Threat Actors

Authorized Tester or Researcher

Documented cases attributed to authorized tester or researcher threat actors, sourced and fact-checked.


6 Cases
Confirmed

UIUC USB Drive Drop Field Experiment (2015)

Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up and 45% were plugged in and opened, with the first connection occurring in under six minutes, the first rigorous, quantified real-world proof that USB-baiting works.

Incident 2015Read →
Confirmed

PromptLock: AI-Generated Ransomware Proof-of-Concept Discovered on VirusTotal

ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model (gpt-oss:20b via Ollama) to write its malicious Lua exfiltration/encryption logic at runtime, later traced to an NYU Tandon academic research prototype, not a criminal attack.

Incident 2025Read →
Confirmed

Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up on a bystander employee's badge scan, then posed as a new security-team hire at the help desk for 30 minutes to probe whether staff would challenge him. He was ultimately stopped, seven months later, by a guard who cited that very fake-badge incident as the reason for denying access.

Incident 2018Read →
Confirmed

Imperva OpenClaw Message-Object Prompt Injection (vCard/Contact/Geolocation)

Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields, and geolocation pin labels, invisible to victims because OpenClaw's UI truncated the fields, could make the OpenClaw AI agent silently fetch and execute an attacker-hosted setup.py, a flaw OpenClaw patched in v2026.4.23.

Incident 2026Read →
Confirmed

GAO Covert Testers Use Fake Law-Enforcement Badges and Driver's Licenses to Breach Federal Buildings, Including an IRS Facility (2000-2009)

Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.

Incident 2000Read →
Confirmed

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field, then exfiltrated CRM data through an expired, CSP-whitelisted domain they re-bought for $5, when an employee later asked Agentforce about the lead.

Incident 2025Read →