Real incidents against named organisations. Each one records how the attacker got in, what it cost, and the control that would have stopped it.
When an attack reaches the news, two questions matter: how did it actually work, and would our own checks have caught it? Most published material answers neither.
173 cases. 170 confirmed by primary reporting or regulatory filings. Every figure on this page is counted from the records, not estimated.
How the attacker got in.
Who gets targeted.
Who's behind the attack.
Named victims and targets.
How the attack is carried out.
Counted from the 173 cases here, so this is what attackers actually ran rather than a taxonomy. Counts overlap where an attack crossed channels.
| Attack type | What it is | Cases | A documented example |
|---|---|---|---|
| Phishing | A deceptive email that impersonates a trusted sender to steal credentials or trigger a payment. | 62 | Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In (2013) |
| Vishing (Voice Phishing) | A phone call. The attacker impersonates IT, a bank, or an executive and works in real time against your hesitation. | 32 | Retool smishing + deepfake vishing breach (2023) (2023, $15M) |
| Pretexting & Impersonation | An invented but plausible scenario that gives the attacker a reason to be asking, built before any request is made. | 28 | Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025) (2024, $20K) |
| Physical Social Engineering (Tailgating & Baiting) | Getting bodily into a building or dropping a malicious device, by tailgating an employee or posing as a contractor. | 22 | Tennant Co. v. Advance Machine Co. - Dumpster Diving / Conversion Punitive Damages Verdict (1978, $100K) |
| Agentic AI Attacks (AI-Powered Social Engineering) | AI systems that research the target, write the lure, and carry the conversation, letting one operator run thousands of tailored attacks. | 22 | See hub |
| Smishing (SMS Phishing) | The same deception delivered by SMS or a messaging app, where there is no sender address to inspect. | 15 | Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass) (2024) |
| Deepfake & Synthetic Media | A cloned voice or face, used on a call or voicemail so the victim believes they are speaking to someone they know. | 14 | Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M) (2024, $25.6M) |
| ClickFix & SEO Poisoning | A poisoned search result or a fake error telling the user to paste a command, so the victim installs the malware themselves. | 8 | See hub |
| Help-Desk & MFA Manipulation | Calling the service desk as a locked-out employee to have MFA reset, which turns the recovery process into the way in. | 8 | Caesars Entertainment Vendor Social Engineering Breach (2023) (2023, $15M) |
| Quishing (QR Code Phishing) | A QR code that carries the malicious link, moving the click onto a personal phone outside corporate filtering. | 7 | UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset (2024) |
Median disclosed loss across the 52 cases that state a figure in US dollars. We report a median rather than a total because the library records single-victim losses alongside campaign-wide and modelled estimates, and those cannot meaningfully be added together. Non-USD figures are left out rather than converted at a rate we cannot source.
Sorted by the figure the victim or a regulator disclosed. Alleged means reported estimate, not confirmed accounting.
Observations from the corpus itself, not borrowed vendor statistics.
One case, set out the way all 173 are: the sequence on the left, the control that would have broken it on the right.
A few of the most common are below. See all 32 questions, answered from documented cases →