{"$schema":"https://json-schema.org/draft/2020-12/schema","$id":"https://global-social-engineering-impact-da.vercel.app/api/schema","title":"Social engineering incident record","type":"object","required":["slug","title","date","victim_org","sector","country","primary_vector","ai_involvement","confidence","entry_type","sources"],"properties":{"slug":{"type":"string","description":"Stable identifier and URL path segment."},"title":{"type":"string"},"date":{"type":"string","pattern":"^\\d{4}(-\\d{2}(-\\d{2})?)?$","description":"When the incident occurred, or was disclosed if the occurrence date is unknown."},"date_precision":{"enum":["day","month","year"]},"year":{"type":"integer"},"victim_org":{"type":"string","description":"Targeted organisation, or a description when there is no single victim."},"sector":{"enum":["Financial Services","Technology","Healthcare","Government","Retail","Manufacturing","Energy & Utilities","Telecom","Education","Media & Entertainment","Gaming & Casino","Transportation & Logistics","Professional Services","Nonprofit","Cryptocurrency","Legal","Consumer","Defense","Hospitality","Other"]},"country":{"type":"string"},"entry_type":{"enum":["incident","campaign","benchmark"],"description":"incident = one dated attack; campaign = a sustained multi-victim operation; benchmark = an aggregate agency statistic kept for context and never summed with incident losses."},"primary_vector":{"enum":["Vishing (Voice Phishing)","Deepfake Video Call","Voice Clone / Audio Deepfake","Spear Phishing (Email)","Business Email Compromise","Help Desk Impersonation","MFA Fatigue / Push Bombing","SIM Swap","Smishing (SMS)","Callback Phishing (TOAD)","Physical Pretexting","Insider Recruitment","Fake Job Offer / Recruitment Lure","Vendor / Supply Chain Impersonation","Romance / Investment Scam","Tech Support Scam","QR Code Phishing","Watering Hole / Malvertising","Fake IT Worker Infiltration","Credential Phishing Portal"],"description":"How the attacker reached the human."},"secondary_vectors":{"type":"array","items":{"enum":["Vishing (Voice Phishing)","Deepfake Video Call","Voice Clone / Audio Deepfake","Spear Phishing (Email)","Business Email Compromise","Help Desk Impersonation","MFA Fatigue / Push Bombing","SIM Swap","Smishing (SMS)","Callback Phishing (TOAD)","Physical Pretexting","Insider Recruitment","Fake Job Offer / Recruitment Lure","Vendor / Supply Chain Impersonation","Romance / Investment Scam","Tech Support Scam","QR Code Phishing","Watering Hole / Malvertising","Fake IT Worker Infiltration","Credential Phishing Portal"]}},"ai_involvement":{"enum":["Confirmed AI-enabled","Suspected AI-enabled","No AI reported","Unknown"]},"ai_notes":{"type":"string","description":"What the AI was actually used for."},"outcomes":{"type":"array","items":{"enum":["Wire Fraud / Financial Loss","Data Breach","Ransomware Deployment","Credential Theft","Cryptocurrency Theft","Supply Chain Compromise","Espionage","Service Disruption","Extortion","Attempt Blocked","Identity Theft","Insider Access"]}},"loss_usd":{"type":["number","null"],"description":"Published figure in USD. Null means no figure was published, not zero. Always read loss_kind before comparing or summing this."},"loss_kind":{"type":["string","null"],"enum":["direct_loss","ransom_paid","business_impact","criminal_proceeds","aggregate","seizure",null],"description":"What loss_usd measures. direct_loss = money the victim actually lost; ransom_paid = an extortion payment; business_impact = lost revenue, remediation cost, settlement or damages sought; criminal_proceeds = what the attackers earned; aggregate = a total across many victims or an agency statistic; seizure = the value of assets seized by authorities. ONLY direct_loss and ransom_paid may be summed together."},"loss_note":{"type":"string","description":"Original currency, recovery, and what the number covers."},"records_affected":{"type":["number","null"],"description":"People or records affected as reported. Records overlap across incidents."},"threat_actor":{"type":["string","null"]},"summary":{"type":"string"},"how_it_worked":{"type":"string","description":"The social engineering mechanics: pretext, channel, trust signals abused, pressure applied."},"lessons":{"type":"string","description":"The control that would have caught it."},"confidence":{"enum":["Confirmed","Reported","Alleged"],"description":"Confirmed = victim or authority confirmed it. Reported = credible reporting. Alleged = claimed but unverified."},"sources":{"type":"array","minItems":1,"items":{"type":"object","required":["url"],"properties":{"title":{"type":"string"},"url":{"type":"string","format":"uri"},"publisher":{"type":"string"}}}},"provenance":{"type":"string","enum":["seed","community","auto"],"description":"Where the record came from. \"seed\" shipped in the curated catalogue. \"community\" arrived through the public form and was approved by a human editor. \"auto\" was found by the daily automated research pass and published without a human reading it, though it passed the same validation gate."},"contributed":{"type":"boolean","description":"Legacy alias for provenance === \"community\"."},"url":{"type":"string","format":"uri"}}}