Every case in this library is built from public sources: court filings and indictments, regulatory disclosures (including SEC 8-K filings), company statements and breach notifications, and reporting from established security and business journalism outlets. We link directly to primary sources wherever they exist and prefer them over secondary reporting when the two disagree.
Each case carries a status badge:
Confirmed means the incident, the attack method, and the outcome described are acknowledged by the affected organization, established in court, or reported by multiple independent primary sources.
Alleged means the case is based on an indictment, a lawsuit, a single source, or a disputed account where facts remain contested. We still document these cases because the attack pattern is instructive, but we flag the uncertainty rather than presenting disputed claims as settled fact.
Where a case has more than one relevant date - for example, the year an incident occurred versus the year it was publicly disclosed or resolved in court - we label both explicitly rather than picking one and hiding the other.
We do not include unverified rumors, cases sourced only from anonymous forum posts, or incidents we cannot tie to at least one credible public source. We do not accept payment to include, exclude, or reframe a case.
This is a living library. When new facts emerge, or when we get something wrong, we update the case page and note what changed. If you believe a case is inaccurate or mislabeled, contact us via diopter.ai.