Case Library

Download the dataset

All 173 documented cases as structured data, free to reuse with attribution.

Social Engineering Examples, a Diopter AI research project·Licensed CC BY 4.0·Updated 11 Aug 2026

cases.csv
Comma-separated, one row per case. Opens in Excel, Sheets, pandas.
cases.json
JSON with licence and attribution metadata in the envelope.

How to cite this dataset

Social Engineering Examples (Diopter AI). Social Engineering Examples case library, 2026. 173 documented cases. Licensed CC BY 4.0. Available at: https://socialengineeringexamples.com/data

Licence

This dataset is released under the Creative Commons Attribution 4.0 International licence. You may copy, redistribute, adapt and build on it, including commercially, provided you give appropriate credit to Social Engineering Examples, a Diopter AI research project, link back to this page, and indicate if changes were made.

Attribution is carried in the data itself: every row includes an attribution and license field, so credit survives the file being opened, filtered and pasted elsewhere.

What is in each row

FieldDescription
case_idStable slug identifying the case. Also the URL path on this site.
titleCase title as published.
victimNamed organisation or victim group.
incident_dateDate or period of the incident, as reported.
yearFour-digit year of the incident.
countryCountry of the affected organisation, where known.
attack_channelsAttack families, semicolon separated. A case may have more than one.
sectorsSectors affected, semicolon separated.
threat_actorsThreat-actor classification, semicolon separated.
case_typeEither a real-world incident or a research advisory.
statusWhether the case is confirmed or still alleged.
loss_usdVerified single-organisation loss in US dollars, or 0 where none was disclosed. Multi-victim aggregates, modelled estimates and non-USD-only figures are recorded as 0.
loss_basisThe verbatim impact note the figure came from, so you can audit our reading of it.
source_countNumber of sources cited on the case page.
urlCanonical URL of the full case write-up.
attributionRequired credit line. Present on every row.
licenseCC BY 4.0.

Notes on the data

Because a case can carry more than one attack channel or sector, those columns are multi-valued and counts across them sum to more than 173. Do not treat them as mutually exclusive categories.

The loss_usd column is deliberately conservative. Where a source published only an economy-wide model, a figure spanning many victims, or explicitly stated that no amount was ever disclosed, we record 0 rather than a number that would not survive checking. Summary figures are on our statistics page; sourcing rules are in our methodology.

The written case analysis, attack-chain breakdowns and defensive guidance on the case pages are not included in this export and remain the copyright of Diopter AI.