desk & MFA Manipulation: Real Attack Examples

Help-desk and MFA manipulation attacks don't bother with malware: an attacker calls IT support pretending to be a locked-out employee, or floods a target's phone with MFA push prompts until one gets approved out of fatigue. This family covers the run of 2021-2023 breaches, including Uber, EA, Caesars and Microsoft, that made this the defining enterprise social engineering pattern of its era.


8 Cases
HA
Confirmed $3M

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved.

Incident 2022Read →
HA
Confirmed

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.

Incident 2015Read →
HA
Confirmed

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.

Incident 2023Read →
HA
Confirmed

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.

Incident 2022Read →
HA
Alleged

Jaguar Land Rover Vishing-Triggered Shutdown

JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling itself.

Incident 2025Read →
HA
Confirmed

FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.

Incident 2006Read →
HA
Confirmed

EA Games Slack/MFA Social Engineering Breach (2021)

Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack.

Incident 2021Read →
HA
Confirmed $15M

Caesars Entertainment Vendor Social Engineering Breach (2023)

The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom in 2023.

Incident 2023Read →

Help-Desk Vishing Breaches

MGM Resorts, Caesars Entertainment, and Jaguar Land Rover were all breached after an attacker called IT support and talked a help-desk agent into resetting credentials or approving access for someone who was not who they claimed to be.

MFA Push-Bombing and Credential Fatigue

Uber in 2022 was breached after a contractor was flooded with MFA push prompts and eventually approved one out of fatigue, EA Games suffered a Slack and MFA social engineering breach the year before, and the Microsoft LAPSUS$/DEV-0537 source-code intrusion followed the same push-fatigue and social engineering pattern.

Critical Infrastructure and Regulatory Targets

The 2015 Ukraine power grid attack by Sandworm and BlackEnergy showed the same social engineering foothold techniques used against industrial control systems, while the FTC pretexting sweep against telephone record sellers showed regulators treating pretext-based access as a distinct enforcement priority.

Explore more

Browse the rest of the library

Techniques

How these attacks are carried out

Techniques used in this family