Social Engineering Examples

Phishing Examples: 61 Real Attacks and How They Worked

Phishing is still the workhorse of social engineering — the fraudulent email behind the $120M Google and Facebook Rimasauskas fraud, the 2013 Target breach, and the Ubiquiti $46.7M wire fraud — usually impersonating a vendor, executive, or IT department to get someone to click, enter credentials, or wire money. The 61 cases below range from mass-market credential theft to nine-figure business email compromise, and each one names the lure, what it cost, and the specific check that would have caught it.


61 Cases
PH
Confirmed $3M

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved.

Incident 2022Read →
PH
Confirmed $39.1M

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.

Incident 2015Read →
PH
Confirmed

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.

Incident 2015Read →
PH
Confirmed $11M

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.

Incident 2018Read →
PH
Confirmed $18.6M

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls.

Incident 2018Read →
PH
Confirmed $37.5M

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent.

Incident 2019Read →
PH
Confirmed $23K

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.

Incident 2026Read →
PH
Confirmed

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors.

Incident 2010Read →
PH
Confirmed

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.

Incident 2013Read →
PH
Confirmed $17.2M

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.

Incident 2014Read →
PH
Confirmed

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.

Incident 2016Read →
PH
Confirmed

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan.

Incident 2016Read →
PH
Confirmed

Sony Pictures 'Guardians of Peace' hack: fake Apple ID emails to admins

North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.

Incident 2014Read →
PH
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.

Incident 2020Read →
PH
Confirmed

RSA SecurID Breach: The "2011 Recruitment Plan" Spear-Phishing Email (2011)

A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.

Incident 2011Read →
PH
Confirmed $111.6K

Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)

Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan.

Incident 2017Read →
PH
Confirmed $898.3K

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam executed with bank fraud.

Incident 2026Read →
PH
Confirmed

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).

Incident 2025Read →
PH
Confirmed $30.8K

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.

Incident 2024Read →
PH
Confirmed $15M

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes.

Incident 2023Read →
PH
Confirmed $122.1M

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.

Incident 2013Read →
PH
Confirmed $2.6M

Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)

A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account.

Incident 2020Read →
PH
Confirmed

Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms

Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.

Incident 2009Read →
PH
Confirmed $60M

Orion S.A. $60M fraudulently induced wire transfers (2024)

A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.

Incident 2024Read →
PH
Confirmed $21.5M

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.

Incident 2018Read →
PH
Confirmed $689.2K

School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)

Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.

Incident 2024Read →
PH
Confirmed $2.1M

Pine Bluff School District $3.2M Construction-Payment BEC (Thread-Hijack via Lookalike Vendor Domain)

Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.

Incident 2025Read →
PH
Confirmed

Pivotal Labs W-2 Phishing (CEO-Spoof), 2016

A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.

Incident 2016Read →
PH
Confirmed $6M

New Haven Public Schools $6M COO-email vendor thread-hijack BEC

Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.

Incident 2023Read →
PH
Confirmed $2.5M

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over $2.5 million.

Incident 2021Read →
PH
Confirmed

MacEwan University BEC Fraud

A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.

Incident 2017Read →
PH
Confirmed

Main Line Health W-2 Executive-Spoof Phishing Breach

A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to criminals.

Incident 2016Read →
PH
Confirmed $3.5M

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M.

Incident 2021Read →
PH
Confirmed

Mattel CEO-Fraud Wire ($3M, Recovered)

A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.

Incident 2015Read →
PH
Confirmed $4.8M

Medidata Solutions $4.8M CEO-Fraud Wire Transfer (2014)

Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.

Incident 2014Read →
PH
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.

Incident 2025Read →
PH
Confirmed $2.6M

Johnson County Schools $3.36M fake-Pearson vendor BEC

A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike.

Incident 2024Read →
PH
Confirmed $44.6M

Leoni AG CEO Fraud (2016)

Fraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.

Incident 2016Read →
PH
Confirmed

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers.

Incident 2005Read →
PH
Confirmed $794.9K

JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)

A fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend.

Incident 2026Read →
PH
Confirmed

GTIG Discloses PROMPTFLUX: First "Just-in-Time" Self-Obfuscating AI Malware Using the Gemini API

Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.

Incident 2025Read →
PH
Confirmed

GCI (Alaska telecom) W-2 phishing: CFO-spoof email drained 2,500+ employees' tax data

A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI.

Incident 2016Read →
PH
Confirmed

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.

Incident 2024Read →
PH
Confirmed $47M

FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier

Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project.

Incident 2016Read →
PH
Confirmed

Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload

A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL --.

Incident 2026Read →
PH
Confirmed $75.8M

Crelan Bank CEO Fraud (Belgium, 2016)

The Crelan Bank phishing attack: fraudsters impersonating the CEO tricked staff into wiring nearly €70M (~$75.8M) in Belgium's costliest CEO fraud case.

Incident 2016Read →
PH
Confirmed $63.4K

Dickinson Public Schools $4.9M Vendor-Impersonation BEC

Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.

Incident 2026Read →
PH
Confirmed

GRU 'Someone has your password' phishing of the DNC and Clinton campaign (2016)

Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.

Incident 2016Read →
PH
Confirmed $1.7M

Cabarrus County $1.7M vendor-impersonation BEC (2019)

Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.

Incident 2018Read →
PH
Confirmed

AA21-148A: Nobelium's USAID/Constant Contact Spearphishing Campaign

A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.

Incident 2021Read →
PH
Confirmed

CoHost's Near-Hire of a Fabricated AI Candidate with Deepfake-Mimicking References

Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose.

Incident 2026Read →
PH
Confirmed

Council on Foreign Relations Watering-Hole Attack (IE Zero-Day, CVE-2012-4792)

In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and drop malware.

Incident 2012Read →
PH
Confirmed

Anthem health-insurer breach (78.8M records)

A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data on 78.8 million people.

Incident 2014Read →
PH
Confirmed $540M

Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M

Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.

Incident 2022Read →
PH
Confirmed

Azure Monitor Alert Abuse TOAD Scam: Fake $459.90 Windows Defender Billing Notice Cleared as a False Positive

Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated.

Incident 2026Read →
PH
Confirmed $3M

Argan, Inc. $3M Phishing-Induced Wire Fraud (2023)

A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3 million pre-tax loss.

Incident 2023Read →
PH
Confirmed $480K

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank.

Incident 2014Read →
PH
Confirmed $6.2M

Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise

Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank.

Incident 2023Read →
PH
Confirmed

Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.

Incident 2026Read →
PH
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations.

Incident 2022Read →
PH
Confirmed

SEC Section 21(a) Report on Nine Issuers' Business Email Compromise Losses

SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public.

Incident 2018Read →

Executive and CEO Wire Fraud

Pathe's EUR19.2M fake-CEO cinema-chain fraud, Toyota Boshoku's $37M business email compromise, Scoular Company's $17.2M grain-trader wire fraud, FACC's ~EUR42M "fake president" fraud, and Orion S.A.'s $60M fraudulently induced wire transfers all used a spoofed or impersonated executive to authorize a payment nobody would otherwise approve.

Vendor and Invoice Impersonation

Evaldas Rimasauskas's $120M fraud against Google and Facebook, Unatrac Holding's $11M Caterpillar-export-office compromise, Tecnimont's $18.6M fraud with staged fake conference calls, and Pine Bluff School District's $3.2M construction-payment diversion all forged a trusted vendor's invoices or domain to redirect a real payment.

W-2 and Payroll Data Theft

Seagate's 2016 CEO-spoof W-2 breach, Snapchat's payroll phishing breach, GCI Alaska's CFO-spoof email that drained over 2,500 employees' tax data, and Main Line Health's W-2 executive-spoof breach all used a fake executive request to get HR or payroll staff to hand over employee tax records.

Nation-State and Espionage Phishing

Operation Aurora's Chinese state-linked campaign against Google and Adobe, the Sony Pictures "Guardians of Peace" hack via fake Apple ID emails, the 2011 RSA SecurID spear-phishing breach, and Google's 2010 disclosure of Gmail phishing against Chinese human-rights activists all used a targeted phishing email as the entry point for long-running espionage, not a quick payout.

Explore more

Browse the rest of the library

Techniques

How these attacks are carried out


Common questions
Spear phishing vs phishingSmishing vs phishingVishing vs phishingVishing vs smishingBaiting vs phishingPhishing vs pretextingQuishing vs phishingSmishing vs quishingPhishing vs spoofingPhishing vs pharming