Almost every breach on this page began with a person, not a vulnerability — a text, a phone call, a WhatsApp thread, a video call with a CFO who wasn't real. Most of it arrived on a phone your MDM will never enrol. Scamless puts an AI scam detector on your employees' personal phones, in the seconds before they answer.
You have spent a decade hardening the paths an attacker used to take. So they stopped taking them. The first contact now happens on a device you don't own, in an app you don't administer, through a channel that has no gateway in front of it.
The opening move is an SMS, a WhatsApp thread, a LinkedIn DM or a voice call. None of it routes through your secure email gateway.
Personal phones aren't enrolled and won't be. Cisco's 2022 intrusion started in an employee's personal Google account, synced from a personal browser.
Push fatigue, genuine codes read aloud to a fake help desk, OAuth consent screens clicked by a vished employee. Every credential in those breaches was valid.
The module was in March. The call came on a Tuesday at 4:50pm from someone who knew the org chart, the tooling and the manager's name.
| Where first contact actually lands | Email gateway |
MDM / EDR |
Identity controls |
Awareness training |
Scamless |
|---|---|---|---|---|---|
| Corporate email | Covered | Partial | Partial | Partial | — |
| SMS to a personal number | None | None | None | Partial | Covered |
| WhatsApp, Telegram, Signal | None | None | None | Partial | Covered |
| Social & recruiter DMs | None | None | None | Partial | Covered |
| Personal email on a personal phone | None | None | None | Partial | Covered |
| Look-alike SSO / payment links | Partial | Partial | Partial | Partial | Covered |
“Partial” is doing a lot of work in that table — a training module and a URL blocklist help, but neither of them is present in the thread at the moment your employee decides to reply.
They were talked into it — through a help desk, a phone call, a text to a personal number, an OAuth consent screen, a video call in which every other participant was generated. Where it wasn't their own employee who was persuaded, it was someone else's: a vendor's support agent, a partner's integration token. Filter by how the attacker got in.
Compiled from public reporting, SEC 8-K filings, breach notifications and vendor incident write-ups. Attribution follows the researchers who published it and is not always confirmed by the affected company. Country labels marked in the source as illustrative are shown plainly here; the pattern, not the jurisdiction, is the point.
Broken English, a robotic voice, a generic greeting, an obviously wrong number. Every one of those signals has been priced out of existence in the last three years.
A finance worker at Arup joined a video call in which every other participant — the CFO included — was AI-generated, and made 15 transfers. Ferrari, LastPass and WPP all had executives cloned from public footage in the same year.
A LinkedIn page, a breach dump and a model are enough to produce a script that names your CFO, your IdP, your ticketing tool and the manager the target reports to. The MGM intrusion started with exactly that homework.
0ktapus texted employees at more than 130 organisations — Twilio, Cloudflare, DoorDash, T-Mobile — on their own phones. There is no queue for you to quarantine and no log for you to hunt in.
MGM, Clorox and Caesars were all entered through a support function that reset a password or an MFA factor for a convincing stranger. Coinbase's attackers skipped persuasion and simply bribed the contractors.
Either a control made the stolen credential worthless, or a human being stopped and asked one more question. There is no third category.
Three of the six were technology catching up after the person had already been fooled. The other three were a person who paused. You cannot roster that, and you cannot train for it reliably. Scamless makes the pause systematic — it arrives in the thread, names the manipulation out loud, and does it whether or not the employee is having a good day.
An Android app on the employee's own phone that reads incoming messages on the device, recognises how a social-engineering attempt behaves, and warns them before they reply, click, approve or pay.
Personal devices are the whole point, which means the deployment has to survive legal, privacy and the works council before it survives your budget. It was built that way.
We agree the population — the whole company, or start with finance, IT, the help desk and the exec team — the seat count, and how it's paid.
We write it with you. They install Scamless, enter your code, and protection is on in two minutes. No ticket, no rollout window, no helpdesk queue.
Adoption, and what your workforce is being targeted with in aggregate. Useful early warning when a campaign starts working your sector — and defensible to every employee who asks.
The security review is the long pole, and we hand you the documentation for it on day one.
You offer it; they choose. There is no enrolment, no profile and no visibility for you into an individual's device or messages — which is exactly why employees accept it where they refuse MDM on a personal handset. Framed as a benefit that also protects their family, take-up looks nothing like a mandated security rollout.
Training is a memory test taken in a quiet room. This is a control that fires in the thread, at 4:50pm, while the message is manufacturing urgency — and it says why the message is wrong rather than asking the employee to recall a slide. The two are complementary: training raises the floor, Scamless is present at the moment of decision.
No. It doesn't touch your network, your identity provider, your CRM or your mail. It reads incoming messages on the employee's device to score them, and the analysis happens there. Nothing about your environment is exposed to us, which also means nothing about us is exposed to your environment — there is no new third-party integration for an attacker to abuse — which is precisely how most of the 2025–26 wave on this page reached its victims.
Scamless ships on Android today, which is where the message-level access that makes this work is available. Ask us for the current iOS position and roadmap on the call — we'll give you a straight answer rather than a date on a slide.
Coverage of your population, and aggregate threat trends: what your people are being targeted with, how it changes quarter to quarter, and when a campaign starts hitting your sector. Combined with the fact that every peer breach in this index reached the same board through the same door, it is an unusually easy slide to defend.
Tell us the population you'd cover. We'll come back with seat pricing, a pilot outline, the privacy and security documentation your review will demand — and a walkthrough of how the attacks in this index would have looked on your employees' phones.
Someone from Scamless will reply within two working days with pricing, a pilot outline and the security documentation pack.
We'll use this only to reply to you. Scamless never reads or sells anyone's data.