Documented cases attributed to authorized tester or researcher threat actors, sourced and fact-checked.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that up to 98% were picked up and 45% were plugged in and opened, with the first connection occurring in under six minutes, the first rigorous, quantified real-world proof that USB-baiting works.
ConfirmedESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model (gpt-oss:20b via Ollama) to write its malicious Lua exfiltration/encryption logic at runtime, later traced to an NYU Tandon academic research prototype, not a criminal attack.
ConfirmedA Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up on a bystander employee's badge scan, then posed as a new security-team hire at the help desk for 30 minutes to probe whether staff would challenge him. He was ultimately stopped, seven months later, by a guard who cited that very fake-badge incident as the reason for denying access.
ConfirmedImperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields, and geolocation pin labels, invisible to victims because OpenClaw's UI truncated the fields, could make the OpenClaw AI agent silently fetch and execute an attacker-hosted setup.py, a flaw OpenClaw patched in v2026.4.23.
ConfirmedBetween 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test, ordinary driver's licenses) to talk their way past armed-guard checkpoints at federal buildings, including an IRS facility, with a 100% breach rate each time, exposing how a claimed badge of authority overrides physical security screening. No public record substantiates a parallel breach of the U.S. Capitol or the GAO-13-370 report cited in some retellings.
ConfirmedNoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field, then exfiltrated CRM data through an expired, CSP-whitelisted domain they re-bought for $5, when an employee later asked Agentforce about the lead.