Sectors

Nonprofit & NGO

Documented social engineering incidents targeting the nonprofit & ngo sector, sourced and fact-checked.


10 Cases
Confirmed

Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)

Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan; insurance covered all but roughly $112,000.

Incident 2017Read →
Confirmed

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.

Incident 2024Read →
Confirmed

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.

Incident 2021Read →
Confirmed

Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)

A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1 million in bank wires (on top of stealing from his church, an investment club, and his own daughter) trying to chase fake returns, collapsing Heartland Tri-State Bank and drawing a 293-month federal sentence.

Incident 2022Read →
Confirmed

Google Discloses Chinese Human-Rights-Activist Gmail Phishing/Malware Compromises (2010)

In the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to human-rights activists in the US, China, and Europe had been "routinely accessed by third parties, most likely via phishing scams or malware," a separate, longer-running espionage campaign against individual activists, distinct from the corporate network intrusion.

Incident 2010Read →
Confirmed

Greenpeace v. Dow Chemical / Sasol Corporate Espionage ("D-Lines")

Dow Chemical and Sasol paid PR firms Ketchum and Dezenhall, who subcontracted private intelligence firm Beckett Brown International to run over 120 dumpster-diving raids on Greenpeace's DC offices between July 1998 and July 2000, including using a bribed/subcontracted DC police officer's badge to bypass a locked trash enclosure.

Incident 1998Read →
Confirmed

GRU 'Someone has your password' phishing of the DNC and Clinton campaign (2016)

Russian GRU officers spoofed Google security-alert emails with Bitly-masked links to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails after an IT aide's fateful 'legitimate' typo.

Incident 2016Read →
Confirmed

AA21-148A: Nobelium's USAID/Constant Contact Spearphishing Campaign

A compromised Constant Contact mass-mailing account let Russia-linked Nobelium (APT29) send USAID-spoofed phishing emails that funneled roughly 3,000-7,000 accounts across 150-350 government, IGO, and NGO organizations toward an ISO-file/Cobalt Strike infection chain, prompting a joint CISA/FBI advisory (AA21-148A) and a DOJ domain seizure.

Incident 2021Read →
Confirmed

Council on Foreign Relations Watering-Hole Attack (IE Zero-Day, CVE-2012-4792)

In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and drop malware on the browsers of its policy-elite visitors.

Incident 2012Read →
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.

Incident 2025Read →