How we produce Threat Watcher breakdowns

Threat Watcher is a continuously updated library of real-world phishing, vishing, and social engineering attacks. This page explains how each breakdown is produced, so you know exactly what you’re reading and where it comes from.

Sourcing

Our pipeline monitors more than 250 security news feeds and vendor advisories around the clock. New reports are collected hourly, deduplicated so the same incident isn’t covered twice, and filtered to attacks that involve social engineering: phishing, vishing, business email compromise, deepfakes, and related techniques.

Analysis

Each report is analyzed with AI assistance to extract a concise summary, key findings, the MITRE ATT&CK techniques involved, the industries and roles being targeted, and practical awareness takeaways. Every breakdown links back to the original reporting, and we always credit the source publication.

Video explainers

The videos on each page are original explainers produced by Mirage Security, not clips from the source reporting. We generate them from our analysis of each attack so security teams can share a short, watchable summary with their organization.

Freshness

Pages are refreshed as new intelligence arrives. The “Similar attacks” section on each page is recomputed as related incidents are ingested, and the “Last updated” date reflects the most recent change to the page’s content.

Why we publish this

Mirage Security builds AI-powered social engineering simulations. Threat Watcher is the same intelligence that powers our simulation scenarios, published openly so security teams can keep up with how attackers actually operate. If you spot an error in a breakdown, contact us at hello@miragesecurity.ai and we’ll correct it.