Documented social engineering incidents targeting the hospitality, gaming & travel sector, sourced and fact-checked.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified family-tie claim, then was found carrying a USB drive initially flagged as containing malware, a determination prosecutors later said may have been a false positive, along with four phones, over $7,600 cash, and a hidden-camera detector.
ConfirmedA federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.
ConfirmedA roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize identity-system control, and trigger an outage MGM valued at about $100 million.
ConfirmedFIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.
ConfirmedDOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.
ConfirmedAttackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since identified in litigation as Coforge, into resetting credentials, stole the Caesars Rewards loyalty database (SSNs and driver's license numbers), and Caesars reportedly paid roughly $15 million to keep the data private. It was disclosed in an SEC 8-K days before the parallel MGM Resorts breach by the same actor.
ConfirmedA single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials, giving an unauthorized actor a foothold that led to the theft of personal data on nearly 6 million people.
ConfirmedLazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF, then pivoted to the Ronin bridge validator keys and drained roughly $540-625M in crypto.