Threat Actors

Unaffiliated Individual

Documented cases attributed to unaffiliated individual threat actors, sourced and fact-checked.


13 Cases
Confirmed

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified.

Incident 2019Read →
Confirmed

Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)

Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.

Incident 2024Read →
Confirmed

Kevin Mitnick's Pretexting of Novell Tech Support (NetWare Source Code Theft)

Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.

Incident 1993Read →
Confirmed

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.

Incident 2020Read →
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.

Incident 2025Read →
Confirmed

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him.

Incident 2024Read →
Confirmed

Johnson County Schools $3.36M fake-Pearson vendor BEC

A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike.

Incident 2024Read →
Confirmed

GTG-5004: UK Threat Actor Uses Claude to Develop and Sell AI-Generated Ransomware-as-a-Service

A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.

Incident 2025Read →
Confirmed

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.

Incident 2023Read →
Confirmed

Federal Pretexting Prosecutions Post-2006: Bunch and Anderson Charged Under New Anti-Pretexting Statute (2008)

In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.

Incident 2008Read →
Confirmed

CoHost's Near-Hire of a Fabricated AI Candidate with Deepfake-Mimicking References

Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose.

Incident 2026Read →
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.

Incident 2025Read →
Confirmed

Twitter July 2020 Account Hijack via Phone Spear Phishing (Vishing)

Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.

Incident 2020Read →
Explore more

Browse the rest of the library