Case studies
- Coinbase insider data breach – May 2025. Attackers bribed overseas support staff at the cryptocurrency exchange to leak customer details such as names, birthdates, email addresses and partial Social Security numbers. The stolen data was used for highly targeted scams. Coinbase refused a US$20 million ransom and instead offered a bounty while preparing reimbursements that could total hundreds of millions.
- CoGUI phishing campaign floods Japan. Between January and April 2025 a phishing kit called CoGUI sent more than 580 million scam emails across Japan, impersonating trusted brands like Amazon, PayPal and tax agencies. The goal was to trick recipients into entering credentials and payment information.
- Scattered Spider infiltrates UK retailers. A UK-focused gang known as Scattered Spider targeted major retailers such as Marks & Spencer and Harrods by impersonating IT or service-desk staff. Employees were duped into resetting credentials or disabling multi-factor authentication, allowing ransomware deployment and resulting in online shopping outages that reportedly cost Marks & Spencer around £300 million. An analysis explained that the attackers gather staff details via social media, call help desks with urgent requests and use spoofed phone numbers to pressure staff into bypassing security. Recommended defences include strict identity verification for resets, enforcing MFA that cannot be disabled by a single agent, limiting help-desk privileges and training staff to recognise urgent social-engineering requests.
- McDonald’s AI hiring chatbot breach. In July 2025 security researchers discovered that a Paradox.ai account used by McDonald’s “McHire” platform was secured with the easily guessable password “123456” and no multi-factor protection. By guessing the password, researchers accessed the backend and exposed up to 64 million job-applicant records containing names, email addresses and phone numbers. Further investigation revealed that a Paradox developer’s device had been infected with “Nexus Stealer” malware that exposed numerous weak passwords and authentication cookies.
- LexisNexis repository breach. On 25 December 2024 attackers gained access to LexisNexis Risk Solutions’ private GitHub repositories via social engineering and exposed personal data—including names, phone numbers and Social Security numbers—for more than 364,000 individuals.
Why these stories matter
These breaches highlight that social-engineering attacks focus on people, not just technology. Bribery, phishing, impersonation and weak passwords undermine even sophisticated defences. Training cannot be a one-off exercise; it must be continuous and tailored. SafetyShadow’s programs teach employees to:
- Verify identities: Require out-of-band confirmation for password resets and service-desk requests.
- Recognise red flags: Treat urgent requests for credential resets or changes with suspicion and verify them through a separate channel.
- Use strong authentication: Enforce unique, complex passwords and multi-factor authentication for all accounts—including vendor portals and test accounts.
- Protect development tools: Control access to code repositories and ensure developers follow strict security practices.
- Report incidents quickly: Encourage staff to report suspicious emails or calls so security teams can respond promptly.
Continuous awareness training and simulated social-engineering exercises help build a human-first defence strategy. By learning from these real cases, organisations can prevent attackers from exploiting trust and complacency.

