Biggest Phishing Breaches
Real incidents, verified costs, and attack methods. These are the breaches that changed how organisations think about phishing risk.
Combined Losses
$598.5M
Across 10 featured incidents
Most Common Vector
CEO Fraud
BEC responsible for $50B+ since 2013
Recovery Rate
~16%
Of BEC losses recovered (FBI IC3 2022)
| Company | Year | Attack Method | Cost | Severity |
|---|---|---|---|---|
| Ubiquiti Networks | 2015 | Whaling / CEO Fraud (BEC) | $46.7M | critical |
| 2020 | Vishing (phone social engineering) | $120M (est. market cap impact) | critical | |
| RSA Security | 2011 | Spear phishing (malicious Excel attachment) | $66M+ (estimated) | critical |
| Sony Pictures | 2014 | Spear phishing (Apple credential harvesting) | $100M+ | critical |
| Google & Facebook | 2013–2015 | Email phishing (fake invoices — BEC) | $100M | high |
| Crelan Bank (Belgium) | 2016 | Whaling / CEO Fraud (BEC) | $75.8M | critical |
| Twilio / Cloudflare (OKTAPUS) | 2022 | Smishing (SMS phishing) | $65M+ (Twilio); reputational | high |
| Abnormal Security Customer (Healthcare) | 2023 | Spear phishing (vendor impersonation) | $4.8M | high |
| Scoular Company | 2014 | Whaling / CEO Fraud (BEC) | $17.2M | high |
| Mattel | 2015 | Whaling / CEO Fraud (BEC) | $3M (recovered) | medium |
Detailed Incident Analysis
Ubiquiti Networks
2015 — Whaling / CEO Fraud (BEC)
Attackers impersonated an executive and directed the finance team via email to make a series of wire transfers to fraudulent overseas accounts. The company recovered $8.1M through legal action, leaving a net loss of $38.6M.
2020 — Vishing (phone social engineering)
Teenage hackers called Twitter employees posing as internal IT support staff, convincing them to provide VPN credentials. 130 high-profile accounts were hijacked — including Barack Obama, Elon Musk, and Joe Biden — to run a Bitcoin scam that netted $120K directly, with massive reputational fallout.
RSA Security
2011 — Spear phishing (malicious Excel attachment)
A spear phishing email sent to four RSA employees with subject '2011 Recruitment Plan' contained an Excel spreadsheet exploiting a Flash zero-day. The compromise exposed SecurID two-factor authentication seed values used by millions, including defence contractors Lockheed Martin and L-3.
Sony Pictures
2014 — Spear phishing (Apple credential harvesting)
Attackers sent Apple ID phishing emails to Sony executives. Once inside, they deployed destructive malware wiping 70% of Sony's servers and exfiltrating 100TB of data — including unreleased films, salaries, Social Security numbers, and executives' private emails.
Google & Facebook
2013–2015 — Email phishing (fake invoices — BEC)
Lithuanian national Evaldas Rimasauskas created a fake company impersonating Quanta Computer, a real hardware vendor used by both Google and Facebook. Over two years, he sent fraudulent invoices totalling $100M. Both companies paid — and later recovered most funds through legal action.
Crelan Bank (Belgium)
2016 — Whaling / CEO Fraud (BEC)
Cybercriminals compromised the email account of the CEO and used it to send payment instructions to finance staff. The fraud was discovered during an internal audit. The bank absorbed the full loss as the transfers were approved by authorised personnel.
Twilio / Cloudflare (OKTAPUS)
2022 — Smishing (SMS phishing)
Threat group 0ktapus sent SMS messages to employees of 130+ companies impersonating Okta IT support, directing them to a fake login page. Twilio, Cloudflare, DoorDash, and others were breached. 9,931 accounts at over 130 organisations were compromised.
Abnormal Security Customer (Healthcare)
2023 — Spear phishing (vendor impersonation)
A mid-size healthcare provider received convincing spear phishing emails impersonating a trusted medical equipment vendor. Finance staff approved payments totalling $4.8M before the fraud was detected. Classic vendor email compromise — representative of thousands of similar incidents annually.
Scoular Company
2014 — Whaling / CEO Fraud (BEC)
Grain trading company Scoular was defrauded when an employee received emails purportedly from the CEO and an external KPMG accountant instructing transfers to a Chinese bank account for a confidential acquisition. The employee completed 3 wire transfers before the fraud was discovered.
Mattel
2015 — Whaling / CEO Fraud (BEC)
A Mattel finance executive received an email from a fraudster impersonating the new CEO requesting a $3M payment to a Chinese vendor. The transfer was made. Mattel recovered the funds due to a rare coincidence — the fraud was discovered on a Chinese public holiday when the bank was still open.
Could your organisation be next?
Every organisation featured here thought they had adequate controls. Calculate your phishing risk exposure in 60 seconds.
Calculate My Risk →