Documented social engineering incidents targeting the retail & e-commerce sector, sourced and fact-checked.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake crypto trading platform, NanoBit, wiring over $2 million to Hong Kong before the SEC secured a $5.5 million default judgment in one of its first pig-butchering enforcement actions.
ConfirmedCensys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames behind a WebSocket-based backend that streamed victims' card data in real time and included an operator kill-switch, a concrete technical case of the package-delivery smishing wave USPS itself had flagged as rising in June 2025.
ConfirmedA mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.
ConfirmedA federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.
ConfirmedTV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.
ConfirmedTwo Scottish small businesses, an unnamed Perth firm in 2019 and Dumfries-based Handmade Craft House in 2026, lost £31,000 and over £5,000 respectively after callers impersonating bank fraud-team staff talked owners into "safeguarding" money by transferring it straight to the scammers.
ConfirmedP&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G self-disclosed the operation, fired three employees, and settled with Unilever in September 2001.
ConfirmedNTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.
ConfirmedA Mattel finance executive wired $3M to China on a forged email from her brand-new CEO, and the company clawed it back within days thanks to a Chinese bank holiday and an FBI letter.
ConfirmedA retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.
ConfirmedTejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.
ConfirmedFIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.
ConfirmedDOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.
ConfirmedThe FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned, send recipients to phishing sites or malware instead of the promised gift-sender reveal or return instructions.
ConfirmedA caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.
ConfirmedFraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script, and talked a 70-something UK jeweller into installing AnyDesk on his business PC, draining GBP 48,451.78 from two accounts before solicitors clawed back GBP 25,650 from the bank.
ConfirmedA single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.