Pretexting is the invented scenario that makes any of the other techniques work: posing as a journalist, an auditor, a new hire, or a vendor to extract information or access under a false identity. These 28 cases span corporate espionage, help-desk social engineering, and impersonation schemes that unfolded over weeks rather than a single call or email.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting, and the resulting exposé triggered FTC enforcement, congressional hearings, and the 2006 federal law criminalizing pretexting for phone records.
PAAn unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles, texting and calling senators, governors and business leaders with requests including a pardon list and a cash transfer, triggering an FBI investigation.
PAA Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake AI-generated Zoom "government meeting" that appeared to feature PM Lawrence Wong and other senior officials.
PAA Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.
PAScammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats to extract $131,464 from customers in 2025, a documented 72% drop from 2024 that SCE publicly credited to customer awareness and its recurring scam-education campaigns.
PACosta Rica-based telemarketing ringleader Roger Roger used VOIP-spoofed Washington D.C. caller ID and fake government-official personas to convince hundreds of mostly elderly U.S. victims they had won sweepstakes prizes, bilking them of over $4 million before advance-fee "taxes and fees" demands. He was convicted at trial in 2024 and sentenced to over 15 years in 2025.
PAA joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad, while a San Diego federal grand jury indicted alleged Ko Thet Company manager/recruiter Thet Min Nyi ("Pixy") and criminal complaints charged three others tied to the Sanduo Group and Giant Company networks.
PAScammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and tell them to have a store cashier scan it to "pay," draining funds instantly through a channel with no fraud checkpoint; PG&E's own fraud investigator quantified over $211,000 in losses through mid-2026.
PAA Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America, with a spoofed caller ID matching the real number on the back of her bank card, convinced her a hacker was draining her account and that transferring the funds would "protect" them, a case the FBI cites as a textbook "Phantom Hacker" scam.
PAFugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.
PAAn Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their late spouse's policy was "in arrears" and draining over $100,000 from them via prepaid gift cards, while separately hiding that income to keep collecting SSI, Medicaid, and HUD housing assistance.
PAA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.
PAA retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.
PATejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.
PATo unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.
PAGoogle's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite and re-obfuscate its own source code hourly, making it the first documented "just-in-time" self-modifying AI malware, though GTIG assessed it as an experimental, not-yet-operational prototype.
PARussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.
PAFTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.
PABetween 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.
PAIn the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal, Nicholas Shaun Bunch and Vaden Anderson were separately charged in late 2008 with tricking T-Mobile and Sprint/Nextel into handing over customers' confidential call records: one by posing as the account holder with a name and partial Social Security number, the other by serving the carrier a fake federal court subpoena.
PAIn June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a global pig-butchering money-laundering network, the largest crypto seizure in U.S. Secret Service history and the biggest tied to crypto confidence scams.
PAA Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild, closers posed as defense attorneys, police, or court staff, and in-person couriers collected cash, bilking hundreds of elderly Americans out of millions of dollars.
PAAn MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.
PAA long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens of thousands of Canadians with arrest or deportation over fake tax debts, stealing tens of millions of dollars before RCMP's Project OCTAVIA and Indian police raids on roughly 39-40 call centres, plus Canadian money-mule prosecutions, disrupted the operation.
PADOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.
PADOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls, including 25.7 million-plus to Do-Not-Call Registry numbers, using robocalls voiced by "Amber" or "Audrey" that falsely told consumers they were following up on the consumer's own SSDI eligibility inquiry.
PAA caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.
PAThe FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.