Threat Actors

Organized Crime

Documented cases attributed to organized crime threat actors, sourced and fact-checked.


55 Cases
Confirmed

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting, and the resulting exposé triggered FTC enforcement, congressional hearings, and the 2006 federal law criminalizing pretexting for phone records.

Incident 2005Read →
Confirmed

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake crypto trading platform, NanoBit, wiring over $2 million to Hong Kong before the SEC secured a $5.5 million default judgment in one of its first pig-butchering enforcement actions.

Incident 2023Read →
Confirmed

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved, opening the door to Uber's internal network.

Incident 2022Read →
Confirmed

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset, tricking drivers into paying "parking fees" on cloned sites that harvested full card details or signed them up for hidden subscriptions.

Incident 2024Read →
Confirmed

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then used the live CFO mailbox to send about 15 fake-invoice wire requests over nine days, draining nearly $11 million overseas.

Incident 2018Read →
Confirmed

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames behind a WebSocket-based backend that streamed victims' card data in real time and included an operator kill-switch, a concrete technical case of the package-delivery smishing wave USPS itself had flagged as rising in June 2025.

Incident 2026Read →
Confirmed

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.

Incident 2018Read →
Confirmed

Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

A mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and personal data, drawing 2,000+ FBI complaints within weeks of an April 2024 IC3 alert and continuing into 2025; the underlying 'Lighthouse' phishing kit was targeted by a Google civil lawsuit in November 2025.

Incident 2024Read →
Confirmed

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he wired $17.2M in three tranches to a Shanghai account.

Incident 2014Read →
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Incident 2020Read →
Confirmed

Singapore Anti-Scam Centre / Police Impersonation Scam: "Jane" Loses S$1.2 Million (2024-2025)

A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre officer and then police "Inspector Chong" convinced her she was linked to money laundering, coaching her to lie to the real Anti-Scam Centre and extracting funds via bank transfers and four in-person cash handoffs.

Incident 2024Read →
Confirmed

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake AI-generated Zoom "government meeting" that appeared to feature PM Lawrence Wong and other senior officials.

Incident 2026Read →
Confirmed

SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)

SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South Africa's major banks: digital banking losses rose from roughly R1.08bn (2023, including R625.7m in banking-app fraud alone) to R1.888bn (2024, +74%), with SABRIC explicitly attributing the rise to social engineering rather than technical hacks, while a widely circulated "R3.9bn in 2025" figure and claim of a single four-bank joint alert could not be verified against any primary SABRIC or bank source.

Incident 2023Read →
Confirmed

Roger Roger's Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+

Costa Rica-based telemarketing ringleader Roger Roger used VOIP-spoofed Washington D.C. caller ID and fake government-official personas to convince hundreds of mostly elderly U.S. victims they had won sweepstakes prizes, bilking them of over $4 million before advance-fee "taxes and fees" demands. He was convicted at trial in 2024 and sentenced to over 15 years in 2025.

Incident 2014Read →
Confirmed

San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)

A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad, while a San Diego federal grand jury indicted alleged Ko Thet Company manager/recruiter Thet Min Nyi ("Pixy") and criminal complaints charged three others tied to the Sanduo Group and Giant Company networks.

Incident 2026Read →
Confirmed

Quebec AI-Assisted "Grandparent Scam" Ring: Teodor/Condurache Sentenced After Targeting Saskatchewan Seniors

Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors of tens of thousands of dollars were sentenced in Regina provincial court, with the judge explicitly finding AI was used to mimic victims' grandchildren's voices and calling lead defendant Ciprian Teodor "the human face of an otherwise faceless, AI-driven fraud."

Incident 2025Read →
Confirmed

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.

Incident 2013Read →
Confirmed

Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into receiving "maintenance"/upgrade-related SMS one-time PINs that he intercepted to fraudulently buy and reroute high-end phones for offshore resale, netting more than AUD $1 million in seized cash before his November 2024 arrest.

Incident 2023Read →
Confirmed

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition, costing two executives their jobs.

Incident 2018Read →
Confirmed

Naresh Gujral WhatsApp CEO-Impersonation Fraud (2026)

Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display photo of former Rajya Sabha MP Naresh Gujral, and impersonated him to his company's finance staff to push through four RTGS transfers totaling Rs 7.68 crore before Delhi Police froze roughly Rs 4.28 crore and arrested one mule-account holder.

Incident 2026Read →
Confirmed

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.

Incident 2014Read →
Confirmed

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.

Incident 2021Read →
Confirmed

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.

Incident 2021Read →
Confirmed

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize identity-system control, and trigger an outage MGM valued at about $100 million.

Incident 2023Read →
Confirmed

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group exfiltrated and publicly leaked roughly 37GB of partial source code for Bing, Bing Maps, and Cortana in March 2022, part of a wider spree in which the group used MFA push-bombing, SIM swaps, and paid-for insider MFA approvals to breach well-defended tech companies.

Incident 2022Read →
Confirmed

Los Cyber Bank-Impersonation Vishing Network Dismantled in Colombia

A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers, talked mostly over-50 victims into sharing their phone screens, and drained COP 1.685 billion from 94 people across 10 departments before a joint Fiscalia-Policia Nacional operation captured the group, including alleged leader alias "Ralf."

Incident 2025Read →
Confirmed

Lampion Banking Trojan ClickFix Campaign vs Portuguese Government, Finance and Transport Sectors

A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the Windows Run dialog, chaining through multiple obfuscated VBS stages before Unit 42 caught it with the final payload stage disabled.

Incident 2025Read →
Confirmed

Johor Baru Retired Bank Manager Macau Scam (RM936,000)

A retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively as an insurance agent, a police officer, and a deputy public prosecutor convinced her to open a new bank account, transfer her savings into it, and hand over her online banking credentials "for investigation," only for the funds to be drained before she discovered the theft on 15 May 2026.

Incident 2026Read →
Confirmed

NatWest "Vishing" Callback Fraud Costs Surrey Solicitor Karen Mackie £734,000 and Her Career

Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire £734,000 of client money to "safe" accounts, costing her nearly £512,000 unrecovered, her legal career, and ultimately her home and solvency.

Incident 2015Read →
Confirmed

Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)

A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1 million in bank wires (on top of stealing from his church, an investment club, and his own daughter) trying to chase fake returns, collapsing Heartland Tri-State Bank and drawing a 293-month federal sentence.

Incident 2022Read →
Confirmed

India-Based IRS/USCIS Impersonation Call-Center Takedown (U.S. v. HGlobal et al., 61 Defendants)

DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad, India call-center conglomerates for a 2012-2016 IRS/USCIS impersonation vishing scheme that threatened over 15,000 U.S. victims with arrest or deportation to extort payment via prepaid cards and wires.

Incident 2016Read →
Confirmed

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.

Incident 2020Read →
Confirmed

Hamilton Academical FC £989,000 Vishing Fraud (RBS Bank Impersonation)

Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's sole authorised banking employee into moving nearly £1 million into 26 "safe" accounts over two days in October 2017, netting roughly £800,000 after partial recovery and triggering a club lawsuit against the bank over its duty of care.

Incident 2017Read →
Confirmed

GootLoader and SocGholish Dual Campaign Against Six Law Firms (2023)

eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns: SEO-poisoned fake "agreement" downloads delivering GootLoader, and a compromised Notary Public website serving a fake Chrome update to deliver SocGholish.

Incident 2023Read →
Confirmed

GootLoader SEO Poisoning of Legal Services Firms

GootLoader operators hijacked Google search rankings for legal-agreement phrases, luring law firm staff to fake forum "direct download" pages that delivered malicious JavaScript loaders, some of which escalated via Cobalt Strike into REvil ransomware attacks, a pattern CFC's Incident Response Team documented after seeing it hit multiple insured legal services firms.

Incident 2021Read →
Confirmed

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.

Incident 2020Read →
Confirmed

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.

Incident 2024Read →
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Incident 2015Read →
Confirmed

FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.

Incident 2006Read →
Confirmed

EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme

A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used to defraud five US victims of over $10 million after grooming them via dating apps, social media, and messaging platforms.

Incident 2022Read →
Confirmed

Crelan Bank CEO Fraud (Belgium, 2016)

Belgian bank Crelan lost close to EUR 70 million (~US$75.8M) after fraudsters impersonating its CEO induced internal staff to execute a series of unauthorized wire transfers, discovered via internal controls in January 2016.

Incident 2016Read →
Confirmed

DOJ files record $225.3M civil forfeiture against USDT laundered from pig-butchering crypto scams (2025)

In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a global pig-butchering money-laundering network, the largest crypto seizure in U.S. Secret Service history and the biggest tied to crypto confidence scams.

Incident 2025Read →
Confirmed

Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)

A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild, closers posed as defense attorneys, police, or court staff, and in-person couriers collected cash, bilking hundreds of elderly Americans out of millions of dollars.

Incident 2019Read →
Confirmed

Caesars Entertainment Vendor Social Engineering Breach (2023)

Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since identified in litigation as Coforge, into resetting credentials, stole the Caesars Rewards loyalty database (SSNs and driver's license numbers), and Caesars reportedly paid roughly $15 million to keep the data private. It was disclosed in an SEC 8-K days before the parallel MGM Resorts breach by the same actor.

Incident 2023Read →
Confirmed

Carnival Corporation Employee Vishing Breach (2026)

A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials, giving an unauthorized actor a foothold that led to the theft of personal data on nearly 6 million people.

Incident 2026Read →
Confirmed

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.

Incident 2025Read →
Confirmed

Citizens Disability SSDI Impersonation/Robocall Scheme

DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls, including 25.7 million-plus to Do-Not-Call Registry numbers, using robocalls voiced by "Amber" or "Audrey" that falsely told consumers they were following up on the consumer's own SSDI eligibility inquiry.

Incident 2019Read →
Confirmed

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.

Incident 2023Read →
Confirmed

CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens of thousands of Canadians with arrest or deportation over fake tax debts, stealing tens of millions of dollars before RCMP's Project OCTAVIA and Indian police raids on roughly 39-40 call centres, plus Canadian money-mule prosecutions, disrupted the operation.

Incident 2014Read →
Confirmed

Austin "Pig Butchering" Courier Arrest - $1.4M DAIQ Crypto Investment Scam

A Taiwan-linked money courier was caught in an Austin bank sting after helping collect part of the $1,408,850 a local victim lost over six months to a "pig butchering" romance-investment scam run through the LINE app and a fake "DAIQ" crypto trading platform.

Incident 2025Read →
Confirmed

Abubakari Twins / Ohio $15M AI-Driven Romance Fraud Ring

DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used fictitious female personas to defraud 130+ older Americans of $15 million+ between 2024 and 2026.

Incident 2024Read →
Confirmed

Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.

Incident 2026Read →
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.

Incident 2022Read →
Confirmed

Abu Trica AI Romance Scam Network (Kumi & Yussif) - $8M+ Elder Fraud, Northern District of Ohio

Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network that allegedly used AI-generated personas and AI-driven video platforms to defraud 80+ elderly Americans of more than $8 million between 2023 and 2025.

Incident 2023Read →
Confirmed

Gootloader Returns After 7-Month Hiatus: SEO Poisoning, Glyph-Swapped Fonts, and a Dual-Personality Malformed ZIP (2025)

After going quiet on March 31, 2025 following a researcher's disruption campaign, Gootloader returned on November 5, 2025 with a glyph-swapping WOFF2 web font to hide malicious filenames and a malformed ZIP archive that extracts a working JScript loader in Windows Explorer but a harmless decoy in 7-Zip, Python, or VirusTotal - spread across 100+ SEO-poisoned sites and thousands of keywords, feeding the Supper SOCKS5 backdoor and, via Storm-0494/Vanilla Tempest, ransomware deployment.

Incident 2025Read →