Social Engineering Examples

Phishing

Phishing is still the workhorse of social engineering: a fraudulent email, often impersonating a vendor, executive or IT department, designed to get someone to click, enter credentials, or wire money. The 62 cases below range from mass-market credential theft to nine-figure business email compromise, and each one names the lure, what it cost, and the specific check that would have caught it.


62 Cases
PH
Confirmed

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved, opening the door to Uber's internal network.

Incident 2022Read →
PH
Confirmed $46.7M

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad in 14 transfers over two weeks.

Incident 2015Read →
PH
Confirmed

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities, harvesting credentials that let them remotely open substation breakers and cut power to about 225,000 customers, marking the first confirmed cyberattack to cause a real-world blackout.

Incident 2015Read →
PH
Confirmed $11M

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then used the live CFO mailbox to send about 15 fake-invoice wire requests over nine days, draining nearly $11 million overseas.

Incident 2018Read →
PH
Confirmed

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.

Incident 2013Read →
PH
Confirmed $18.6M

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.

Incident 2018Read →
PH
Confirmed $37M

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent payment-change instructions.

Incident 2019Read →
PH
Confirmed

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to a "safe" Capitec account, with three transfers completed within 20 minutes; Standard Bank's own investigation attributed the loss to vishing while denying any breach of its systems, and the case has been escalated to the National Financial Ombud and North West police.

Incident 2026Read →
PH
Confirmed

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors, then physically destroyed roughly 1,000 uranium centrifuges.

Incident 2010Read →
PH
Confirmed $17.2M

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he wired $17.2M in three tranches to a Shanghai account.

Incident 2014Read →
PH
Confirmed

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs and earnings for several thousand US employees.

Incident 2016Read →
PH
Confirmed

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan Spiegel's identity, part of a nationwide spring-2016 wave of spoofed-executive W-2 phishing that prompted an IRS public alert.

Incident 2016Read →
PH
Confirmed

Sony Pictures 'Guardians of Peace' hack: fake Apple ID emails to admins

North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated wiper malware that crippled the studio.

Incident 2014Read →
PH
Confirmed $25M

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Incident 2020Read →
PH
Confirmed

RSA SecurID Breach: The "2011 Recruitment Plan" Spear-Phishing Email (2011)

A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to the theft of SecurID data later used to attack defense contractor Lockheed Martin.

Incident 2011Read →
PH
Confirmed $1M

Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)

Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan; insurance covered all but roughly $112,000.

Incident 2017Read →
PH
Confirmed $898.3K

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.

Incident 2026Read →
PH
Confirmed

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging Face API) at runtime to dynamically generate the Windows recon and data-theft commands it then executes against Ukrainian government targets, the first publicly documented malware to call an LLM live in operations.

Incident 2025Read →
PH
Confirmed $220K

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.

Incident 2024Read →
PH
Confirmed $15M

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes, letting attackers exploit Google Authenticator cloud sync to take over 27 crypto customer accounts and steal ~$15M.

Incident 2023Read →
PH
Confirmed $120M

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.

Incident 2013Read →
PH
Confirmed

Pivotal Labs W-2 Phishing (CEO-Spoof), 2016

A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.

Incident 2016Read →
PH
Confirmed $2.6M

Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)

A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account in January 2020.

Incident 2020Read →
PH
Confirmed

Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms

Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.

Incident 2009Read →
PH
Confirmed $60M

Orion S.A. $60M fraudulently induced wire transfers (2024)

A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M to attacker-controlled accounts, with no system or data breach involved.

Incident 2024Read →
PH
Confirmed

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition, costing two executives their jobs.

Incident 2018Read →
PH
Confirmed $700K

School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)

Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000 into fraud accounts; the loss surfaced only during the annual city audit.

Incident 2024Read →
PH
Confirmed $3.2M

Pine Bluff School District $3.2M Construction-Payment BEC (Thread-Hijack via Lookalike Vendor Domain)

Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect, then used a lookalike "easthardings.com" domain to redirect a $3.2M construction payment to accounts they controlled.

Incident 2025Read →
PH
Confirmed $6M

New Haven Public Schools $6M COO-email vendor thread-hijack BEC

Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to swap in their own bank account, and diverted about $6M in city funds.

Incident 2023Read →
PH
Confirmed $2.5M

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.

Incident 2021Read →
PH
Confirmed $11.8M

MacEwan University BEC Fraud

A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders, tricked staff into redirecting $11.8 million CAD in construction payments to fraudulent bank accounts in Montreal and Hong Kong, one of the largest publicly documented BEC losses at a North American university.

Incident 2017Read →
PH
Confirmed

Main Line Health W-2 Executive-Spoof Phishing Breach

A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing the W-2 and personal data of all ~11,000 staff to criminals.

Incident 2016Read →
PH
Confirmed $3.5M

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.

Incident 2021Read →
PH
Confirmed $3M

Mattel CEO-Fraud Wire ($3M, Recovered)

A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO, and the company clawed it back within days thanks to a Chinese bank holiday and an FBI letter.

Incident 2015Read →
PH
Confirmed $4.8M

Medidata Solutions $4.8M CEO-Fraud Wire Transfer (2014)

Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.

Incident 2014Read →
PH
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.

Incident 2025Read →
PH
Confirmed $3.4M

Johnson County Schools $3.36M fake-Pearson vendor BEC

A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike "pearson.quest" domain.

Incident 2024Read →
PH
Confirmed $44.6M

Leoni AG CEO Fraud (2016)

Fraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40 million (about US$44.6 million) to attacker-controlled accounts in August 2016.

Incident 2016Read →
PH
Confirmed

JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)

A fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend, diverting USD 794,934.04 away from DTC and delaying payment to shareholders.

Incident 2026Read →
PH
Confirmed

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.

Incident 2005Read →
PH
Confirmed

GTIG Discloses PROMPTFLUX: First "Just-in-Time" Self-Obfuscating AI Malware Using the Gemini API

Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite and re-obfuscate its own source code hourly, making it the first documented "just-in-time" self-modifying AI malware, though GTIG assessed it as an experimental, not-yet-operational prototype.

Incident 2025Read →
PH
Confirmed

GCI (Alaska telecom) W-2 phishing: CFO-spoof email drained 2,500+ employees' tax data

A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI, Denali Media, UUI and Unicom worker.

Incident 2016Read →
PH
Confirmed

Google Discloses Chinese Human-Rights-Activist Gmail Phishing/Malware Compromises (2010)

In the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to human-rights activists in the US, China, and Europe had been "routinely accessed by third parties, most likely via phishing scams or malware," a separate, longer-running espionage campaign against individual activists, distinct from the corporate network intrusion.

Incident 2010Read →
PH
Confirmed $223M

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.

Incident 2024Read →
PH
Confirmed

FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier

Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project; EUR 41.9M was lost and both the CEO and CFO were later fired.

Incident 2016Read →
PH
Confirmed

Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload

A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL -- used malvertising and SEO poisoning to push Windows visitors to a credential-stealing loader and Mac visitors to Odyssey Stealer (an AMOS/Atomic Stealer fork) that also swapped in trojanized Ledger and Trezor wallet apps.

Incident 2026Read →
PH
Confirmed $75.8M

Crelan Bank CEO Fraud (Belgium, 2016)

Belgian bank Crelan lost close to EUR 70 million (~US$75.8M) after fraudsters impersonating its CEO induced internal staff to execute a series of unauthorized wire transfers, discovered via internal controls in January 2016.

Incident 2016Read →
PH
Confirmed $4.9M

Dickinson Public Schools $4.9M Vendor-Impersonation BEC

Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district; the FBI and U.S. Attorney's Office later seized about $4.86M.

Incident 2026Read →
PH
Confirmed

GRU 'Someone has your password' phishing of the DNC and Clinton campaign (2016)

Russian GRU officers spoofed Google security-alert emails with Bitly-masked links to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails after an IT aide's fateful 'legitimate' typo.

Incident 2016Read →
PH
Confirmed $2.5M

Cabarrus County $1.7M vendor-impersonation BEC (2019)

Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County, NC wired $2.5M to the fraud account, losing $1.73M net.

Incident 2018Read →
PH
Confirmed

AA21-148A: Nobelium's USAID/Constant Contact Spearphishing Campaign

A compromised Constant Contact mass-mailing account let Russia-linked Nobelium (APT29) send USAID-spoofed phishing emails that funneled roughly 3,000-7,000 accounts across 150-350 government, IGO, and NGO organizations toward an ISO-file/Cobalt Strike infection chain, prompting a joint CISA/FBI advisory (AA21-148A) and a DOJ domain seizure.

Incident 2021Read →
PH
Confirmed

CoHost's Near-Hire of a Fabricated AI Candidate with Deepfake-Mimicking References

Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose "references" used voice/video filters mimicking his mannerisms on camera, with every digital trace vanishing within 30 minutes of rejection.

Incident 2026Read →
PH
Confirmed

Council on Foreign Relations Watering-Hole Attack (IE Zero-Day, CVE-2012-4792)

In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and drop malware on the browsers of its policy-elite visitors.

Incident 2012Read →
PH
Confirmed

Anthem health-insurer breach (78.8M records)

A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that quietly stole personal data on 78.8 million people over the next 11 months.

Incident 2014Read →
PH
Confirmed $600M

Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M

Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF, then pivoted to the Ronin bridge validator keys and drained roughly $540-625M in crypto.

Incident 2022Read →
PH
Confirmed

Azure Monitor Alert Abuse TOAD Scam: Fake $459.90 Windows Defender Billing Notice Cleared as a False Positive

Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated fake $459.90 Windows Defender billing notice with fraud callback numbers, which a human SOC reviewer cleared as a false positive.

Incident 2026Read →
PH
Confirmed $3M

Argan, Inc. $3M Phishing-Induced Wire Fraud (2023)

A "complex criminal phishing scheme" fraudulently induced Argan, Inc. to send two outbound wires on March 6-7, 2023, producing a roughly $3 million pre-tax loss with only about $0.2M potentially recoverable through insurance.

Incident 2023Read →
PH
Confirmed $18M

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.

Incident 2014Read →
PH
Confirmed

Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise

Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank account under a bogus tax-refund pretext; Rs 22.31 crore was never recovered, and a second, separate business-email-compromise hit Alkem's Enzene Biosciences US subsidiary roughly 18 months later.

Incident 2023Read →
PH
Confirmed

Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.

Incident 2026Read →
PH
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.

Incident 2022Read →
PH
Confirmed $100M

SEC Section 21(a) Report on Nine Issuers' Business Email Compromise Losses

SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public companies, finding that existing wire-authorization controls weren't consistently followed under the pressure of the schemes.

Incident 2018Read →