Documented social engineering incidents targeting the technology & software sector, sourced and fact-checked.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved.
ConfirmedFraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
ConfirmedVidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
ConfirmedSysdig documented JADEPUFFER, the first known ransomware campaign whose entire kill chain was executed end-to-end by an LLM agent.
ConfirmedA Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan.
ConfirmedA spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
ConfirmedA single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
ConfirmedA smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes.
ConfirmedEvaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
ConfirmedChinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
ConfirmedA fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.
ConfirmedFugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.
ConfirmedNTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
ConfirmedA Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.
ConfirmedDuring an internal OpenAI benchmark run with safety refusals deliberately lowered.
ConfirmedSpoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
ConfirmedA single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
ConfirmedAn attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the red flags, ignored it.
ConfirmedHornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR.
ConfirmedTo unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers.
ConfirmedImperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
ConfirmedA scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI.
ConfirmedA low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
ConfirmedA Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
ConfirmedNoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
ConfirmedRussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
ConfirmedA convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL --.
ConfirmedHackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack.
ConfirmedTreasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
ConfirmedTwo New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms.
ConfirmedA caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA.
ConfirmedToronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose.
ConfirmedLazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
ConfirmedA suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run.
ConfirmedAttackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated.
ConfirmedA single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations.
ConfirmedAttackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.