Skip to content
NetarxNetarx

Global Social Engineering Impact Database

Worldwide losses to deepfakes, impersonation and the oldest exploit in the stack: convincing a human being.

You can patch a server. You cannot patch the person who answers the phone. This is a public, source-linked record of the breaches, frauds, thefts and ransomware that began with someone being persuaded, by a stranger, a familiar voice, or a face that was never in the room.

Documented impact of social engineeringUpdated Sep 11, 2026
Documented dollars stolen
5,345,846,501
Money actually taken from victims, in wire fraud, crypto theft and ransoms, summed across 53 source-linked entries. 32 other published figures are excluded as not comparable.
Documented impacts
1,839,654,668
People and records affected across 56 entries with a published figure. Counts impacts, not unique people. The same person can be hit more than once.
Estimated total losses, all timeover $2 trillion, touching more than 6 billion impacts.Modeled estimate, not a count
What is in the catalogue

276 documented entries, every one linked to its source

See the full breakdown →
215
Discrete incidents
Plus 56 multi-victim campaigns
13%
Involve AI
25 confirmed, 10 suspected
48%
Ran over a live channel
Phone, video call or help desk, not just email
26
Attempts that were stopped
Cases where a control or a suspicious human caught it
Most common entry vector
Vishing (Voice Phishing)
55
Credential Phishing Portal
36
Business Email Compromise
33
Spear Phishing (Email)
28
Help Desk Impersonation
20
Vendor / Supply Chain Impersonation
15
Voice Clone / Audio Deepfake
12
Fake IT Worker Infiltration
10
Insider Recruitment
9
Documented in these entries
Dollars actually stolen
$5.35B
People or records exposed
1.8B
Primary sources cited
584

Only 53 entries carry a comparable victim-loss figure, so this is a floor rather than a cost estimate. A further 36 entries publish a number that measures something else, such as an agency total, a seizure or lost revenue, and those are never added in.

Latest additions

Most recent entries

All 276 entries →
August 24, 2026·Technology

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · United States

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
August 7, 2026·Retail

Levi Strauss files 8-K after social engineering compromises three employee computers

Levi Strauss & Co. · United States

Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.

Vishing (Voice Phishing)
Confirmed2 sources
August 6, 2026·Financial Services

Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks

Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States

BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.

Vishing (Voice Phishing)Attempt blocked
$10.6M criminal proceedsConfirmed3 sources
July 13, 2026·Consumer

Brinks Home breached after Microsoft Entra vishing call to an employee

Brinks Home · United States

Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.

Vishing (Voice Phishing)
Confirmed2 sources
July 6, 2026·Financial Services

Apollo Global Management breached by BlackFile callers posing as IT support

Apollo Global Management · United States

Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.

Vishing (Voice Phishing)
Confirmed2 sources
July 2026·Technology

RingCentral data on 1.6M accounts leaked after social engineering campaign

RingCentral · United States

Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.

Vishing (Voice Phishing)
1.6M affectedConfirmed2 sources
The AI-enabled subset

25 entries where AI was confirmed in the attack

Cloned voices, live deepfaked faces on video calls, synthetic identities passing job interviews. The database tracks AI involvement as its own field so you can see how the share is moving, rather than assuming it.

Contribute

Report an incident

Anyone can submit. Nothing appears on the site automatically. An editor reviews every submission against its sources before it is published, and the entry is marked as a community contribution when it goes live.

Submit an incident
Machine access

Built to be read by AI

A filterable JSON API, an llms.txt manifest, schema.org JSON-LD on every entry, bulk CSV and JSON exports, and an MCP server so Claude and other agents can query the catalogue as a tool.

Global Social Engineering Impact Database · Entries summarise public reporting and are not legal findings. How this database is built