Help-desk and MFA manipulation attacks don't bother with malware: an attacker calls IT support pretending to be a locked-out employee, or floods a target's phone with MFA push prompts until one gets approved out of fatigue. This family covers the run of 2021-2023 breaches, including Uber, EA, Caesars and Microsoft, that made this the defining enterprise social engineering pattern of its era.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved, opening the door to Uber's internal network.
HARussia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities, harvesting credentials that let them remotely open substation breakers and cut power to about 225,000 customers, marking the first confirmed cyberattack to cause a real-world blackout.
HAA roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize identity-system control, and trigger an outage MGM valued at about $100 million.
HAA single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group exfiltrated and publicly leaked roughly 37GB of partial source code for Bing, Bing Maps, and Cortana in March 2022, part of a wider spree in which the group used MFA push-bombing, SIM swaps, and paid-for insider MFA approvals to breach well-defended tech companies.
HAJLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling itself "Scattered Lapsus$ Hunters", but a June 2026 New York Times investigation, backed by JLR's own then-CISO, instead points to Russian hackers who exploited aging technology and deployed novel ransomware, with no social engineering involved, plus a separate, earlier and unrelated intrusion by a Jordanian hacker.
HABetween 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.
HAHackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack, then twice talked EA IT support into issuing a fresh MFA token by claiming a lost phone, then walked straight into EA's network and out with ~780GB including FIFA 21 and Frostbite engine source code.
HAAttackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since identified in litigation as Coforge, into resetting credentials, stole the Caesars Rewards loyalty database (SSNs and driver's license numbers), and Caesars reportedly paid roughly $15 million to keep the data private. It was disclosed in an SEC 8-K days before the parallel MGM Resorts breach by the same actor.