Sectors

Retail & E-commerce

Documented social engineering incidents targeting the retail & e-commerce sector, sourced and fact-checked.


17 Cases
Confirmed

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake crypto trading platform, NanoBit, wiring over $2 million to Hong Kong before the SEC secured a $5.5 million default judgment in one of its first pig-butchering enforcement actions.

Incident 2023Read →
Confirmed

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames behind a WebSocket-based backend that streamed victims' card data in real time and included an operator kill-switch, a concrete technical case of the package-delivery smishing wave USPS itself had flagged as rising in June 2025.

Incident 2026Read →
Confirmed

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.

Incident 2013Read →
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Incident 2020Read →
Confirmed

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.

Incident 2006Read →
Confirmed

Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Two Scottish small businesses, an unnamed Perth firm in 2019 and Dumfries-based Handmade Craft House in 2026, lost £31,000 and over £5,000 respectively after callers impersonating bank fraud-team staff talked owners into "safeguarding" money by transferring it straight to the scammers.

Incident 2019Read →
Confirmed

P&G's 'Bad Hair Day': Dumpster-Diving Corporate Espionage on Unilever's Hair-Care Business

P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G self-disclosed the operation, fired three employees, and settled with Unilever in September 2001.

Incident 2000Read →
Confirmed

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.

Incident 2014Read →
Confirmed

Mattel CEO-Fraud Wire ($3M, Recovered)

A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO, and the company clawed it back within days thanks to a Chinese bank holiday and an FBI letter.

Incident 2015Read →
Confirmed

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.

Incident 2024Read →
Confirmed

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.

Incident 2020Read →
Confirmed

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.

Incident 2020Read →
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Incident 2015Read →
Confirmed

FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned, send recipients to phishing sites or malware instead of the promised gift-sender reveal or return instructions.

Incident 2025Read →
Confirmed

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.

Incident 2023Read →
Confirmed

Barclays-Impersonation Vishing of UK Jeweller (2024)

Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script, and talked a 70-something UK jeweller into installing AnyDesk on his business PC, draining GBP 48,451.78 from two accounts before solicitors clawed back GBP 25,650 from the bank.

Incident 2024Read →
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.

Incident 2022Read →