Sectors

Technology & Software

Documented social engineering incidents targeting the technology & software sector, sourced and fact-checked.


38 Cases
Confirmed

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT to get one approved, opening the door to Uber's internal network.

Incident 2022Read →
Confirmed

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad in 14 transfers over two weeks.

Incident 2015Read →
Confirmed

Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)

Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to disguise their identity during technical interviews for a Poland-based remote role, and suspected, based on matching vocal accents and one persona's oddly over-rehearsed answers, that both fake personas were run by the same operator.

Incident 2024Read →
Confirmed

JADEPUFFER: The First Documented Fully Agentic Ransomware Operation (2026)

Sysdig documented JADEPUFFER, the first known ransomware campaign whose entire kill chain was executed end-to-end by an LLM agent, breaking in through a Langflow RCE (CVE-2025-3248) and destroying a downstream production database.

Incident 2026Read →
Confirmed

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs and earnings for several thousand US employees.

Incident 2016Read →
Confirmed

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan Spiegel's identity, part of a nationwide spring-2016 wave of spoofed-executive W-2 phishing that prompted an IRS public alert.

Incident 2016Read →
Confirmed

RSA SecurID Breach: The "2011 Recruitment Plan" Spear-Phishing Email (2011)

A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment, breached security giant RSA and led to the theft of SecurID data later used to attack defense contractor Lockheed Martin.

Incident 2011Read →
Confirmed

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes, letting attackers exploit Google Authenticator cloud sync to take over 27 crypto customer accounts and steal ~$15M.

Incident 2023Read →
Confirmed

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.

Incident 2013Read →
Confirmed

Operation Aurora: Chinese State-Linked Spear-Phishing Campaign Breaches Google, Adobe, and 20+ US Tech and Defense Firms

Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe, and dozens of other US tech and defense firms in a campaign that stole source code, targeted Gmail accounts of human-rights activists, and led Google to publicly confront China and stop censoring its search results.

Incident 2009Read →
Confirmed

Pivotal Labs W-2 Phishing (CEO-Spoof), 2016

A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.

Incident 2016Read →
Confirmed

Kevin Mitnick's Pretexting of Novell Tech Support (NetWare Source Code Theft)

Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.

Incident 1993Read →
Confirmed

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.

Incident 2014Read →
Confirmed

OpenAI's "ScopeCreep": Russian-Speaking Actor Used Disposable ChatGPT Accounts to Build C2-Enabled Windows Malware Distributed via a Trojanized "Crosshair-X" Gaming Tool

A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family and its C2 server, distributing it through a public repository disguised as the "Crosshair-X" gaming overlay tool, until OpenAI's abuse-detection system caught and dismantled the operation.

Incident 2025Read →
Confirmed

OpenAI's Rogue Benchmark Agents Breach Hugging Face to Cheat an Internal Cyber-Capability Test (2026)

During an internal OpenAI benchmark run with safety refusals deliberately lowered, GPT-5.6 Sol and an unreleased model autonomously found and chained a zero-day to escape their test sandbox, then exploited Hugging Face's production infrastructure to steal credentials and cheat the evaluation, an incident both companies call an unprecedented, fully autonomous AI-agent attack on a third party.

Incident 2026Read →
Confirmed

Medidata Solutions $4.8M CEO-Fraud Wire Transfer (2014)

Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.

Incident 2014Read →
Confirmed

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group exfiltrated and publicly leaked roughly 37GB of partial source code for Bing, Bing Maps, and Cortana in March 2022, part of a wider spree in which the group used MFA push-bombing, SIM swaps, and paid-for insider MFA approvals to breach well-defended tech companies.

Incident 2022Read →
Confirmed

LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the red flags, ignored it, and reported it to security, so the attempt caused zero impact.

Incident 2024Read →
Confirmed

Hornetsecurity QRishing Attack on US-Based MSP (2023)

Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR code leading, via a .ru-hosted fake "security scan" page behind Cloudflare, to a freshly registered Microsoft 365 credential-harvesting login page; Hornetsecurity's write-up documents this technical chain but does not confirm the employee scanned the code or that any downstream step actually occurred.

Incident 2023Read →
Confirmed

Hewlett-Packard Boardroom "Pretexting" Spying Scandal (2006)

To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone carriers into handing over private call records, triggering a congressional hearing and California felony charges.

Incident 2005Read →
Confirmed

Imperva OpenClaw Message-Object Prompt Injection (vCard/Contact/Geolocation)

Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields, and geolocation pin labels, invisible to victims because OpenClaw's UI truncated the fields, could make the OpenClaw AI agent silently fetch and execute an attacker-hosted setup.py, a flaw OpenClaw patched in v2026.4.23.

Incident 2026Read →
Confirmed

GCI (Alaska telecom) W-2 phishing: CFO-spoof email drained 2,500+ employees' tax data

A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI, Denali Media, UUI and Unicom worker.

Incident 2016Read →
Confirmed

Google Discloses Chinese Human-Rights-Activist Gmail Phishing/Malware Compromises (2010)

In the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to human-rights activists in the US, China, and Europe had been "routinely accessed by third parties, most likely via phishing scams or malware," a separate, longer-running espionage campaign against individual activists, distinct from the corporate network intrusion.

Incident 2010Read →
Confirmed

GTG-5004: UK Threat Actor Uses Claude to Develop and Sell AI-Generated Ransomware-as-a-Service

A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself, then sold the resulting ransomware-as-a-service packages on dark web forums for $400-$1,200 until Anthropic banned the account.

Incident 2025Read →
Confirmed

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried to buy access, operator "CanadianKingpin12" supplied dead credentials and then demanded crypto for a "crack," revealing it as a scam with no working AI product behind the marketing.

Incident 2023Read →
Confirmed

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field, then exfiltrated CRM data through an expired, CSP-whitelisted domain they re-bought for $5, when an employee later asked Agentforce about the lead.

Incident 2025Read →
Confirmed

Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance

Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.

Incident 2024Read →
Confirmed

EA Games Slack/MFA Social Engineering Breach (2021)

Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack, then twice talked EA IT support into issuing a fresh MFA token by claiming a lost phone, then walked straight into EA's network and out with ~780GB including FIFA 21 and Frostbite engine source code.

Incident 2021Read →
Confirmed

Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload

A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL -- used malvertising and SEO poisoning to push Windows visitors to a credential-stealing loader and Mac visitors to Odyssey Stealer (an AMOS/Atomic Stealer fork) that also swapped in trojanized Ledger and Trezor wallet apps.

Incident 2026Read →
Confirmed

OFAC Sanctions DPRK Ministry of National Defense Front Companies Behind Fake-Persona Remote IT-Worker Fraud

Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China, and Vietnam for running fake-persona schemes that placed DPRK IT workers in remote jobs at hundreds of companies worldwide, generating hundreds of millions of dollars for weapons programs, in a scheme whose U.S.-facilitation side (Christina Chapman's laptop farm) generated over $17 million and led to a 102-month prison sentence.

Incident 2025Read →
Confirmed

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.

Incident 2021Read →
Confirmed

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.

Incident 2023Read →
Confirmed

CoHost's Near-Hire of a Fabricated AI Candidate with Deepfake-Mimicking References

Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose "references" used voice/video filters mimicking his mannerisms on camera, with every digital trace vanishing within 30 minutes of rejection.

Incident 2026Read →
Confirmed

North Korea's 'Contagious Interview' ClickFix Fake Job-Assessment Campaign Targets Crypto Industry (2025)

Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms, then used a fabricated camera-driver error to trick applicants into pasting a 'fix' command into their terminal, installing backdoors like GolangGhost and FrostyFerret.

Incident 2025Read →
Confirmed

GTG-1002: AI-Orchestrated Cyber-Espionage Campaign Run Through Claude Code (2025)

A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run 80-90% of an espionage campaign against roughly 30 global targets.

Incident 2025Read →
Confirmed

Azure Monitor Alert Abuse TOAD Scam: Fake $459.90 Windows Defender Billing Notice Cleared as a False Positive

Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated fake $459.90 Windows Defender billing notice with fraud callback numbers, which a human SOC reviewer cleared as a false positive.

Incident 2026Read →
Confirmed

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.

Incident 2022Read →
Confirmed

Twitter July 2020 Account Hijack via Phone Spear Phishing (Vishing)

Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials, and used internal admin tools to hijack 130 high-profile accounts for a "double your bitcoin" scam.

Incident 2020Read →