For security leaders

Your controls end at the device you manage. The attack doesn't.

Almost every breach on this page began with a person, not a vulnerability — a text, a phone call, a WhatsApp thread, a video call with a CFO who wasn't real. Most of it arrived on a phone your MDM will never enrol. Scamless puts an AI scam detector on your employees' personal phones, in the seconds before they answer.

No MDM enrolment. No message content leaves the phone.
Messages · +1 (628) 555-0119
Hi — Marcus from the IT service desk. We're seeing failed logins on your account from outside the US and I'm locking it now.
I've pushed a verification code to your phone. Read it back to me here and re-enrol at
sso-okta-verify.company-hr.co/reset
⚠️ Likely Scam
+1 (628) 555-0119
  • A real help desk never asks you to read back an MFA code
  • Login domain doesn't belong to your company
  • Account-lockout urgency from an unknown number
3 look-alike login domains flagged this month
An intrusion crew only needs one employee.
Scamless is reading every message.
59
incidents below in which attackers went at people and the vendors around them, not your perimeter — public disclosures, 2013–2026
~$100M
EBITDAR impact at MGM Resorts from one call to the help desk — MGM 8-K, Oct 2023
£485M
quarterly pre-tax loss at Jaguar Land Rover after a social-engineering intrusion — JLR results, 2025
6 of 59
were stopped — half of them by a person who simply paused and asked one more question — see below
The gap

Your stack isn't wrong. It's just pointed somewhere else.

You have spent a decade hardening the paths an attacker used to take. So they stopped taking them. The first contact now happens on a device you don't own, in an app you don't administer, through a channel that has no gateway in front of it.

📧
Email security

Never sees the message

The opening move is an SMS, a WhatsApp thread, a LinkedIn DM or a voice call. None of it routes through your secure email gateway.

📱
MDM & EDR

Not on that device

Personal phones aren't enrolled and won't be. Cisco's 2022 intrusion started in an employee's personal Google account, synced from a personal browser.

🔑
MFA & SSO

Approves what the human approves

Push fatigue, genuine codes read aloud to a fake help desk, OAuth consent screens clicked by a vished employee. Every credential in those breaches was valid.

🎓
Awareness training

Recalled in a calm room

The module was in March. The call came on a Tuesday at 4:50pm from someone who knew the org chart, the tooling and the manager's name.

Where first contact actually lands Email
gateway
MDM /
EDR
Identity
controls
Awareness
training
Scamless
Corporate email Covered Partial Partial Partial
SMS to a personal number None None None Partial Covered
WhatsApp, Telegram, Signal None None None Partial Covered
Social & recruiter DMs None None None Partial Covered
Personal email on a personal phone None None None Partial Covered
Look-alike SSO / payment links Partial Partial Partial Partial Covered

“Partial” is doing a lot of work in that table — a training module and a URL blocklist help, but neither of them is present in the thread at the moment your employee decides to reply.

The breach wall

59 companies. Almost none of them were hacked.

They were talked into it — through a help desk, a phone call, a text to a personal number, an OAuth consent screen, a video call in which every other participant was generated. Where it wasn't their own employee who was persuaded, it was someone else's: a vendor's support agent, a partner's integration token. Filter by how the attacker got in.

Compiled from public reporting, SEC 8-K filings, breach notifications and vendor incident write-ups. Attribution follows the researchers who published it and is not always confirmed by the affected company. Country labels marked in the source as illustrative are shown plainly here; the pattern, not the jurisdiction, is the point.

Why now

The tells your training was built around have stopped being tells

Broken English, a robotic voice, a generic greeting, an obviously wrong number. Every one of those signals has been priced out of existence in the last three years.

🎤

The voice and the face are real now

A finance worker at Arup joined a video call in which every other participant — the CFO included — was AI-generated, and made 15 transfers. Ferrari, LastPass and WPP all had executives cloned from public footage in the same year.

Arup · 2024 · ~$25.6M
🔍

Reconnaissance costs nothing

A LinkedIn page, a breach dump and a model are enough to produce a script that names your CFO, your IdP, your ticketing tool and the manager the target reports to. The MGM intrusion started with exactly that homework.

MGM Resorts · 2023 · ~$100M
📲

It arrives where you have no sensor

0ktapus texted employees at more than 130 organisations — Twilio, Cloudflare, DoorDash, T-Mobile — on their own phones. There is no queue for you to quarantine and no log for you to hunt in.

0ktapus · 2022 · 130+ orgs
🎟

The help desk is the new perimeter

MGM, Clorox and Caesars were all entered through a support function that reset a password or an MFA factor for a convincing stranger. Coinbase's attackers skipped persuasion and simply bribed the contractors.

Clorox · 2023 · $380M claimed
What worked

Every attack in this index that failed, failed for one of two reasons

Either a control made the stolen credential worthless, or a human being stopped and asked one more question. There is no third category.

  • Ferrari
    An executive on a call with a deepfaked CEO asked a personal question the impersonator could not answer.
  • LastPass
    An employee receiving deepfake audio of the CEO over WhatsApp noticed the channel was wrong and reported it instead of replying.
  • WPP
    The target of a fake Teams meeting built from public footage of the CEO was simply sceptical.
  • Cloudflare
    Employees did enter their credentials on the 0ktapus phishing page. FIDO2 hardware keys made those credentials useless.
  • Okta
    The stolen Drift OAuth token was genuine. The source IP wasn't allowed, so the query never ran.
  • KnowBe4
    A DPRK operative was hired under a stolen identity and loaded malware on day one. Detection and containment took 25 minutes.

Three of the six were technology catching up after the person had already been fooled. The other three were a person who paused. You cannot roster that, and you cannot train for it reliably. Scamless makes the pause systematic — it arrives in the thread, names the manipulation out loud, and does it whether or not the employee is having a good day.

What Scamless is

An Android app on the employee's own phone that reads incoming messages on the device, recognises how a social-engineering attempt behaves, and warns them before they reply, click, approve or pay.

  • Always on across the apps the first message actually arrives in
  • Explains why it looks wrong — the urgency, the look-alike domain, the MFA-code request
  • Analysis happens on the phone; only suspicious messages are checked in the cloud
  • Installed by the employee in about two minutes — no enrolment, no profile, no agent
Watches
Messages WhatsApp Instagram Messenger X TikTok Telegram TextNow
Catches
Fake help-desk resets MFA code requests Look-alike SSO pages Fake exec payment requests Payroll redirects Fake recruiter lures Vendor invoice fraud Bank impersonation
Rollout

A control you can deploy without an IT project — or a privacy fight

Personal devices are the whole point, which means the deployment has to survive legal, privacy and the works council before it survives your budget. It was built that way.

What your privacy team will ask
  • Detection runs on the device. Only messages that already look suspicious are sent for a second opinion.
  • The employee installs it themselves, on their own phone, and can switch it off at any time.
  • You receive adoption rates and aggregate threat trends for your population — the kind of number a board slide is made of.
  • Seats extend to family members, who are frequently the softer route to the same employee.
  • No MDM enrolment, no management profile, no remote wipe, no device control of any kind.
  • No message content, no contacts, no location, and no per-employee reporting back to you. Ever.
  • Nothing to integrate: no SDK, no IdP change, no connector, no agent inside your network.
1

One call, one decision

We agree the population — the whole company, or start with finance, IT, the help desk and the exec team — the seat count, and how it's paid.

2

One email to your people

We write it with you. They install Scamless, enter your code, and protection is on in two minutes. No ticket, no rollout window, no helpdesk queue.

3

A quarterly picture, never a personal one

Adoption, and what your workforce is being targeted with in aggregate. Useful early warning when a campaign starts working your sector — and defensible to every employee who asks.

4

Live in a month

The security review is the long pole, and we hand you the documentation for it on day one.

Objections

The five questions you're about to ask

It's their personal phone. Can we even offer this?

You offer it; they choose. There is no enrolment, no profile and no visibility for you into an individual's device or messages — which is exactly why employees accept it where they refuse MDM on a personal handset. Framed as a benefit that also protects their family, take-up looks nothing like a mandated security rollout.

How is this different from the awareness training we already buy?

Training is a memory test taken in a quiet room. This is a control that fires in the thread, at 4:50pm, while the message is manufacturing urgency — and it says why the message is wrong rather than asking the employee to recall a slide. The two are complementary: training raises the floor, Scamless is present at the moment of decision.

Does it see any corporate data?

No. It doesn't touch your network, your identity provider, your CRM or your mail. It reads incoming messages on the employee's device to score them, and the analysis happens there. Nothing about your environment is exposed to us, which also means nothing about us is exposed to your environment — there is no new third-party integration for an attacker to abuse — which is precisely how most of the 2025–26 wave on this page reached its victims.

Which platforms are supported?

Scamless ships on Android today, which is where the message-level access that makes this work is available. Ask us for the current iOS position and roadmap on the call — we'll give you a straight answer rather than a date on a slide.

What do I get to show the board?

Coverage of your population, and aggregate threat trends: what your people are being targeted with, how it changes quarter to quarter, and when a campaign starts hitting your sector. Combined with the fact that every peer breach in this index reached the same board through the same door, it is an unusually easy slide to defend.

Get the briefing

Tell us the population you'd cover. We'll come back with seat pricing, a pilot outline, the privacy and security documentation your review will demand — and a walkthrough of how the attacks in this index would have looked on your employees' phones.

🛡️ Thanks — that's on its way.

Someone from Scamless will reply within two working days with pricing, a pilot outline and the security documentation pack.

We'll use this only to reply to you. Scamless never reads or sells anyone's data.

AI-powered scam protection for your digital life. Stay safe across all messaging platforms with real-time threat detection.
Support
© 2026 Protexo.ai. All rights reserved.
Available on