Phishing is still the workhorse of social engineering — the fraudulent email behind the $120M Google and Facebook Rimasauskas fraud, the 2013 Target breach, and the Ubiquiti $46.7M wire fraud — usually impersonating a vendor, executive, or IT department to get someone to click, enter credentials, or wire money. The 61 cases below range from mass-market credential theft to nine-figure business email compromise, and each one names the lure, what it cost, and the specific check that would have caught it.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved.
PHFraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
PHRussia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
PHA phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
PHFraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls.
PHA European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent.
PHA caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
PHA nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors.
PHA mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
PHImpostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
PHA spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
PHA Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan.
PHNorth Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
PHA federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
PHA single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
PHAttackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan.
PHA small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam executed with bank fraud.
PHGoogle's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
PHA compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
PHA smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes.
PHEvaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
PHA forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account.
PHChinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
PHA non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
PHFraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.
PHImpersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
PHScammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.
PHA fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.
PHAttackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
PHA Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over $2.5 million.
PHA spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
PHA spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to criminals.
PHA four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M.
PHA Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
PHSpoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
PHA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
PHA Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike.
PHFraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.
PHTo unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers.
PHA fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend.
PHGoogle's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.
PHA scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI.
PHFTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
PHFraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project.
PHA convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL --.
PHThe Crelan Bank phishing attack: fraudsters impersonating the CEO tricked staff into wiring nearly €70M (~$75.8M) in Belgium's costliest CEO fraud case.
PHCriminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
PHRussian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
PHScammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
PHA compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
PHToronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose.
PHIn late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and drop malware.
PHA single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data on 78.8 million people.
PHLazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.
PHAttackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated.
PHA complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3 million pre-tax loss.
PHA fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank.
PHFraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank.
PHAn interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
PHA single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations.
PHSEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public.
Pathe's EUR19.2M fake-CEO cinema-chain fraud, Toyota Boshoku's $37M business email compromise, Scoular Company's $17.2M grain-trader wire fraud, FACC's ~EUR42M "fake president" fraud, and Orion S.A.'s $60M fraudulently induced wire transfers all used a spoofed or impersonated executive to authorize a payment nobody would otherwise approve.
Evaldas Rimasauskas's $120M fraud against Google and Facebook, Unatrac Holding's $11M Caterpillar-export-office compromise, Tecnimont's $18.6M fraud with staged fake conference calls, and Pine Bluff School District's $3.2M construction-payment diversion all forged a trusted vendor's invoices or domain to redirect a real payment.
Seagate's 2016 CEO-spoof W-2 breach, Snapchat's payroll phishing breach, GCI Alaska's CFO-spoof email that drained over 2,500 employees' tax data, and Main Line Health's W-2 executive-spoof breach all used a fake executive request to get HR or payroll staff to hand over employee tax records.
Operation Aurora's Chinese state-linked campaign against Google and Adobe, the Sony Pictures "Guardians of Peace" hack via fake Apple ID emails, the 2011 RSA SecurID spear-phishing breach, and Google's 2010 disclosure of Gmail phishing against Chinese human-rights activists all used a targeted phishing email as the entry point for long-running espionage, not a quick payout.