Phishing is still the workhorse of social engineering: a fraudulent email, often impersonating a vendor, executive or IT department, designed to get someone to click, enter credentials, or wire money. The 62 cases below range from mass-market credential theft to nine-figure business email compromise, and each one names the lure, what it cost, and the specific check that would have caught it.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved, opening the door to Uber's internal network.
PHFraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad in 14 transfers over two weeks.
PHRussia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities, harvesting credentials that let them remotely open substation breakers and cut power to about 225,000 customers, marking the first confirmed cyberattack to cause a real-world blackout.
PHA phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then used the live CFO mailbox to send about 15 fake-invoice wire requests over nine days, draining nearly $11 million overseas.
PHA mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.
PHFraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.
PHA European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent payment-change instructions.
PHA caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to a "safe" Capitec account, with three transfers completed within 20 minutes; Standard Bank's own investigation attributed the loss to vishing while denying any breach of its systems, and the case has been escalated to the National Financial Ombud and North West police.
PHA nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted contractors, then physically destroyed roughly 1,000 uranium centrifuges.
PHImpostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he wired $17.2M in three tranches to a Shanghai account.
PHA spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs and earnings for several thousand US employees.
PHA Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan Spiegel's identity, part of a nationwide spring-2016 wave of spoofed-executive W-2 phishing that prompted an IRS public alert.
PHNorth Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated wiper malware that crippled the studio.
PHA federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.
PHA single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to the theft of SecurID data later used to attack defense contractor Lockheed Martin.
PHAttackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan; insurance covered all but roughly $112,000.
PHA small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.
PHGoogle's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging Face API) at runtime to dynamically generate the Windows recon and data-theft commands it then executes against Ukrainian government targets, the first publicly documented malware to call an LLM live in operations.
PHA compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.
PHA smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes, letting attackers exploit Google Authenticator cloud sync to take over 27 crypto customer accounts and steal ~$15M.
PHA Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.
PHA fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.
PHA forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account in January 2020.
PHChinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.
PHA non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M to attacker-controlled accounts, with no system or data breach involved.
PHFraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition, costing two executives their jobs.
PHImpersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000 into fraud accounts; the loss surfaced only during the annual city audit.
PHScammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect, then used a lookalike "easthardings.com" domain to redirect a $3.2M construction payment to accounts they controlled.
PHAttackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to swap in their own bank account, and diverted about $6M in city funds.
PHA Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.
PHA spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders, tricked staff into redirecting $11.8 million CAD in construction payments to fraudulent bank accounts in Montreal and Hong Kong, one of the largest publicly documented BEC losses at a North American university.
PHA spoofed email impersonating a company executive tricked a Main Line Health employee into emailing the W-2 and personal data of all ~11,000 staff to criminals.
PHA four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.
PHA Mattel finance executive wired $3M to China on a forged email from her brand-new CEO, and the company clawed it back within days thanks to a Chinese bank holiday and an FBI letter.
PHSpoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.
PHA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.
PHA Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike "pearson.quest" domain.
PHFraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40 million (about US$44.6 million) to attacker-controlled accounts in August 2016.
PHA fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend, diverting USD 794,934.04 away from DTC and delaying payment to shareholders.
PHTo unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.
PHGoogle's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite and re-obfuscate its own source code hourly, making it the first documented "just-in-time" self-modifying AI malware, though GTIG assessed it as an experimental, not-yet-operational prototype.
PHA scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI, Denali Media, UUI and Unicom worker.
PHIn the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to human-rights activists in the US, China, and Europe had been "routinely accessed by third parties, most likely via phishing scams or malware," a separate, longer-running espionage campaign against individual activists, distinct from the corporate network intrusion.
PHFTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.
PHFraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project; EUR 41.9M was lost and both the CEO and CFO were later fired.
PHA convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL -- used malvertising and SEO poisoning to push Windows visitors to a credential-stealing loader and Mac visitors to Odyssey Stealer (an AMOS/Atomic Stealer fork) that also swapped in trojanized Ledger and Trezor wallet apps.
PHBelgian bank Crelan lost close to EUR 70 million (~US$75.8M) after fraudsters impersonating its CEO induced internal staff to execute a series of unauthorized wire transfers, discovered via internal controls in January 2016.
PHCriminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district; the FBI and U.S. Attorney's Office later seized about $4.86M.
PHRussian GRU officers spoofed Google security-alert emails with Bitly-masked links to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails after an IT aide's fateful 'legitimate' typo.
PHScammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County, NC wired $2.5M to the fraud account, losing $1.73M net.
PHA compromised Constant Contact mass-mailing account let Russia-linked Nobelium (APT29) send USAID-spoofed phishing emails that funneled roughly 3,000-7,000 accounts across 150-350 government, IGO, and NGO organizations toward an ISO-file/Cobalt Strike infection chain, prompting a joint CISA/FBI advisory (AA21-148A) and a DOJ domain seizure.
PHToronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose "references" used voice/video filters mimicking his mannerisms on camera, with every digital trace vanishing within 30 minutes of rejection.
PHIn late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and drop malware on the browsers of its policy-elite visitors.
PHA single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that quietly stole personal data on 78.8 million people over the next 11 months.
PHLazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF, then pivoted to the Ronin bridge validator keys and drained roughly $540-625M in crypto.
PHAttackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated fake $459.90 Windows Defender billing notice with fraud callback numbers, which a human SOC reviewer cleared as a false positive.
PHA "complex criminal phishing scheme" fraudulently induced Argan, Inc. to send two outbound wires on March 6-7, 2023, producing a roughly $3 million pre-tax loss with only about $0.2M potentially recoverable through insurance.
PHA fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.
PHFraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank account under a bogus tax-refund pretext; Rs 22.31 crore was never recovered, and a second, separate business-email-compromise hit Alkem's Enzene Biosciences US subsidiary roughly 18 months later.
PHAn interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.
PHA single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.
PHSEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public companies, finding that existing wire-authorization controls weren't consistently followed under the pressure of the schemes.