Social Engineering Examples: A Structured Dataset of 173 Documented Social Engineering Incidents (1978-2026)
收藏资源简介:
A structured, source-verified dataset of 173 documented social engineering incidents spanning 1978 to 2026, compiled from primary sources including regulatory filings, court records, enforcement actions, and reported incident disclosures. Each record captures the victim organisation, incident date, country, attack channel, affected sector, threat actor type where known, case status (confirmed or alleged), and financial loss where a figure is available. Every loss figure carries a written basis explaining its provenance, including explicit notes where no consolidated figure was ever disclosed. The loss_usd field is net of documented recovery, and only rows typed victim_loss or court_award carry a non-zero value, so consult the included README before aggregating. Provenance standard: every case in this dataset is supported by at least two independent sources, with a mean of 6.46 sources per case and no single-source entries. 170 of 173 cases are confirmed; the remaining 3 are explicitly flagged as alleged. The dataset covers social engineering as an attack vector specifically, including phishing, spear phishing, vishing, smishing, quishing, business email compromise, CEO and invoice fraud, deepfake and voice-cloning fraud, help-desk and MFA manipulation, physical intrusion techniques, and prompt-injection attacks on AI agents. Intended for security researchers, risk analysts, insurers, educators, and journalists requiring a citable base of real incidents rather than vendor survey estimates. Case-level narrative detail, defensive analysis, and full source lists for each incident are available at socialengineeringexamples.com. Compiled and maintained by Diopter AI.



