Every week's disclosed breaches, logged and scored — human crews and AI agents on the same page. Each entry answers three questions a board will ask: how bad was it, will it happen again, and do we have the same hole. The recurring answer is identity.
Breaches logged by week of public disclosure, split by who (or what) was at the keyboard. Agent incidents were a curiosity in June. By August they were a category.
Each breach is tagged with the identity weakness that opened (or widened) the path, and the control that would have broken the chain. Click a row to filter the ledger. The Mirror Test plots every breach by how often that gap exists in the wild against how likely the attack is to repeat.
Click any entry for the attack chain, the identity angle, the control that breaks it, and how each score was built. Amber tags mark attacker claims the victim hasn't confirmed.
Scores are The Perimeter's editorial read, built from disclosed facts and published benchmarks — not audited measurements. Every component is visible on each entry, and scores move only when the evidence does.
Blast is how many people or organizations. Data is how sensitive (identity documents and health records sit at the top). Privilege is how deep the attacker got — a marketing inbox is a 3, domain admin is a 10. Ops is operational damage beyond the data.
How likely this breach pattern repeats somewhere in the next quarter. Frequency is computed live from how often the identity vector appears in the ledger (so it rises as the pattern recurs). Ease is attacker cost. Automation is how much of the chain an agent or commodity tool can run unattended.
The share of enterprises that likely carry the same weakness today. Each vector is anchored to a published survey or dataset (below), with a confidence grade. Treat it as a planning estimate for your own gap assessment, not a census.
| Identity vector | Mirror % | Anchor | Confidence | Breaks the chain |
|---|
// New entries, rescored patterns, and the one line to say in your next board meeting