These Scams Are Not Hypothetical.
They Happened. To Real People.

Every case below comes from police, courts, regulators, security researchers, or the companies themselves. Verified sources. Real losses. Real consequences.

If it happened to them, it can happen to anyone.

These are not people who fell for obvious junk mail. They are homeowners, finance teams, CEOs, universities, a central bank, and some of the biggest companies in the world. An 85-year-old retiree handed $200,000 in gold coins to a stranger in a black Mustang. Google and Facebook wired $122 million to a man with a laptop and a spoofed domain name. An Austrian aerospace CEO was fired after his company lost $47 million to a single fake email. A first-time Chicago homebuyer lost her entire down payment in a wire transfer that took under an hour.

This is the power of Read-Time Fraud Detection.
This is the protection of EFA.

Every case below is real. Every loss is documented. And every EFA warning shown is tied to what investigators, victims, courts, companies, or security researchers actually found. Choose a case below to see what happened, the warning EFA looks for, and why it matters — or simply keep scrolling.

Select any case to jump directly to the story

It All Started With an Email.

Not a phone call. Not a letter. Not a knock at the door. An email. An 85-year-old retiree. Facebook's finance team. An Austrian aerospace CEO. A first-time homebuyer in Chicago. Britain's largest automaker. Different people, different countries, different dollar amounts — but the same entry point every time.

Named Victim — Documented Loss 2025 United Kingdom Targeted Phishing Attack

It Started With an Email. It Shut Down Britain's Largest Automaker.

Estimated Economic Impact
£1.9 BILLION

Jaguar Land Rover was hit by a major cyberattack in 2025. Security researchers investigating the attack identified targeted phishing emails, stolen employee passwords, and manipulation of staff among the methods tied to the attackers. JLR never disclosed the precise point of entry.

JLR shut down its global systems and paused production for five weeks. The disruption spread through its dealers, suppliers, and the wider automotive supply chain. JLR reported £196 million in cyber-related costs, while the UK's Cyber Monitoring Centre estimated the wider economic impact at £1.9 billion across more than 5,000 organizations, calling it the most financially damaging cyber event ever to hit the UK.

EFA Warning Not established by the public record

We don't know enough about the original phishing email to say exactly which EFA warning would have appeared. What we do know is that an email helped start an attack that ultimately caused enormous damage. EFA is there for that moment — when the email first arrives and someone has to decide whether to trust it.

Named Victim — Documented Loss 2013 – 2019 Lithuania → USA Fake Vendor Invoice

Facebook and Google Wired $122 Million to a Fake Vendor

Total Stolen
$122,000,000

Evaldas Rimasauskas registered a real company in Latvia and gave it the same name as Quanta Computer — a legitimate Taiwan-based hardware manufacturer that did real business with Facebook and Google. Not a near-miss spelling. The actual name. Over two years, he sent fraudulent invoices with spoofed email addresses, along with forged contracts and fake corporate seals. Employees at both tech giants wired payments to bank accounts he controlled in Latvia, Cyprus, Hungary, and Hong Kong.

Facebook wired nearly $100 million. Google wired over $23 million. Rimasauskas was extradited from Lithuania, pleaded guilty to wire fraud, and was sentenced to five years in federal prison. He was ordered to forfeit $49.7 million and pay $26.5 million in restitution.

The company name on these invoices was not even a near-miss — he had registered a real company using the supplier's real name, so the name checked out. What did not check out was the address the mail came from. If an invoice arrives from vendor@acme-co.com instead of the vendor@acme.com address you know, EFA warns you. If the email also tells you to pay a new bank account, EFA warns you about that too.

Named Victim — Documented Loss August 2024 Luxembourg / United States Payment Switched

One Employee. Several Wire Transfers. A $60 Million Hole in the Accounts.

Expected Charge
USD $60 MILLION

Orion S.A. is a chemical manufacturer listed on the New York Stock Exchange. On August 10, 2024 the company determined that one of its employees — specifically not a senior executive — had been the target of a criminal scheme that resulted in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. Nobody broke into Orion's systems. Someone convinced a person to send the money.

Orion told the SEC two days later that it expected a one-time pre-tax charge of roughly $60 million for the transfers it had not recovered. The same filing states the company found no evidence of any other fraudulent activity and does not believe the incident involved unauthorized access to its data or systems. Law enforcement was notified and Orion said it would pursue recovery, including through insurance.

The filing doesn't describe the messages the employee received, so we don't know exactly what EFA would have seen. What it does tell us is how the attack worked: one ordinary employee, several wire transfers, and no hacking at all. That is exactly the situation EFA is built for — an email asks someone to move money, and the last thing standing between the company and the loss is that person deciding to check first. Sixty million dollars left this company without a single system being breached.

Named Victim — Documented Loss January 2016 Ried im Innkreis, Austria Fake Message From the Boss

An Austrian Aerospace Giant Lost $47 Million to a Single Fake Email. The CEO Was Fired.

Total Loss
$47,000,000

FACC — an Austrian aerospace manufacturer that makes parts for Boeing, Airbus, and Rolls-Royce — received a fraudulent email impersonating its CEO, Walter Stephan. The email instructed an employee in the finance department to wire roughly €50 million to fund a "confidential acquisition." The employee complied. By the time FACC realized what had happened, the money had moved through banks in Slovakia and Asia.

FACC recovered about €10.9 million but took a €41.9 million loss. The company posted a pretax loss of €23.4 million for the fiscal year. The supervisory board fired CEO Walter Stephan and CFO Minfen Gu for "severely violating their duties" in what FACC dubbed the "Fake President Incident." The finance employee who executed the transfer was also dismissed.

An email saying something like "keep this confidential" while asking you to wire millions of dollars is exactly the kind of combination EFA warns about. The idea is simple: slow the person down before the money moves.

Named Victim — Documented Loss July 2024 Singapore → Timor-Leste Fake Supplier Email

One Letter Changed. $42.3 Million Went to the Wrong Account.

Amount Transferred
$42.3 MILLION

A Singapore commodity firm received an email that appeared to come from one of its legitimate suppliers. The sender's email address differed from the real supplier's address by just one character — an “i” had been replaced with an “l.” The email instructed the company to send a pending payment to a new bank account in Timor-Leste. The company transferred $42.3 million.

The scam email arrived on July 15 and the transfer went out on July 19. Four days after that, the genuine supplier told the company it had never received the payment. Singapore Police filed a report and contacted INTERPOL, whose rapid payment-interception mechanism reached authorities in Timor-Leste within 24 hours. More than $39 million was withheld from the fraudulent account, roughly another $2 million was recovered in follow-up work, and seven suspects were arrested in Timor-Leste — over $40 million returned in total.

The fake supplier address was off by one letter. EFA would put the suspicious address next to the one you already know so you can see the difference. And when the same email says, "Send this payment to our new bank account," EFA warns about that too.

Named Victim — Documented Loss August 2019 Japan → Europe Payment Switched

A Toyota Supplier Followed Payment Directions That Were Never Real. It Cost ¥4 Billion.

Expected Loss
~$37 MILLION

On August 14, 2019, the European subsidiary of Toyota Boshoku Corporation — a Toyota Group parts maker that supplies car seats and interiors — acted on fraudulent payment directions sent by a third party and transferred company funds outside the company. Toyota Boshoku disclosed the incident on September 6, putting the expected loss at up to roughly ¥4 billion, about US$37 million.

The company said it became aware the directions were fraudulent shortly afterward, assembled a team of legal professionals, and reported the loss to local investigating authorities. Toyota Boshoku did not publish the contents of the email or the sender details.

If a normal supplier suddenly emails new banking instructions, EFA tells you to stop and verify them before paying. A quick phone call to a number you already have can be the difference between paying your supplier and paying a criminal.

Named Victim — Documented Loss March 2018 Netherlands → Dubai Fake Message From the Boss

A Secret Acquisition That Did Not Exist Cost Pathé €19.2 Million.

Total Loss
€19.2 MILLION

Between March 8 and March 27, 2018, the Dutch arm of the French cinema group Pathé received a series of emails purporting to come from the CEO of Pathé in France. They described a confidential acquisition of a cinema operator in the Gulf, said the matter "must remain strictly confidential," and asked that replies go only to a personal address. Four transfers totalling €19,244,304 went to an account in the name of Towering Stars General Trading in Dubai.

Pathé Nederland's managing director Dertje Meijer and financial director Edwin Slutter were suspended and dismissed. The details became public through an October 31, 2018 ruling of the District Court of Amsterdam in Slutter's unfair-dismissal claim, which found in his favor on the severance he was owed.

"This is confidential. Don't tell anyone. Send the money." Those are exactly the kinds of words EFA is looking for. When secrecy and a large payment request show up together, EFA gives you a reason to stop before following the instructions.

Named Victim — Documented Loss November 2018 India → Hong Kong Fake Message From the Boss

They Impersonated the CEO by Email — Then Held Conference Calls to Back It Up.

Total Loss
$18.6 MILLION

Attackers emailed the India head of Tecnimont SpA, part of the Italian group Maire Tecnimont, from an account that looked deceptively similar to one used by the group's CEO. They then staged a series of conference calls in which members of the group played the CEO, other senior Tecnimont executives, and a Swiss lawyer, to discuss a "confidential" acquisition in China. The India head was told the money could not be sent from Italy for regulatory reasons. He authorized three transfers in one week — $5.6 million, $9.4 million and $3.6 million — to banks in Hong Kong, where the funds were withdrawn within minutes.

The fraud surfaced when Tecnimont SpA's chairman visited India. The company dismissed its India chief and its head of accounts and finance.

The fake CEO's email address looked almost like the real one. EFA would show the two addresses together so the difference is much harder to miss. Add words like "confidential" and an urgent wire request, and there is even more reason to stop before sending anything.

Named Victim — Documented Loss August 2017 Edmonton, Alberta, Canada Fake Vendor

A University Changed a Vendor's Banking Details Because an Email Asked It To.

Total Paid to Fraudsters
C$11.8 MILLION

MacEwan University received a series of emails from what appeared to be Clark Builders, a construction firm the university had worked with for more than a decade. The messages carried the vendor's logo and asked staff to update the banking details on file. Staff made the change. Between August 10 and August 19, 2017, three payments — ranging from about $22,000 to $9.9 million — went to accounts the fraudsters controlled. The scheme relied on fake websites and targeted emails impersonating more than a dozen Edmonton-area construction companies.

The fraud came to light on August 23, when the real contractor called to ask why it had not been paid. Working with banks, lawyers in several jurisdictions and police, the university traced and froze funds in Canada and Hong Kong. By the time proceedings concluded in April 2018 it had recovered about $10.9 million — roughly 92% of what was taken. The remaining shortfall was covered from reserves.

If a vendor you've worked with for years suddenly emails, "We've changed banks — use this new account," EFA warns you. Then it tells you to call the vendor using a number you already have before changing anything.

Named Victim — Documented Loss June – July 2023 Malaysia Fake Supplier

The Supplier Asked for Payment to a New Account. Police Stopped RM28 Million on Its Way Out of the Country.

Amount Paid — Intercepted
RM28,361,636

A Malaysian company had been buying liquefied petroleum gas from an overseas supplier since January 2023. On June 22 it received an email from someone presenting as a representative of that supplier, instructing that payment be made to a new bank account. The company paid. It only learned it had been defrauded when the real supplier said the money had never arrived.

Bukit Aman's Commercial Crime Investigation Department, working with Bank Negara Malaysia and the banks involved, traced the transfers and stopped RM28,361,636 from reaching a foreign account. Its director, Datuk Seri Ramli Mohamed Yoosuf, described the method plainly: syndicates hack or monitor a company's email to watch its transactions, then pose as a business partner or supplier. His advice was equally plain — be wary of any instruction to change a bank account for payment, and phone the supplier to confirm.

The email said the supplier had a new bank account. That's enough for EFA to warn you. Even if the email address looks completely normal, changing where the money goes should always get a second check.

Named Victim — Documented Loss September 2020 Australia → Singapore Fake Internal Invoice

The Invoice Emails Looked Like They Came From Staff. The Bank Details Did Not.

Total Paid
AUD 2.67 MILLION

In September 2020, offenders claiming to be staff sent internal invoice emails to an Australian company's finance area — the same routine paperwork that team processes every day, but with the bank details altered. Finance paid twice: AUD 519,545, then AUD 2,148,938. Both payments went to an account in Singapore.

The Australian Federal Police coordinated with INTERPOL and the Singapore Police Force. The first transfer had already been drained by the offenders, but the second was intercepted after the bank was alerted — AUD 2.1 million of the AUD 2.67 million was recovered. The AFP published the case as part of a disclosure that business email compromise had cost Australian victims more than $79 million in twelve months.

An invoice can look completely ordinary and still send the money to the wrong account. If the email changes the banking details, EFA warns the finance team to verify them before paying.

Named Victim — Documented Loss 2021 United Kingdom Home Purchase / Payment Switched

The Payment Request Was for Exactly What He Expected to Pay. That's What Made It Work.

Total Loss
£640,000

Criminals intercepted the emails going back and forth between a homebuyer and their solicitor. They then set up an email account made to look like the solicitor's and sent payment instructions on headed paper — for exactly the amount the buyer was already expecting to pay. The buyer sent £640,000. The solicitor later confirmed they had never asked for it.

Most of the money was never recovered and the purchase collapsed. The Law Society published the case alongside the National Economic Crime Centre and Action Fraud, with one clear piece of advice for buyers: always call your lawyer to check before transferring money, because emails can be intercepted or diverted.

Buying a house means wiring a huge amount of money because an email told you where to send it. The account the criminals set up was built to look like the solicitor's, and EFA would put that address next to the real one so the difference is visible. Because the request was for the exact right amount, nothing in the message itself looked wrong — which is why EFA also tells you, in plain words, to confirm payment details by phone before you send anything.

Named Victim — Documented Loss August 2019 Johannesburg, South Africa Home Purchase Fraud

She Was Buying a House. The Bank Details in the Attachment Had Been Swapped.

Total Loss
R5.5 MILLION

Judith Hawarden was buying a home in Forest Town, Johannesburg, and had to pay the balance into the trust account of the law firm Edward Nathan Sonnenbergs (ENSafrica). The firm's banking details were sent to her as a PDF attached to an email from a secretary in its property department. The correspondence was intercepted and the account details in it were substituted for the fraudster's. The email in the chain did not come from the firm at all.

Real
ensafrica.com
Fake
ensafirca.com

On August 22, 2019, Hawarden transferred R5.5 million. It went to the fraudsters and was gone.

Hawarden sued the law firm. In January 2023 the Johannesburg High Court ordered ENSafrica to pay her R5.5 million, plus interest and extra costs as a penalty. ENSafrica appealed, and on June 10, 2024 the Supreme Court of Appeal overturned that ruling, deciding the firm had no legal duty to warn her about the risk. Hawarden did not recover her money. The appeal changed who bore the loss; it did not change how the fraud was carried out.

The real domain was ensafrica.com. The fake one was ensafirca.com. Most people will never notice two letters being swapped in the middle of a long address. EFA does.

Named Victim — Documented Loss February 2020 New York, USA → Germany Fake Invoice

One Misspelled Letter in an Assistant's Address Cost Barbara Corcoran $388,700.

Amount Wired
$388,700

A scammer emailed the "Shark Tank" investor's bookkeeper posing as Corcoran's assistant, using an address that misspelled the real one by a single letter. The message carried an invoice for a real estate renovation — $388,700.11, from a company called FFH Concept GmbH in Germany. Nothing about that is odd for someone who invests in property, which is exactly why nobody questioned it. The bookkeeper wired $388,700 to an account in Germany. Nobody questioned it until the bookkeeper noticed the address was wrong.

Corcoran initially said the money was gone. Her bank then asked the German bank to freeze the transaction while her team proved the payment was fraudulent, and the funds were returned to her in early March 2020 — an outcome that is the exception rather than the rule.

This entire scam came down to one wrong letter in an email address. EFA compares the sender with the people you already know and shows you when the addresses are almost — but not quite — the same.

Named Victim — Documented Loss March – May 2022 Chile → United States Fake Supplier

A Missing "m" Cost Chile's Central Bank $205,000.

Total Loss
USD $205,000

Chile's central bank owed $205,000 to RVK, an American consulting firm that advises on sovereign fund management. Someone set up an email account in the name of the firm's real contact, changing the address only at the very end.

Real
name@rvkinc.com
Fake
name@rvkinc.co

Writing as the consultant, they asked for the payment to go somewhere else instead — to a company called JDB Investment Limited LLC, at a Wells Fargo account in New York. The bank made two transfers, $16,400 and $188,600.

The real consulting firm eventually asked why its invoice from March had not been paid, and confirmed the email account was fake and the money had never reached it. The Banco Central de Chile filed a criminal complaint with Chile's Ministerio Público and opened an internal investigation, which found no evidence of employee involvement and no other funds affected.

A missing letter at the end of an address is almost impossible to catch by eye — rvkinc.co and rvkinc.com look the same in a busy inbox. EFA puts the two side by side and says plainly that they are not the same company. And when that email asks for an invoice to be paid to a completely new beneficiary, EFA warns about the changed payment details too. If a central bank can be caught by one missing character, anyone can.

Named Victim — Documented Loss April 2026 Gainesville, Florida, USA Refund Scam

85-Year-Old Retiree Loses $200,000 in Fake PayPal Refund Scam

Total Loss
$200,000

Brian Oliver received an email claiming PayPal owed him $450. He called the phone number in the email. The scammer walked him through a fake "typo" that appeared to deposit $10,000 into his Bank of America account — except the bank website he was looking at was a mirrored fake. Over the next three days, Oliver fed $10,000 in cash into a crypto ATM and handed $198,560 in gold coins to a courier driving a black Mustang. The password at the door was "blue."

Gainesville Police set up a sting operation. One courier, Seth Wayne, received 18 years in federal prison. A second courier, Atharva Shailesh Sathawane, was convicted of conspiracy and money laundering tied to over 30 transactions and nearly $8 million stolen from elderly victims.

If an email says it's from PayPal but it actually came from a domain PayPal doesn't own, EFA tells you. That warning can come before you call the fake support number and before the scammer ever gets you on the phone.

Named Victim — Documented Loss 2025 Tasmania, Australia Renovation Payment Fraud

The Invoice Was an Exact Replica of the Real One. Only the Account Number Had Changed.

Total Loss — Not Recovered
AUD 120,000

A Tasmanian homeowner renovating her property was corresponding with a construction company when scammers intercepted the email thread. They wrote to her from a spoofed address that closely mimicked the legitimate business, telling her the company had updated its banking details. The invoice they attached was an exact replica of the real one — every line the same, except the payment details, which now pointed to the scammers' account. She paid AUD 120,000.

Because the fraud was reported late, the money was not recovered. The Australian Federal Police published the case in a warning about criminals targeting the construction sector, where large scheduled payments between homeowners, builders and suppliers make an altered invoice unremarkable.

Imagine getting the same invoice you've been expecting, except the bank account has secretly been changed. EFA can warn you about both pieces of the scam: the suspicious sender and the new payment instructions.

Named Victim — Documented Loss September 2019 Dubai, UAE → Russia Fake Supplier

cheersexhibitions.com and cheersexhlbitions.com. A Client Could Not Tell Them Apart.

Total Loss
~$53,000

A fraudster compromised the mailbox of Cheers Exhibition Services, a Dubai exhibition-stand company, and read its correspondence to learn which contracts were live. He then registered a second web address, one letter off from the real one, and wrote to the firm's clients from it — copying the real signatures, logos and invoice formatting.

Real
md@cheersexhibitions.com
Fake
md@cheersexhlbitions.com

A Russian client, paying for a stand at GITEX in Dubai, wired $53,000 (Dh194,700) to an account at a bank in Finland.

The account had been opened in the company's own name by the fraudster. Gulf News reported that police described the operation as far more sophisticated than ordinary phishing — the difference between the two addresses, as investigators put it, was not apparent to the naked eye.

The real address used an "i." The fake one used an "l." In a long email address, they looked almost identical. EFA compares the addresses for you instead of expecting you to spot a one-letter trick with your eyes.

Named Victim — Documented Loss 2021 Chicago, Illinois, USA Wire Fraud / First-Time Buyer

She Saved for Years. One Fake Email Took It All in the Blink of an Eye.

Total Loss
$42,000

Jenna Carlson had saved for years to buy her first home. She was putting 20% down — $42,000. She had exchanged 16 emails with her real estate attorney's paralegal, asking clarifying questions before the wire. One of those emails contained the wiring instructions. She went to the bank and sent the money. The next day, the real paralegal called asking about the down payment. Carlson said she'd already wired it. The paralegal replied: "What email? I didn't send any email." The sender's address was nearly identical to the paralegal's — just two extra letters added.

Chase Bank was able to stop $9,000 of the wire. The other $33,000 was gone. "It was fraud and I'd been scammed," Carlson said. "Everything I'd saved was gone in the blink of an eye. And I couldn't do anything about it." She went through months of therapy to cope with the loss. FBI Special Agent Siobhan Johnson, quoted in the ABC7 story, said real estate wire fraud is one of the fastest-growing cyber scams in the country.

She had already been emailing the real paralegal. Then the wiring instructions came from an address with just two extra letters. EFA would put that new address next to the one she already knew and warn her before she sent the down payment.

Named Victim — Documented Loss 2020 Dubai, UAE Fake Client

One Letter Changed, and the Company Wired Dh100,000 to Strangers.

Total Loss
Dh100,000

A Dubai company received an email from a client it already did business with, asking for dues to be paid. It was not the client. As the prosecutor put it, the suspect had misled the company by creating a similar email format with one letter changed. The company wired Dh100,000. The first suspect received the money and immediately moved it to the second suspect's account.

Dubai prosecutors charged both men with fraud and illegally obtaining Dh100,000, and sent the case to the Misdemeanour Court even though neither man was there to answer it.

The email looked like it came from a client the company already knew. One letter in the address had been changed. That's exactly the kind of difference EFA is there to point out before someone sends the money — it compares the incoming address with the one you've been writing to and shows you both.

Named Victim — Documented Loss 2017 Christchurch, New Zealand Fake University Order

The Purchase Order Came From a University. The University Had Never Heard of It.

Total Loss
NZD 32,000

A Christchurch solar-panel manufacturer was approached by email for a quote on goods, then received a purchase order from what appeared to be a New Zealand university. The address was not the university's. Fraudsters running the scheme used altered addresses impersonating New Zealand universities and a district health board, changed only by minor punctuation — enough to own the address, little enough to read as legitimate. The goods were shipped, the scammers paid the freight, and the invoice went to the institution that had never ordered anything. The manufacturer was left NZD 32,000 out of pocket.

New Zealand Police's financial crime unit reported the pattern hitting hardware and electronics suppliers across the country, and stopped a shipment of 1,000 computer hard drives from reaching the scammers overseas after freight companies flagged the suspicious emails.

If an email says it's from a university but the address doesn't actually belong to that university, EFA warns you. And if this is the first time you've ever heard from them and they're already sending purchase orders or asking for money, EFA gives you another reason to verify who you're dealing with.

Documented Attack Campaign April 2026 26 countries Fake Sign-In Page

The Email Passed Every Security Check. It Was Still a Scam.

Documented Scale
35,000+ users · 13,000+ organizations · 26 countries
Microsoft reports stolen passwords and stolen logins. No financial loss figure is attributed to this campaign.

Over three days in April 2026, Microsoft's Defender research team tracked phishing that reached more than 35,000 users at over 13,000 organizations across 26 countries. The emails were sent through real, legitimate email services, so nothing about them looked broken. They were professionally designed, used an urgent "code of conduct" warning to sound like a message from HR, named the recipient's own company in the text, and claimed to be arriving through an official internal channel — some even included a line insisting the message was genuine. Anyone who followed the link landed on a fake Microsoft sign-in page. Signing in there handed the criminals two things: the password, and the already-approved login that signing in created — which they could reuse to get back into the account without having to sign in again.

An email can pass all the normal security checks and still be a scam. If a message sends you to a fake Microsoft sign-in page to steal your password and your login, EFA looks at what the email is actually asking you to do — not just whether it arrived from a properly set-up mail server.

Documented Attack Campaign March – April 2026 Global Sign-In Code Scam

The Code Was Real. The Reason You Were Given for Entering It Was Not.

Documented Scale
10–15 distinct campaigns launching every 24 hours
Microsoft reports hundreds of organizations compromised daily since mid-March 2026. No financial loss figure is attributed to this campaign.

Microsoft documented widespread account compromise through device-code phishing. The lures were ordinary business themes — invoices, RFPs, shared files, e-signature requests, voicemail and secure-message notices — with generative AI used to tailor them to the recipient's role. Clicking the link opened a page that generated a genuine, live Microsoft device code on the spot and then sent the victim to the real microsoft.com/devicelogin portal to enter it. Everything the victim touched after the email was authentic; approving the code logged the attacker straight into the account.

If someone emails you a sign-in code and tells you to enter it for them, don't. EFA warns you because a real sign-in code is for a sign-in you started yourself — not something a stranger should be asking you to approve.

Documented Attack Campaign 2024 Global QR Code Phishing

They Emailed a Security Company QR Codes. One of Its Own Employees Got Caught.

Documented Outcome
One employee's password and login stolen
No financial loss figure is attributed to this campaign.

Across four waves in 2024, attackers emailed Sophos employees PDF attachments containing QR codes. The documents carried company logos, DocuSign-style branding and a deadline — "this document will expire in 24 hours" — and later versions even included the target's own name and job details. Scanning the code opened a fake Microsoft 365 sign-in page that captured the password and the multi-factor code as they were typed. At least one employee was caught. The attacker walked away with their password and their approved login, and tried to use both to get into internal systems.

A QR code hides where you're about to go. You can't hover over it, you can't read it, and scanning it usually moves you to your phone, where a fake sign-in page is even harder to spot. EFA checks where the code actually leads and warns you before you scan. If a security company's own staff can be caught by this, the lesson isn't that they were careless — it's that a square of dots is not something a person can check.

Documented Attack Campaign 2021 Global Fake Secure Message

"You Have a Secure Message Waiting." You Didn't.

Documented Scale
~75,000 mailboxes potentially exposed
No financial loss figure is attributed to this campaign.

A phishing campaign copied the notification emails sent by Zix, a real company that businesses use to send encrypted email. The messages were titled "Secure Zix message," repeated the claim in a header, and offered one button to read it. The button downloaded an HTML attachment rather than opening anything genuine. The campaign reached around 75,000 mailboxes, with the sharpest targeting aimed at CFOs, directors and company presidents — the people most used to receiving documents that are supposed to be confidential.

A message saying "you have a secure document waiting" is very good bait, because the whole point of a secure message is that you can't see it until you sign in. EFA gives you a reason to stop and check who really sent it before you do. And a genuinely confidential document is sent to you, not to a crowd — so if the same message went out to thousands of people, that's worth knowing too.

Documented Attack Campaign May – June 2025 Global Callback / Fake Invoice

The Invoice Is Fake. The Phone Number Is the Trap.

Brands Impersonated
Microsoft · PayPal · DocuSign · Adobe · McAfee · NortonLifeLock · Geek Squad
No financial loss figure is attributed to this campaign.

Researchers documented a wave of emails with blank bodies and a PDF attached. Open the PDF and you find an invoice for a few hundred dollars from a brand you recognize — McAfee, PayPal, Geek Squad — for something you never bought, plus a phone number to call and sort it out. Some also carried QR codes. The number does not reach the company. It reaches the criminals, who then talk the caller into handing over information or installing software that gives them access to the computer.

If an unexpected invoice says you owe $399 for Geek Squad and gives you a number to call and cancel it, the phone number may be the scam. There's no bad link to click and nothing to download, so the email itself looks harmless — the damage happens on the call. EFA warns you before you dial, and the rule that protects you is simple: look the company's number up yourself instead of using the one in the message.

Documented Attack Campaign 2024 Global Fake Update / Run This Command

The Email Had No Bad Link and No Attachment. It Just Asked You to Run a Command.

Documented Scale
300+ organizations in a single wave
No financial loss figure is attributed to this campaign.

Researchers documented a technique that spread rapidly through 2024 and became known as ClickFix. Emails arrived under ordinary business subjects — one wave posed as GitHub security notifications and reached more than 300 organizations; another used "Important Software Update: Action Required." Some carried nothing malicious at all: no dangerous link, no attachment. What they carried was an instruction. The recipient was shown an error message and a button labeled “Solution” or “How to fix.” Clicking it silently copied a command to the clipboard. Then came the instructions:

  1. Press the Windows key and R
  2. Press Ctrl and V
  3. Press Enter

Three keystrokes, and the victim installed the malware on their own computer. In one version the attackers padded the copied text with a fake “verify you are human” message, so the real command was pushed out of sight in the Run box.

If an email tells you to copy something, open PowerShell or the Run box, and paste it in, don't. EFA warns you because real software updates never work that way — Windows and your applications update themselves, and no legitimate company asks you to type commands from an email into your own computer. This attack exists because scanning tools look for bad links and bad files, and an instruction is neither.

Documented Attack Campaign 2024 – 2026 Global Fake CAPTCHA

"Verify You Are Human." Then It Asked You to Run Something.

Documented Pattern
Fake verification page → user-run command
No financial loss figure is attributed to this campaign.

A variant of the same technique dressed itself as the checkbox everyone has clicked a thousand times. Email recipients who followed a link landed on a page reading "Verify You Are Human" — but instead of ticking a box, they were walked through a short set of steps that ended with them running a command on their own machine. Microsoft has since documented the same pattern being used as the opening move in longer intrusions.

A real "prove you're human" check is a box you tick or a picture you click. It never asks you to copy anything, and it never asks you to open PowerShell. The moment a verification step wants you to run something, it isn't a verification step. EFA warns you when an email leads into that trick, because by the time the fake page is in front of you it looks completely routine.

Documented Attack Campaign 2024 Global — focus on US & Israel Fake Sign-In Pages

A Real Name, a Real-Looking Domain, a Real PDF — and a Fake Sign-In Page.

Documented Scale
50+ Google Sites campaigns disrupted in six months
Google reports targeting and one confirmed account compromise. No financial loss figure is attributed to these campaigns.

Google's Threat Analysis Group documented the Iran-linked group APT42 running phishing built out of borrowed credibility. The attackers wrote under the names of real researchers and journalists, using web addresses like understandingthewar.org and brookings.email — close enough to well-known organizations to feel real at a glance. They often sent a genuinely harmless PDF first to establish trust, then moved targets on to phishing pages and redirects hosted on Google Sites, Google Drive, Dropbox and OneDrive, sometimes via link shorteners, ending at fake Gmail, Outlook and Yahoo sign-in pages. Google says it disrupted the group's abuse of Google Sites across more than 50 similar campaigns in six months.

A familiar name doesn't mean the email is really from that person. A convincing website name doesn't mean it's the real website either. EFA checks the name, the address and the links separately so one good-looking piece doesn't make the whole email feel trustworthy.

Documented Attack December 2016 Berkeley, California, USA Fake Email From the Chancellor

2,000 Berkeley Accounts Got an Email From the Chancellor. None of Them Could See Who Else Did.

Documented Scale
2,000+ campus accounts, all blind-copied
No financial loss figure is attributed to this attack.

More than 2,000 UC Berkeley email accounts received a message appearing to come from Chancellor Nicholas B. Dirks. It did not come from Berkeley at all — the real sender was penweltm@miamioh.edu, an account on a completely different university's domain. Attached was a PDF whose link led to a page asking for a username and password. Berkeley's Information Security Office noted one detail in its write-up:

What the header showed
To: (empty)

More than 2,000 people received the same message, and not one of them could see that anyone else had. They had all been blind-copied.

Being blind-copied is completely normal for a newsletter and completely odd for a personal note from your chancellor. EFA tells you when you weren't actually addressed, because hiding the recipient list is how one message goes to thousands of people while looking like it was written to you. Pair that with a name you trust sitting in front of an address from another university, and there are two separate reasons to slow down.

Documented Attack June 2020 Providence, Rhode Island, USA Gmail’s Own Warning

Gmail Already Knew. It Put a Banner on the Message Before Anyone Reported It.

Documented Outcome
Gmail's own warning fired on a real reported message
No financial loss figure is attributed to this attack.

Brown University's Phish Bowl published a genuine message reported by staff. It carried a colleague's name and the opening line every finance team eventually sees: "Hello Are you available? Please I need your assistance urgently." The real sender was zachmile931@gmail.com. Gmail had already put its own banner across the top: Be careful with this message… is similar to a name in your organization, but the email address does not belong to your domain.

Sometimes your email provider has already decided a message looks wrong. EFA doesn't ignore that. It carries the provider's concern into the same place it explains everything else it found, so you get one clear picture rather than a grey banner you've learned to scroll past. Two independent systems worrying about the same email is worth noticing.

Documented Attack 2025 Global Real Sender, Fake Destination

The Email Really Was From Google. It Was Still a Scam.

Documented Pattern
Genuine Google-signed notification carrying attacker text
No financial loss figure is attributed to this attack.

Attackers registered a Google Workspace trial and a malicious app, then used Google's own notification system to carry their message. The result genuinely came from Google's own systems and was genuinely sent by Google — there was nothing fake about the sender at all. The text inside claimed Google had received a subpoena to release the contents of the recipient's account, with a link to read more. That link went to a fake Google Support page built on sites.google.com, Google's free site-building service.

This is the clearest proof on the page that checking who sent an email is not enough. The sender was real. What gave it away was where it wanted you to go: a company as large as Google does not handle a legal notice about your account through a page somebody built on a free site builder. EFA looks at the destination as well as the sender — and a message threatening you with a subpoena to make you click quickly is its own kind of warning sign.

Documented Attack Campaign June – August 2026 Global Dangerous Attachment

26,589 Emails Said You Had a Voicemail. The Attachment Was Running Code.

Documented Scale
26,589 malicious emails · 5,527 organizations
Tracked June 1 – August 4, 2026. No financial loss figure is attributed to this campaign.

Researchers at INKY tracked a sustained campaign of 26,589 malicious emails reaching 5,527 organizations, each carrying an attachment dressed up as a missed-voicemail notification, often with the recipient's own email address in the subject line. The attachment looked like a picture, but this particular kind of image file can also carry instructions that run in your browser — and that is where the criminals hid their code. The files were even mislabeled so that security scanners would treat them as harmless plain text. The sending pattern was broad and untargeted, arriving in waves and largely skipping weekends.

A "missed voicemail" attachment can look like a harmless picture and still contain code. EFA warns you about the risky file type before you open it — and also recognizes the voicemail story being used to get you to click.

Documented Attack Campaign 2020 – 2021 Global Attached Fake Sign-In Page

The Attachment Looked Like a Spreadsheet. It Was a Fake Sign-In Page in Disguise.

Documented Scale
A year-long campaign, re-disguised every ~37 days
No financial loss figure is attributed to this campaign.

Microsoft tracked an invoice-themed campaign against Office 365 users that ran for more than a year. The attachments were named like this:

Attachment
Payment receipt_4429_18$_Xls.html
Attachment
Contract-1029384756.XLS.html

Read quickly, you see “Xls” and think spreadsheet. The part that matters is the ending — .html — which makes it a web page, not a spreadsheet. The attackers shuffled the capitals as well (xls.HtMl, xsl_x.h_T_M_L) to get past scanners looking for the obvious pattern.

Opening it launched a convincing Microsoft sign-in screen in the browser — loaded from the recipient's own computer, so there was no suspicious web address to notice. To stay ahead of scanners, the attackers re-scrambled how the page was written roughly every 37 days, at one point resorting to encoding parts of it in Morse code.

An attached web page can open what looks exactly like a normal Microsoft sign-in screen. Because the page is sitting on your own machine, the usual advice — check the address bar — doesn't help you. EFA warns you before you open a file that can be used this way. If you were genuinely expecting a document, asking the sender to send it another way costs nothing.

Documented Attack Campaign 2022 – 2026 Global Password-Protected Attachment

They Locked the File and Then Handed You the Key.

Documented Pattern
Locked attachment + password supplied in the same email
No financial loss figure is attributed to this campaign.

QakBot campaigns broke into real email conversations and replied inside them, attaching a password-protected ZIP file and putting the password in the message. That combination is the whole trick: because the file is locked, the security tools scanning the email cannot see what is inside it, so the only thing that opens it is a person following the instructions. Researchers have documented the same approach continuing after QakBot itself was disrupted, picked up by other criminal groups and by state-backed ones.

If an unexpected email sends you a locked file and then hands you the password in the same message, ask what the lock is actually for. It isn't keeping the document private from you — you were just given the key. What it does keep out is the security software that would otherwise look inside. Some companies genuinely do send protected documents, so this isn't proof on its own, but the combination is worth a phone call to the sender on a number you already have.

Documented Attack Campaign February – March 2026 Global Invisible Characters

2.37 Million Emails a Day With Invisible Characters Hidden Inside Ordinary Words.

Documented Scale
Up to 2.37 million messages in a single weekday
No financial loss figure is attributed to this campaign.

Microsoft documented a finance-themed phishing campaign that hid invisible characters inside normal words. A word like "funding" would be written with something you cannot see wedged into the middle of it, so the message read perfectly to a person while filters looking for that word saw something else entirely.

What you see
funding
What is actually there
fun · ding

The dot is ours — it is standing in for a character that has no appearance at all on screen. The real thing is invisible, which is why reading more carefully cannot save you here.

At its peak on February 26, 2026 the campaign pushed up to 2.37 million messages in a day, run from a cluster of 148 finance-themed sender domains, on strict weekday hours.

You see the word “funding.” A filter reading the same email sees something else entirely, because an invisible character has been wedged into the middle of the word. Reading more carefully cannot save you here — there is literally nothing on the screen to notice. EFA checks the characters a message is actually made of, not just how they look.

Documented Attack 2023 Global Web Address That Looks Like a File

microsoft-office365.zip Looks Like a File. It's a Website.

Documented Outcome
Five live phishing sites found and taken down
No financial loss figure is attributed to this attack.

Within weeks of the .zip domain ending going on sale, Netcraft found criminals already using it. Live phishing sites included microsoft-office365.zip and microsoft-office.zip aimed at Microsoft users, e-mails.zip aimed at Google users, and login.payment-statement.zip aimed at Okta users. The point is the confusion: ".zip" is something almost everyone recognizes as a file, so an address like that reads as an attachment you were expecting rather than a website you have never visited.

Most people judge an address by the bit at the end. When that bit is designed to look like a file name, or simply isn't a real ending at all, the usual instinct stops working. EFA reads the end of the address and tells you when it is being used to fool you — before you decide the link is just the document someone promised to send.

Documented Attack Campaign December 2024 Global Fake Calendar Invite

It Looked Like Google Calendar Sent It for Someone You Know.

Documented Scale
4,000+ emails · ~300 brands impersonated in four weeks
No financial loss figure is attributed to this campaign.

Check Point tracked a campaign that changed the hidden sender information on its messages, so an invitation looked like Google Calendar had sent it for someone the recipient actually knew — the kind of line that reads “Google Calendar on behalf of John Smith.” Around 300 brands were impersonated across more than 4,000 emails in four weeks. The invitations first carried malicious calendar files; when security tools began catching those, the attackers switched to links pointing at Google Drawings and Google Forms instead, so the whole chain stayed inside services people already trust.

Plenty of real services send email for other companies — payroll systems, booking tools and calendars all do it, so "on behalf of" is not suspicious by itself. What matters is whether the pairing makes sense. EFA shows you who is actually sending on behalf of whom, instead of letting a familiar name at the front of the message settle the question for you.

Documented Attack Campaign 2021 Global Mass-Produced Web Addresses

c-hi.xyz. a-cl.xyz. p-at.club. Nobody Names a Company That Way.

Documented Scale
350+ machine-generated phishing domains
No financial loss figure is attributed to this campaign.

Microsoft documented a large credential-phishing campaign running on more than 350 domains the attackers had generated by formula rather than chosen — c-hi.xyz, c-tl.xyz, a-cl.xyz, j-on.xyz, p-at.club, f-io.online, all following the same letter-dash-letters pattern across endings like .xyz, .club, .shop and .online. Mail arrived from a mixture of free accounts, hijacked legitimate domains and the attackers' own generated ones. Links passed through a legitimate site's redirect, then a CAPTCHA page, and finally a fake Office 365 sign-in screen already filled in with the victim's own address.

Real businesses pick names people can say out loud. When you need hundreds of throwaway addresses because the old ones keep getting blocked, you stop picking and start generating — and the result looks like a keyboard smash. You shouldn't have to work out whether c-hi.xyz is a company you've heard of. EFA says plainly that the address looks machine-made rather than chosen, and does the same for a sender name that reads like random characters.

Documented Attack 2015 Loudoun County, Virginia, USA Overpayment / Fake Check

The Address Was Built to Stop Existing.

Documented Pattern
Law-enforcement warning naming six throwaway services
No financial loss figure is attributed to this warning.

The Loudoun County Sheriff's Office warned residents about scammers answering online listings from temporary email services — naming Dispostable, GetAirMail, 10MinuteMail, GuerrillaMail, Mailinator and 33Mail. The scam itself was the classic overpayment: the "buyer" sends a check for more than the asking price, asks the seller to wire back the difference, and the check turns out to be worthless days after the money has gone. By then the address that arranged it has expired.

Some email addresses are designed to disappear a few minutes after they're made. There are honest reasons to use one — signing up for something you don't want mail from — but almost none for doing business with a stranger. EFA recognizes the known throwaway services and tells you the address was never meant to last, which is worth knowing before you accept a check from it.

Documented Attack September 2026 United States Email Made of Pictures

The Email Contained Zero Links. Every Pixel of It Was One.

Documented Outcome
Quarantined before any click
No financial loss is documented for this attack.

A phishing email sent to the chief executive of a small energy company impersonated the e-signature service DocuSign. The message showed a DocuSign logo, a headline reading “Find disclosures for your review,” and a PDF filename with a file size beside it. None of it was real text. It was all one picture, the filename was just pixels, and there was no attachment to open. There was not a single ordinary link in the message either, so tools that pull out web addresses and check them found nothing to check. But every click, anywhere on that card, went to the same place. And none of the usual checks on where the message came from had run at all — there was simply nothing there to confirm the sender.

Where every click went
done4you.tv

Not a name anyone would have approved if they had been shown it.

Sometimes scammers turn the whole email into one big picture so normal text and link checks have very little to inspect. EFA warns you when almost the entire message is an image, so you know not to trust what you're seeing just because it looks polished.

Documented Attack March 2026 United States Disguised Letters

The Law Firm's Name Was Spelled With Letters From Another Alphabet.

Documented Outcome
Quarantined across three mailboxes before any click
No financial loss is documented for this attack.

An email impersonating the US law firm Alston & Bird LLP arrived as a genuine Google Drive sharing notice, sent through Google's own systems — so every security check passed, because Google really did send it. The trick was in the name itself.

Normal English letter
o
The letter they used instead
о

If those two look identical to you, that is exactly the point. They are different characters from different alphabets, drawn almost the same way. The “LLP” used odd small capitals instead of ordinary ones, too. On screen, the whole name reads perfectly.

Replies were pointed at an address on cloudsecurityaccess.com, a web address created roughly 22 hours before the message was sent, with no website and no working mail system behind it.

A scammer can use a letter from another alphabet that looks exactly like an English letter. To you, "Alston" still looks like "Alston." EFA checks the actual characters, not just what they look like on the screen, and can warn you when something is being disguised.

Documented Attack Campaign January 2026 Global Fake Internal Email

It Looked Like an Internal SharePoint Notice. It Wasn't From Inside the Company at All.

Documented Pattern
Every check on the sender failed
Microsoft reports a surge in this technique. No financial loss figure is attributed to this campaign.

Microsoft documented criminals taking advantage of companies whose email settings were loose enough to let outsiders pose as insiders. One example was dressed up as a SharePoint notice asking the recipient to review a shared document. In the inbox, the From line looked like this:

What the recipient saw
From: Pending Approval <you@yourcompany.com>

Their own address, sending them a document to review. The system marked it as internal mail, too.

But the checks that run quietly behind every email — the ones that confirm a message really came from where it claims — all failed. It was like someone wearing your company badge and failing the ID check at the door. The links led on to pages the criminals controlled.

The email looked like an internal SharePoint message, but the checks that confirm where a message really came from all failed. EFA tells you when an email looks like it came from inside your company and the sender doesn't hold up — before you click the fake document link.

Documented Attack Campaign 2018 – 2019 12+ countries Scouting for Targets

An Empty Email With No Subject Isn't a Mistake. It's Someone Checking You're Real.

Documented Scale
7,800+ addresses · 3,200+ companies · 12+ countries
Figures are for a single operator. No financial loss figure is attributed to this scouting activity.

Researchers at Agari followed a Nigerian business email compromise group they called Curious Orca and found the step that comes before the fraud. One associate sent blank probe messages — empty, with no subject at all or just the single letter "i" — to more than 7,800 addresses at over 3,200 companies across at least twelve countries since August 2018. There were two forms, and both look like nothing at all:

Subject
(empty)
Subject
i

No message. No request. No link. Just a test to see whether the address was real.

If one doesn't bounce, the address is live and the person behind it goes into a working list; the group's validated database held more than 35,000 financial controllers and accountants at some 28,000 companies. The invoice fraud comes later, aimed only at addresses already proven real.

A blank email from someone you don't know is easy to dismiss as a slip of the finger. Sometimes it is. But business email almost always has a subject, and criminals send empty ones on purpose to find out which addresses are worth attacking. EFA notices the missing subject instead of treating it as nothing — and the useful response is simply not to reply, because a reply is the answer they were looking for.

Documented Attack April 2026 United States Fake Invoice / Payment Switched

The Sender Looked Right. The Reply Was Going Somewhere Else Entirely.

Documented Outcome
Quarantined across three mailboxes before payment
No financial loss is documented for this attack.

A mid-size technology services firm received a "Past due invoice" email whose sender name matched a vendor contact its staff already knew. It passed every security check, because it had genuinely been sent through a real bulk-email service that was allowed to send on that domain's behalf. The body was short and asked for payment to be redirected. The dangerous part was not visible in the message at all.

Shown in the inbox
your vendor’s name
Where a reply would actually go
mail@ilyff.com

That second address sat on a web address the criminals had registered a few weeks earlier. Anyone who hit reply — to confirm the amount, to query the account details — was writing to the attacker while believing they were writing to their vendor. Nobody opens the reply field to check who is on the other end of it, which is the whole reason this works.

The email looked like it came from the real vendor. But if you hit Reply, your answer would have gone to the scammer. EFA warns you when the address you're about to reply to is different from the address that sent the email.

Documented Attack March 2026 United States Fake Executive / Fake Invoice

The Domain Behind the Invoice Was Four Days Old.

Documented Outcome
Detected before payment
No financial loss is documented for this attack.

Attackers registered ceo-coachinginc.com on March 6, 2026 and used it four days later, writing to a sports-technology company as "Carol Smith, CPA" on behalf of the real firm CEO Coaching International. The email carried a fabricated overdue invoice and named a senior executive at the recipient's own company, so the payment appeared to have been agreed further up. The closing line said this was the last communication before the matter went to a collections agency. Replies were pointed at two addresses the criminals controlled: carol@ceo-coachinginc.com, and admin@azur-email.com on a completely unrelated domain. The message passed every security check — but those checks confirmed an unrelated bulk-mail service, not the company the email claimed to be from.

If a company you've supposedly been doing business with emails you from a website address that was created four days ago, that's worth knowing. EFA shows you how new the domain is so you can stop and verify the invoice before paying it.

Documented Attack June – July 2025 Hong Kong Payment Switched / Lookalike Address

The Domain Was Registered the Same Day the Email Was Sent.

Documented Outcome
Caught before any funds were diverted
No financial loss is documented for this attack. Investigators found no evidence that the company's own email tenant was compromised.

A Hong Kong precision manufacturing firm was targeted by an impersonation attack built entirely from outside its systems. The attacker registered a lookalike domain and used it the same day, sending a message styled as a reply within an existing conversation. It carried two forged PDFs, including fake bank letters, designed to push a payment to a different account. The message was sent through a completely different email provider from the one the real company uses — something nobody reading the email could possibly see, but obvious in the message's hidden details. The attempt was caught before any funds moved.

The scammer created the fake domain the same day it was used and then sent forged bank letters telling the company to pay a different account. EFA can warn you that the domain is brand new and that the payment instructions have changed — two very good reasons to make a phone call before sending money.

Our Commitment to You

Every story on this page comes from a real source — police, courts, regulators, security researchers, or the company it happened to. We don’t invent victims and we don’t inflate losses.

Some cases have a named victim and a documented amount of money lost. Others are real attacks that researchers caught, where nobody has published a loss — we label those clearly and never imply a figure that isn’t there. And when we don’t know exactly what the original email looked like, we say so on the case instead of guessing.

They Didn’t See It Coming. You Can.

Every case on this page started with an email.

EFA is built to stop them before the damage is done.

Protect What Matters — $1.99/month

Works with Gmail and Outlook. Install in minutes.