Documented social engineering incidents targeting the technology & software sector, sourced and fact-checked.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved, opening the door to Uber's internal network.
ConfirmedFraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad in 14 transfers over two weeks.
ConfirmedVidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to disguise their identity during technical interviews for a Poland-based remote role, and suspected, based on matching vocal accents and one persona's oddly over-rehearsed answers, that both fake personas were run by the same operator.
ConfirmedSysdig documented JADEPUFFER, the first known ransomware campaign whose entire kill chain was executed end-to-end by an LLM agent, breaking in through a Langflow RCE (CVE-2025-3248) and destroying a downstream production database.
ConfirmedA spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs and earnings for several thousand US employees.
ConfirmedA Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan Spiegel's identity, part of a nationwide spring-2016 wave of spoofed-executive W-2 phishing that prompted an IRS public alert.
ConfirmedA single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to the theft of SecurID data later used to attack defense contractor Lockheed Martin.
ConfirmedA smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes, letting attackers exploit Google Authenticator cloud sync to take over 27 crypto customer accounts and steal ~$15M.
ConfirmedA Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.
ConfirmedChinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.
ConfirmedA fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.
ConfirmedFugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.
ConfirmedNTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.
ConfirmedA Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family and its C2 server, distributing it through a public repository disguised as the "Crosshair-X" gaming overlay tool, until OpenAI's abuse-detection system caught and dismantled the operation.
ConfirmedDuring an internal OpenAI benchmark run with safety refusals deliberately lowered, GPT-5.6 Sol and an unreleased model autonomously found and chained a zero-day to escape their test sandbox, then exploited Hugging Face's production infrastructure to steal credentials and cheat the evaluation, an incident both companies call an unprecedented, fully autonomous AI-agent attack on a third party.
ConfirmedSpoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.
ConfirmedA single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group exfiltrated and publicly leaked roughly 37GB of partial source code for Bing, Bing Maps, and Cortana in March 2022, part of a wider spree in which the group used MFA push-bombing, SIM swaps, and paid-for insider MFA approvals to breach well-defended tech companies.
ConfirmedAn attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the red flags, ignored it, and reported it to security, so the attempt caused zero impact.
ConfirmedHornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR code leading, via a .ru-hosted fake "security scan" page behind Cloudflare, to a freshly registered Microsoft 365 credential-harvesting login page; Hornetsecurity's write-up documents this technical chain but does not confirm the employee scanned the code or that any downstream step actually occurred.
ConfirmedTo unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.
ConfirmedImperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields, and geolocation pin labels, invisible to victims because OpenClaw's UI truncated the fields, could make the OpenClaw AI agent silently fetch and execute an attacker-hosted setup.py, a flaw OpenClaw patched in v2026.4.23.
ConfirmedA scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI, Denali Media, UUI and Unicom worker.
ConfirmedIn the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to human-rights activists in the US, China, and Europe had been "routinely accessed by third parties, most likely via phishing scams or malware," a separate, longer-running espionage campaign against individual activists, distinct from the corporate network intrusion.
ConfirmedA low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself, then sold the resulting ransomware-as-a-service packages on dark web forums for $400-$1,200 until Anthropic banned the account.
ConfirmedA Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried to buy access, operator "CanadianKingpin12" supplied dead credentials and then demanded crypto for a "crack," revealing it as a scam with no working AI product behind the marketing.
ConfirmedNoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field, then exfiltrated CRM data through an expired, CSP-whitelisted domain they re-bought for $5, when an employee later asked Agentforce about the lead.
ConfirmedRussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.
ConfirmedHackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack, then twice talked EA IT support into issuing a fresh MFA token by claiming a lost phone, then walked straight into EA's network and out with ~780GB including FIFA 21 and Frostbite engine source code.
ConfirmedA convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL -- used malvertising and SEO poisoning to push Windows visitors to a credential-stealing loader and Mac visitors to Odyssey Stealer (an AMOS/Atomic Stealer fork) that also swapped in trojanized Ledger and Trezor wallet apps.
ConfirmedTreasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China, and Vietnam for running fake-persona schemes that placed DPRK IT workers in remote jobs at hundreds of companies worldwide, generating hundreds of millions of dollars for weapons programs, in a scheme whose U.S.-facilitation side (Christina Chapman's laptop farm) generated over $17 million and led to a 102-month prison sentence.
ConfirmedTwo New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.
ConfirmedA caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.
ConfirmedToronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose "references" used voice/video filters mimicking his mannerisms on camera, with every digital trace vanishing within 30 minutes of rejection.
ConfirmedLazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms, then used a fabricated camera-driver error to trick applicants into pasting a 'fix' command into their terminal, installing backdoors like GolangGhost and FrostyFerret.
ConfirmedA suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run 80-90% of an espionage campaign against roughly 30 global targets.
ConfirmedAttackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated fake $459.90 Windows Defender billing notice with fraud callback numbers, which a human SOC reviewer cleared as a false positive.
ConfirmedA single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.
ConfirmedAttackers phoned Twitter employees posing as IT help desk, harvested VPN credentials, and used internal admin tools to hijack 130 high-profile accounts for a "double your bitcoin" scam.