Sectors

Manufacturing & Industrial

Documented social engineering incidents targeting the manufacturing & industrial sector, sourced and fact-checked.


22 Cases
Confirmed

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then used the live CFO mailbox to send about 15 fake-invoice wire requests over nine days, draining nearly $11 million overseas.

Incident 2018Read →
Confirmed

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent payment-change instructions.

Incident 2019Read →
Confirmed

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.

Incident 2013Read →
Confirmed

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.

Incident 2018Read →
Confirmed

Tennant Co. v. Advance Machine Co. - Dumpster Diving / Conversion Punitive Damages Verdict

Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads, and Advance's mishandling of the discovery led a Minnesota jury (and, on appeal, the Minnesota Court of Appeals) to impose $500,000 in combined compensatory and reinstated punitive damages, a landmark early US ruling that trash retains a protectable privacy/property interest against competitor theft.

Incident 1978Read →
Confirmed

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he wired $17.2M in three tranches to a Shanghai account.

Incident 2014Read →
Confirmed

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs and earnings for several thousand US employees.

Incident 2016Read →
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Incident 2020Read →
Confirmed

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.

Incident 2026Read →
Confirmed

Pune Italian Engineering Firm CFO Microsoft Teams Boss-Scam (Rs 56 Lakh Loss, 2026)

A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO's name and photo demanded an urgent transfer, then caught the fraud only when a follow-up Rs 1.5 crore ask prompted her to call the real CEO.

Incident 2026Read →
Confirmed

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.

Incident 2013Read →
Confirmed

Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms

Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.

Incident 2009Read →
Confirmed

Orion S.A. $60M fraudulently induced wire transfers (2024)

A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M to attacker-controlled accounts, with no system or data breach involved.

Incident 2024Read →
Confirmed

Naresh Gujral WhatsApp CEO-Impersonation Fraud (2026)

Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display photo of former Rajya Sabha MP Naresh Gujral, and impersonated him to his company's finance staff to push through four RTGS transfers totaling Rs 7.68 crore before Delhi Police froze roughly Rs 4.28 crore and arrested one mule-account holder.

Incident 2026Read →
Confirmed

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.

Incident 2021Read →
Confirmed

Leoni AG CEO Fraud (2016)

Fraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40 million (about US$44.6 million) to attacker-controlled accounts in August 2016.

Incident 2016Read →
Confirmed

JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)

A fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend, diverting USD 794,934.04 away from DTC and delaying payment to shareholders.

Incident 2026Read →
Alleged

Jaguar Land Rover Vishing-Triggered Shutdown

JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling itself "Scattered Lapsus$ Hunters", but a June 2026 New York Times investigation, backed by JLR's own then-CISO, instead points to Russian hackers who exploited aging technology and deployed novel ransomware, with no social engineering involved, plus a separate, earlier and unrelated intrusion by a Jordanian hacker.

Incident 2025Read →
Confirmed

Greenpeace v. Dow Chemical / Sasol Corporate Espionage ("D-Lines")

Dow Chemical and Sasol paid PR firms Ketchum and Dezenhall, who subcontracted private intelligence firm Beckett Brown International to run over 120 dumpster-diving raids on Greenpeace's DC offices between July 1998 and July 2000, including using a bribed/subcontracted DC police officer's badge to bypass a locked trash enclosure.

Incident 1998Read →
Confirmed

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.

Incident 2021Read →
Confirmed

GTG-1002: AI-Orchestrated Cyber-Espionage Campaign Run Through Claude Code (2025)

A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run 80-90% of an espionage campaign against roughly 30 global targets.

Incident 2025Read →
Confirmed

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.

Incident 2014Read →