# Day 1 Case-Study Packet

Four ready-made, one-page breach case studies for the Day 1 lab "Spot the Vulnerability" and for the week-long team project. Each file has verified facts and links to authoritative sources (FTC, CISA, GAO, Krebs on Security, SEC, NVD).

For each case study, a team identifies: the **asset**, the **vulnerability**, the **threat** that exploited it, which **CIA pillar** broke (Confidentiality, Integrity, Availability), and one **control** that could have prevented or limited the damage.

- [Equifax 2017](equifax-2017.md) - unpatched web-server flaw, 147 million people.
- [Yahoo 2013](yahoo-2013.md) - 3 billion accounts, weak hashing and slow disclosure.
- [Target 2013](target-2013.md) - vendor access plus no network segmentation, 40 million cards.
- [SolarWinds 2020](solarwinds-2020.md) - trojanized software update, about 18,000 organizations.

All figures are approximate and drawn from the cited sources.
