Social Engineering Examples

Pretexting & Impersonation

Pretexting is the invented scenario that makes any of the other techniques work: posing as a journalist, an auditor, a new hire, or a vendor to extract information or access under a false identity. These 28 cases span corporate espionage, help-desk social engineering, and impersonation schemes that unfolded over weeks rather than a single call or email.


28 Cases
PA
Confirmed

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained via carrier pretexting, and the resulting exposé triggered FTC enforcement, congressional hearings, and the 2006 federal law criminalizing pretexting for phone records.

Incident 2005Read →
PA
Confirmed

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles, texting and calling senators, governors and business leaders with requests including a pardon list and a cash transfer, triggering an FBI investigation.

Incident 2025Read →
PA
Confirmed $4.9M

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake AI-generated Zoom "government meeting" that appeared to feature PM Lawrence Wong and other senior officials.

Incident 2026Read →
PA
Confirmed $1.1M

Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)

A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.

Incident 2013Read →
PA
Confirmed $131.5K

Southern California Edison Utility Disconnection Threat Scam (2025)

Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats to extract $131,464 from customers in 2025, a documented 72% drop from 2024 that SCE publicly credited to customer awareness and its recurring scam-education campaigns.

Incident 2024Read →
PA
Confirmed $4M

Roger Roger's Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+

Costa Rica-based telemarketing ringleader Roger Roger used VOIP-spoofed Washington D.C. caller ID and fake government-official personas to convince hundreds of mostly elderly U.S. victims they had won sweepstakes prizes, bilking them of over $4 million before advance-fee "taxes and fees" demands. He was convicted at trial in 2024 and sentenced to over 15 years in 2025.

Incident 2014Read →
PA
Confirmed

San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)

A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad, while a San Diego federal grand jury indicted alleged Ko Thet Company manager/recruiter Thet Min Nyi ("Pixy") and criminal complaints charged three others tied to the Sanduo Group and Giant Company networks.

Incident 2026Read →
PA
Confirmed $211K

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and tell them to have a store cashier scan it to "pay," draining funds instantly through a channel with no fraud checkpoint; PG&E's own fraud investigator quantified over $211,000 in losses through mid-2026.

Incident 2025Read →
PA
Confirmed $20K

Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025)

A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America, with a spoofed caller ID matching the real number on the back of her bank card, convinced her a hacker was draining her account and that transferring the funds would "protect" them, a case the FBI cites as a textbook "Phantom Hacker" scam.

Incident 2024Read →
PA
Confirmed

Kevin Mitnick's Pretexting of Novell Tech Support (NetWare Source Code Theft)

Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.

Incident 1993Read →
PA
Confirmed $100K

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their late spouse's policy was "in arrears" and draining over $100,000 from them via prepaid gift cards, while separately hiding that income to keep collecting SSI, Medicaid, and HUD housing assistance.

Incident 2020Read →
PA
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.

Incident 2025Read →
PA
Confirmed $390K

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.

Incident 2024Read →
PA
Confirmed

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.

Incident 2020Read →
PA
Confirmed

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.

Incident 2005Read →
PA
Confirmed

GTIG Discloses PROMPTFLUX: First "Just-in-Time" Self-Obfuscating AI Malware Using the Gemini API

Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite and re-obfuscate its own source code hourly, making it the first documented "just-in-time" self-modifying AI malware, though GTIG assessed it as an experimental, not-yet-operational prototype.

Incident 2025Read →
PA
Confirmed

Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance

Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.

Incident 2024Read →
PA
Confirmed $223M

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.

Incident 2024Read →
PA
Confirmed $1M

FTC Pretexting Sweep Against Telephone Record Sellers (2006-2008)

Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers, posing as account holders or carrier employees, to obtain consumers' confidential call records and resell them, resulting in permanent injunctions and over $1 million in combined settlements and default-judgment disgorgement.

Incident 2006Read →
PA
Confirmed

Federal Pretexting Prosecutions Post-2006: Bunch and Anderson Charged Under New Anti-Pretexting Statute (2008)

In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal, Nicholas Shaun Bunch and Vaden Anderson were separately charged in late 2008 with tricking T-Mobile and Sprint/Nextel into handing over customers' confidential call records: one by posing as the account holder with a name and partial Social Security number, the other by serving the carrier a fake federal court subpoena.

Incident 2008Read →
PA
Confirmed $225.3M

DOJ files record $225.3M civil forfeiture against USDT laundered from pig-butchering crypto scams (2025)

In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a global pig-butchering money-laundering network, the largest crypto seizure in U.S. Secret Service history and the biggest tied to crypto confidence scams.

Incident 2025Read →
PA
Confirmed

Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)

A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild, closers posed as defense attorneys, police, or court staff, and in-person couriers collected cash, bilking hundreds of elderly Americans out of millions of dollars.

Incident 2019Read →
PA
Confirmed

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.

Incident 2018Read →
PA
Confirmed

CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens of thousands of Canadians with arrest or deportation over fake tax debts, stealing tens of millions of dollars before RCMP's Project OCTAVIA and Indian police raids on roughly 39-40 call centres, plus Canadian money-mule prosecutions, disrupted the operation.

Incident 2014Read →
PA
Confirmed $65M

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.

Incident 2025Read →
PA
Confirmed

Citizens Disability SSDI Impersonation/Robocall Scheme

DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls, including 25.7 million-plus to Do-Not-Call Registry numbers, using robocalls voiced by "Amber" or "Audrey" that falsely told consumers they were following up on the consumer's own SSDI eligibility inquiry.

Incident 2019Read →
PA
Confirmed $380M

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.

Incident 2023Read →
PA
Confirmed $50K

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.

Incident 2006Read →