Documented cases attributed to authorized tester or researcher threat actors, sourced and fact-checked.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up.
ConfirmedESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.
ConfirmedA Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
ConfirmedImperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
ConfirmedBetween 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.
ConfirmedNoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.