Sectors

Retail & E-commerce

Documented social engineering incidents targeting the retail & e-commerce sector, sourced and fact-checked.


17 Cases
Confirmed

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake.

Incident 2023Read →
Confirmed

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.

Incident 2026Read →
Confirmed

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.

Incident 2013Read →
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.

Incident 2020Read →
Confirmed

Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.

Incident 2019Read →
Confirmed

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.

Incident 2006Read →
Confirmed

P&G's 'Bad Hair Day': Dumpster-Diving Corporate Espionage on Unilever's Hair-Care Business

P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.

Incident 2000Read →
Confirmed

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.

Incident 2014Read →
Confirmed

Mattel CEO-Fraud Wire ($3M, Recovered)

A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.

Incident 2015Read →
Confirmed

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him.

Incident 2024Read →
Confirmed

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.

Incident 2020Read →
Confirmed

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.

Incident 2020Read →
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.

Incident 2015Read →
Confirmed

FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned.

Incident 2025Read →
Confirmed

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA.

Incident 2023Read →
Confirmed

Barclays-Impersonation Vishing of UK Jeweller (2024)

Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.

Incident 2024Read →
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations.

Incident 2022Read →
Explore more

Browse the rest of the library