Threat Actors

Unaffiliated Individual

Documented cases attributed to unaffiliated individual threat actors, sourced and fact-checked.


13 Cases
Confirmed

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified family-tie claim, then was found carrying a USB drive initially flagged as containing malware, a determination prosecutors later said may have been a false positive, along with four phones, over $7,600 cash, and a hidden-camera detector.

Incident 2019Read →
Confirmed

Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)

Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to disguise their identity during technical interviews for a Poland-based remote role, and suspected, based on matching vocal accents and one persona's oddly over-rehearsed answers, that both fake personas were run by the same operator.

Incident 2024Read →
Confirmed

Kevin Mitnick's Pretexting of Novell Tech Support (NetWare Source Code Theft)

Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project, defeated a support analyst's voicemail-based identity check by first hijacking that employee's voicemail, and talked his way into a dial-in account used to steal Novell NetWare source code.

Incident 1993Read →
Confirmed

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their late spouse's policy was "in arrears" and draining over $100,000 from them via prepaid gift cards, while separately hiding that income to keep collecting SSI, Medicaid, and HUD housing assistance.

Incident 2020Read →
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.

Incident 2025Read →
Confirmed

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.

Incident 2024Read →
Confirmed

Johnson County Schools $3.36M fake-Pearson vendor BEC

A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike "pearson.quest" domain.

Incident 2024Read →
Confirmed

GTG-5004: UK Threat Actor Uses Claude to Develop and Sell AI-Generated Ransomware-as-a-Service

A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself, then sold the resulting ransomware-as-a-service packages on dark web forums for $400-$1,200 until Anthropic banned the account.

Incident 2025Read →
Confirmed

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried to buy access, operator "CanadianKingpin12" supplied dead credentials and then demanded crypto for a "crack," revealing it as a scam with no working AI product behind the marketing.

Incident 2023Read →
Confirmed

Federal Pretexting Prosecutions Post-2006: Bunch and Anderson Charged Under New Anti-Pretexting Statute (2008)

In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal, Nicholas Shaun Bunch and Vaden Anderson were separately charged in late 2008 with tricking T-Mobile and Sprint/Nextel into handing over customers' confidential call records: one by posing as the account holder with a name and partial Social Security number, the other by serving the carrier a fake federal court subpoena.

Incident 2008Read →
Confirmed

CoHost's Near-Hire of a Fabricated AI Candidate with Deepfake-Mimicking References

Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona whose "references" used voice/video filters mimicking his mannerisms on camera, with every digital trace vanishing within 30 minutes of rejection.

Incident 2026Read →
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.

Incident 2025Read →
Confirmed

Twitter July 2020 Account Hijack via Phone Spear Phishing (Vishing)

Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials, and used internal admin tools to hijack 130 high-profile accounts for a "double your bitcoin" scam.

Incident 2020Read →