The argument

Many breaches are unnecessary. Four structural controls would have prevented or significantly mitigated 49 of the 76 we analyzed.

Security Blueprints is an educational platform dedicated to helping companies enhance their cybersecurity knowledge and practices. We provide a comprehensive catalog of significant security incidents and data breaches, offering detailed technical analyses of root causes, attack vectors, and impacts. The goal is to study these security incidents for common patterns and lessons to be learned. We will show what security measures could have prevented the incidents and provide security practitioners with data-driven approaches to identify where they can effectively allocate resources to close their existing security gaps. We hope to educate professionals and enthusiasts alike, helping them learn from past incidents to improve organizational security postures.

76
Breaches analysed
4
Invariants
76
Scored corpus
2024
Since

Invariant effectiveness · counted across the corpus

Share of the 76 scored breaches each invariant would have prevented or contained. Counted from the per-breach scores; 0 of the 76 analyses are not scored.

Latest analyses

All 76 →
076

JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)

Contained by: PEC, EGR

JADEPUFFER exploited an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then accessed MinIO, PostgreSQL, MySQL, and Alibaba Nacos environments. The operation encrypted exactly 1,342 Nacos configuration items, deleted original tables, and attempted additional database destruction; a later ENCFORGE payload targeted AI and machine-learning files. No victim organization or affected-person count was publicly reported, and the degree of human involvement in the agentic campaign remains unresolved.

075

Allianz Life Insurance Company of North America Data Breach (July 2025)

A threat actor used social engineering to access a third-party cloud-based CRM used by Allianz Life Insurance Company of North America and exfiltrated sensitive personal information. The incident affected approximately 1.5 million customers, financial professionals, and select employees, with exposed data potentially including names, addresses, dates of birth, Social Security numbers, email addresses, and phone numbers. The responsible threat actor or group was not confirmed, although the breach was linked in reporting to a broader campaign associated with ShinyHunters, Scattered Spider, and UNC6040.

074

Qantas Airways Customer Data Breach (June 2025)

An attacker socially engineered an overseas contact-centre agent into authorizing an attacker-controlled data-extraction application against the agent’s legitimate CRM access. Approximately 5.7 million unique Qantas customer records were affected, including names, email addresses, Frequent Flyer information and, for subsets, addresses, dates of birth, phone numbers, gender and meal preferences. Qantas said passwords, PINs, payment, financial, passport and Frequent Flyer login data were not accessed. The initial intruder attribution was not confirmed; later reporting identified Scattered Lapsus$ Hunters as the collective that reportedly published some records after extortion activity.

073

Conduent Business Services Data Breach (January 2025)

Contained by: EGR

Conduent Business Services discovered unauthorized access to a limited portion of its environment on January 13, 2025, after access that began on October 21, 2024. The actor exfiltrated client-associated files containing personal, medical, health-insurance, claims, and Social Security information; SafePay claimed responsibility and alleged theft of 8.5 terabytes, but the role and volume were not independently confirmed. Publicly reported impact reached at least 25 million people, while later HHS OCR figures and state reports remained inconsistent and unresolved.

The Agent Perimeter Fallacy

Why detection-first security for AI agents repeats the same mistakes as traditional perimeter defense. Structural prevention through security invariants offers a more reliable foundation.

Search the corpus

Full text across 76 breach analyses, 4 invariants and 3 posts.

Now playing Bandcamp