When security leaders discuss cyber attacks, they often focus on external threat actors. They talk about phishing emails, ransomware strains, and perimeter breaches. However, some of the most damaging cybersecurity incidents start from within the organization.
Today, we are excited to announce the official launch of the Global Insider Threat Tracker.
We built this central public archive to record, categorize, and analyze major insider threat and insider risk incidents from the last 15 years. Whether you are a Chief Information Security Officer (CISO), a threat intelligence analyst, or a security researcher, this interactive database gives you direct visibility into how internal risks have evolved over time.
Why We Created the Global Insider Threat Tracker
For years, security teams have struggled to access clear historical data on insider threats. Most case studies remain buried inside law enforcement press releases, court filings, or expensive private intelligence feeds. As a result, security leaders miss critical patterns in human risk.
We launched the Global Insider Threat Tracker to bridge that gap.
Our database compiles over 500 documented cases spanning from 2010 to the present day. By centralizing these records, we provide an open reference tool for security teams worldwide. You can now examine real incidents, evaluate motives, and strengthen your internal controls against proven threat vectors.
What You Will Find in the Tracker
The database covers a wide spectrum of internal security breaches across government agencies, tech giants, financial institutions, and healthcare providers.
Key Categories Tracked
To help you navigate the data quickly, every record in the tracker falls under one of six primary risk categories:
- Malicious Insider Activity: Unauthorized access, financial fraud, and credential abuse for personal gain.
- Trade Secret Theft: Employees downloading sensitive IP, AI source code, or proprietary designs before leaving a firm.
- Espionage: Nation-state actors or corporate spies gathering intelligence from within high-value target networks.
- Data Leaks: Accidental or intentional disclosures of confidential business files, tax records, or law enforcement data.
- Sabotage: Disgruntled workers altering system settings, lowering credit limits, or destroying internal infrastructure.
- Compromised Access: Internal staff tricked into assisting external criminal syndicates or threat groups.
The Rise of AI and Modern Insider Threats
As you explore the Global Insider Threat Tracker, you will notice a distinct surge in incident volume starting in recent years. Modern technology has drastically reshaped the insider risk landscape.
For instance, generative AI tools and remote access expanded the modern attack surface. Recent entries in our tracker highlight engineers attempting to exfiltrate proprietary machine learning models. Other records show employees uploading classified files directly into public AI chatbots.
Furthermore, social engineering tactics have grown far more sophisticated. Telegram syndicates and romance scams now actively recruit insiders to buy master keys or process illegal transactions. The tracker highlights these shifting trends, helping you prepare your defense against modern threats rather than outdated risks.
How to Use the Tracker for Your Enterprise
You can filter the repository by Year and Category to find the exact case studies relevant to your sector.
Security teams can use these real-world examples to:
- Improve Security Awareness Training: Show staff real cases of accidental leaks and policy violations.
- Refine Monitoring Policies: Adjust Data Loss Prevention (DLP) and User Activity Monitoring (UAM) rules based on real exfiltration methods.
- Present Risk to Executive Leadership: Use documented historical cases to justify investments in insider risk software.
Explore the Tracker Today
Understanding past insider breaches is the first step toward preventing future ones. We invite you to explore the full public archive today and share it with your team.
👉 Visit the Global Insider Threat Tracker to start analyzing 15 years of insider risk data.
Frequently Asked Questions (FAQ)
What is the Global Insider Threat Tracker?
The Global Insider Threat Tracker is a public, searchable database that archives documented insider threat incidents from 2010 to the present day. It categorizes real-world cases involving trade secret theft, financial fraud, espionage, data leaks, and system sabotage.
What qualifies as an insider threat or insider risk?
An insider threat occurs when an individual with authorized access—such as an employee, contractor, or business partner—misuses their privileges to harm an organization. This includes intentional malicious actions like downloading IP, as well as negligent behaviors like uploading confidential data to public AI platforms.
How far back does the historical data go?
The archive tracks over 15 years of security incidents, starting from 2010 through 2026. This long-term timeline allows security researchers to identify long-term trends and shifting exfiltration vectors.
How often is the Global Insider Threat Tracker updated?
Our research team updates the tracker regularly as new legal filings, government press releases, and verified threat intelligence reports become public.
Can security teams submit new insider risk case studies?
Yes. We encourage researchers, CISOs, and incident response teams to submit documented cases. Every submission undergoes verification against primary sources before being published in the public archive.

