All 173 documented cases as structured data, free to reuse with attribution.
Social Engineering Examples, a Diopter AI research project·Licensed CC BY 4.0·Updated 11 Aug 2026
This dataset is released under the Creative Commons Attribution 4.0 International licence. You may copy, redistribute, adapt and build on it, including commercially, provided you give appropriate credit to Social Engineering Examples, a Diopter AI research project, link back to this page, and indicate if changes were made.
Attribution is carried in the data itself: every row includes an attribution and license field, so credit survives the file being opened, filtered and pasted elsewhere.
| Field | Description |
|---|---|
| case_id | Stable slug identifying the case. Also the URL path on this site. |
| title | Case title as published. |
| victim | Named organisation or victim group. |
| incident_date | Date or period of the incident, as reported. |
| year | Four-digit year of the incident. |
| country | Country of the affected organisation, where known. |
| attack_channels | Attack families, semicolon separated. A case may have more than one. |
| sectors | Sectors affected, semicolon separated. |
| threat_actors | Threat-actor classification, semicolon separated. |
| case_type | Either a real-world incident or a research advisory. |
| status | Whether the case is confirmed or still alleged. |
| loss_usd | Verified single-organisation loss in US dollars, or 0 where none was disclosed. Multi-victim aggregates, modelled estimates and non-USD-only figures are recorded as 0. |
| loss_basis | The verbatim impact note the figure came from, so you can audit our reading of it. |
| source_count | Number of sources cited on the case page. |
| url | Canonical URL of the full case write-up. |
| attribution | Required credit line. Present on every row. |
| license | CC BY 4.0. |
Because a case can carry more than one attack channel or sector, those columns are multi-valued and counts across them sum to more than 173. Do not treat them as mutually exclusive categories.
The loss_usd column is deliberately conservative. Where a source published only an economy-wide model, a figure spanning many victims, or explicitly stated that no amount was ever disclosed, we record 0 rather than a number that would not survive checking. Summary figures are on our statistics page; sourcing rules are in our methodology.
The written case analysis, attack-chain breakdowns and defensive guidance on the case pages are not included in this export and remain the copyright of Diopter AI.