Educational reconstructions. Real breaches, replayed so you can recognise them. Not to alarm you, to prepare you.
BREACHFORGE  CASE FILES

How the big breaches happened

A library of real breaches, replayed stage by stage as the kill chain that actually unfolded. Only what the public record establishes, with every inference marked. Three cases are free to read in full, the rest are part of Pro. Pick one, watch how it ran from the first move to the data leaving the building, then map it to your own estate.

The full case library is part of BreachForge Pro. Three cases are free to read, members read them all. Unlock the full libraryAlready a member, log in
Year
Vector
Sector
Reference architecture Start here
The pension data you never handed over
Capita and USS Hartlink pension breach, 2023, fined October 2025
The case we teach first. A single phished employee, a domain admin account reached in under five hours, and 58 hours before anyone pulled the plug. The failure was timing, and the remedy was mismatched to the harm. Walk the full technical playback, or take the two clocks at a glance.
The case in one comparison
Target response against actual
1 h
58 h to quarantine
The alarm sounded in ten minutes. The response came 58 hours later. A National Insurance number cannot be reissued. The monitoring that protected it lasted twelve months.
See both clocks in full ›
FACT, established in public reporting ASSUMPTION, a reasonable inference, marked LESSON
Educational reconstructions for awareness and training. Sources are listed inside each case file. No customer data is shown. The BreachForge breach library is served live from the threat intel engine.

BreachForge is built and maintained by Saleem Yousaf, Cloud Security Architect and Director at Cyber Spartans Ltd.

saleemyousaf.co.uk cyberspartans.co.uk LinkedIn GitHub