How we produce Threat Watcher breakdowns
Threat Watcher is a continuously updated library of real-world phishing, vishing, and social engineering attacks. This page explains how each breakdown is produced, so you know exactly what you’re reading and where it comes from.
Sourcing
Our pipeline monitors more than 250 security news feeds and vendor advisories around the clock. New reports are collected hourly, deduplicated so the same incident isn’t covered twice, and filtered to attacks that involve social engineering: phishing, vishing, business email compromise, deepfakes, and related techniques.
Analysis
Each report is analyzed with AI assistance to extract a concise summary, key findings, the MITRE ATT&CK techniques involved, the industries and roles being targeted, and practical awareness takeaways. Every breakdown links back to the original reporting, and we always credit the source publication.
Video explainers
The videos on each page are original explainers produced by Mirage Security, not clips from the source reporting. We generate them from our analysis of each attack so security teams can share a short, watchable summary with their organization.
Freshness
Pages are refreshed as new intelligence arrives. The “Similar attacks” section on each page is recomputed as related incidents are ingested, and the “Last updated” date reflects the most recent change to the page’s content.
Why we publish this
Mirage Security builds AI-powered social engineering simulations. Threat Watcher is the same intelligence that powers our simulation scenarios, published openly so security teams can keep up with how attackers actually operate. If you spot an error in a breakdown, contact us at hello@miragesecurity.ai and we’ll correct it.