Case Library

Social engineering statistics

Every figure below is counted from the 173 cases in this library. None is estimated, modelled or extrapolated.

Social Engineering Examples·Recomputed 16 Sep 2026

173
Documented cases
$2.3M
Median disclosed loss
52
Cases with a documented loss
1117
Sources cited
22
Countries represented
1978–2026
Years covered

What the corpus shows

  • Our analysis of 173 documented cases records phishing as the entry channel in 62 of them, more than any other technique.
  • Across the corpus, we find the most-targeted sector is Financial Services & Insurance, with 46 cases.
  • Among the 52 cases that state a loss in US dollars, we record a median of $2.3M. Half of all disclosed losses fall below that figure.
  • The largest single verified loss is $540M, at Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M.
  • We verified every case against primary reporting, citing 1117 sources in total, an average of 6.5 per case.
  • Of the 173 cases, 170 are confirmed by the victim, a regulator or a court, and 3 remain alleged.

Cases by attack channel

A case can use more than one channel, so these are counts of cases, not shares of the total.

Phishing
62
Vishing
32
Pretexting & Impersonation
28
Physical Social Engineering
22
Agentic AI Attacks
22
Smishing
15
Deepfake & Synthetic Media
14
Help-Desk & MFA Manipulation
8
ClickFix & SEO Poisoning
8
Quishing
7

Cases by sector

Top ten sectors. A case can affect more than one.

Financial Services & Insurance
46
Government & Public Sector
42
Technology & Software
38
Consumer / General Public
38
Manufacturing & Industrial
22
Retail & E-commerce
17
Cross-Sector / Multiple Industries
15
Professional & Business Services
14
Cryptocurrency & Digital Assets
13
Media & Entertainment
12

How disclosed losses are distributed

The 52 cases that state a figure in US dollars.

Under $100k
8
$100k – $1M
14
$1M – $10M
14
$10M – $100M
14
Over $100M
2

Documented cases by year

Counts reflect when each incident occurred, not when it was added. Coverage thins before 2015 because public disclosure was rarer, so the rise after 2022 partly reflects reporting requirements rather than attack volume alone.

YearDocumented cases
202619
202526
202423
202318
20228
20217
20206
20196
1978–201860

The current year is partial. Download the full dataset to compute your own cuts.

What the loss figures represent

Most published social engineering statistics blend different quantities into one number. A regulatory fine, a company’s remediation bill, a ransom that was demanded but never paid, and money a victim actually lost are not the same thing. Every figure in this corpus is classified, so you can see exactly what is being counted.

ClassificationCasesCounted as a loss
Victim loss, net of recovery51Yes
Court-awarded damages1Yes
No figure disclosed96No
Regulatory penalty or settlement7No
Remediation and investigation cost5No
Ransom or sum demanded, not confirmed paid4No
Attacker’s own cost or asking price4No
Attacker revenue1No
Reported earnings impact1No
Damages alleged in litigation1No
Modelled or economy-wide estimate2No

Only the first two rows carry a non-zero loss_usd. Every classification was assigned by reading the figure against its source note, not inferred automatically.

How these figures are counted

A case can involve more than one channel and more than one sector, so channel and sector figures are counts of cases rather than percentages, and they sum to more than 173.

We publish a median rather than a grand total. The library records amounts stolen from one organisation alongside remediation costs, regulatory settlements and multi-victim campaign figures, and those are different quantities that cannot meaningfully be added together. Where a source gives only a modelled or economy-wide estimate, or states that no figure was ever disclosed, the case is counted as having no disclosed loss.

Figures stated only in a currency other than US dollars are excluded rather than converted at a rate we cannot source. Per-case sourcing is set out in our methodology.