Threat Actors

Authorized Tester or Researcher

Documented cases attributed to authorized tester or researcher threat actors, sourced and fact-checked.


6 Cases
Confirmed

UIUC USB Drive Drop Field Experiment (2015)

Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up.

Incident 2015Read →
Confirmed

PromptLock: AI-Generated Ransomware Proof-of-Concept Discovered on VirusTotal

ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.

Incident 2025Read →
Confirmed

Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.

Incident 2018Read →
Confirmed

Imperva OpenClaw Message-Object Prompt Injection (vCard/Contact/Geolocation)

Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.

Incident 2026Read →
Confirmed

GAO Covert Testers Use Fake Law-Enforcement Badges and Driver's Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)

Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.

Incident 2000Read →
Confirmed

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.

Incident 2025Read →
Explore more

Browse the rest of the library