Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Free case studies

Security+ Case Studies: Real Breaches, Explained

Every one of these walks through an incident that actually happened, names the technique behind it, and ends on the control that stops it. Each is filed under the SY0-701 objective it maps to, so you can watch the ones that match whatever you are studying this week. Free, no account needed.

Case studies
23
Runtime
4h 4m
Cost
Free

Looking for the structured course instead? Domain 1 is taught in full on video, free, and every objective in Domains 2 to 5 has a lesson for members.

Domain 2

Threats, Vulnerabilities, and Mitigations

17 case studies

SY0-701 · 2.1

Ransomware as a Service: How the Business Model Works

A leaked internal chat log shows a ransomware crew running payroll, onboarding, and a support desk. How affiliates rent the tooling, where the money splits, and why falling payment rates are squeezing the whole model.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.1

The Dark Web and the Market for Stolen Data

One identity listing followed from a marketplace cart to a seizure banner. What actually changes hands down there, how the markets are structured, and why a network built for anonymity keeps losing to law enforcement.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.1

From Breached Record to Scam Call

One leaked customer record traced from the company that lost it to the caller who reads your own address back to you. How breach data gets aggregated and resold, and where the chain can be broken.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.1

Nation-State Insider Threat: Fake Remote IT Workers

A remote hire cleared four video interviews and a background check, then loaded malware onto the company laptop 25 minutes after it arrived. How the North Korean IT worker scheme is staffed, and which hiring controls catch it.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Vishing at the Help Desk: The 2023 Casino Breaches

An attacker phoned support, cleared identity verification with details anyone could look up, and walked away with a password reset. The influence techniques behind the 2023 casino intrusions, and the verification steps that break them.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Business Email Compromise: Impersonating an Executive

A wire request that reads like it came from the CEO usually never touched his mailbox. How display-name spoofing and lookalike domains slip past a reader, where SPF, DKIM, and DMARC stop short, and the out-of-band check that catches the rest.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Attack Surface: Six Breaches That Started Small

A network-connected fish tank. An unpatched web framework. One reused password. Six well-known breaches ranked by how small the initial entry point was, with the same failure sitting under all of them.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Smishing and Long-Con Investment Fraud

A wrong-number text becomes weeks of friendly conversation and an investment app showing balances that never existed. The structure of the con, and the three tells that surface before any money moves.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Deepfake Impersonation on a Live Video Call

An employee joined a routine call with his CFO and colleagues, approved one transfer, and the company lost about 25 million dollars. Every other participant was synthetic. What the fraud needs to work, and the verification habit that ends it.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Voice Cloning: Vishing With a Familiar Voice

A few seconds of public audio is enough to clone a voice, and then the call comes in at 2 a.m. from someone you trust. How the tooling works now, and why an agreed family code word beats caller ID.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

ClickFix: Fake Verification Prompts That Deliver Malware

A fake bot check copies a command onto the clipboard and coaches the visitor into pasting it into the Run box. Endpoint tooling stays quiet because the user is the one executing, which is exactly the point.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Quishing: Malicious QR Codes as a Phishing Vector

A sticker over a real QR code routes a payment to an attacker page, with no email to inspect and no link text to hover. Why the phone alone will not save you, and the check that takes two seconds.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.2

Removable Media and Wireless Attack Vectors

A Flipper Zero, a keystroke-injecting USB stick, a charging cable with a radio inside. What each cheap device really does, which doors it walks through, and the physical controls that close them.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.4

Session Hijacking: A Stolen Cookie Skips MFA

A valid session token is proof that someone already logged in, so an attacker holding one never meets the password prompt or the code. How the theft happens, shown live, plus the two settings that shorten the window.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.4

Infostealer Malware in Cracked Software

A cracked app or game cheat runs code that copies saved passwords, autofill card data, and live session cookies in a single pass. No password guessing and no MFA prompt, because the credentials were already on the machine.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.4

Evil Twin Access Points and Public Wi-Fi

HTTPS ended casual password sniffing, so the live risk is the rogue access point that becomes the network and serves its own pages. How an evil twin gets set up, and what genuinely protects a client on it.

Watch on YouTube (opens in a new tab)
SY0-701 · 2.4

Password Attacks: Hashing, Salting, and Why Length Wins

How a stolen hash becomes a password again through wordlists, mangling rules, and brute force. Then the part the exam tests: why length beats symbol substitution for surviving that process.

Watch on YouTube (opens in a new tab)
Domain 3

Security Architecture

2 case studies

SY0-701 · 3.2

VPNs: What They Protect and What They Miss

Roughly 95 percent of the web is already encrypted in transit, which removes most of the threat a VPN ad describes. What the tunnel actually hides, where it still earns its keep, and who you hand your traffic to instead.

Watch on YouTube (opens in a new tab)
SY0-701 · 3.3

Identity Theft From Breach Data, and the Credit Freeze

Identity theft usually starts with data that leaked somewhere else and was resold cheap, not with a fresh hack of you. What sits inside one record, what a thief does with it, and the free freeze that shuts the scheme down.

Watch on YouTube (opens in a new tab)
Domain 4

Security Operations

4 case studies

SY0-701 · 4.1

Default Credentials and IoT Botnets

Attackers sweep the internet for factory passwords nobody changed, then herd the devices into a botnet the owner never notices. How the scan works, and the baseline hardening that pulls a device back out of the pool.

Watch on YouTube (opens in a new tab)
SY0-701 · 4.6

MFA Fatigue and Push Bombing: The Uber Breach

Repeated push prompts at 3 a.m. wore one contractor down until he tapped Approve. Why push approval is the softest MFA factor, and what number matching and phishing-resistant factors change.

Watch on YouTube (opens in a new tab)
SY0-701 · 4.6

SIM Swapping: Why SMS Is the Weakest Second Factor

Porting a number away from its owner hands over every code sent to it, which is how one attacker hijacked a U.S. SEC account in 2024. What a carrier checks before a port, and the account lock that raises the bar.

Watch on YouTube (opens in a new tab)
SY0-701 · 4.8

Anatomy of a Ransomware Intrusion, Day 1 to Day 34

One real intrusion traced from the opening phishing email through credential theft, lateral movement, and encryption on day 34. Where the timeline left gaps a defender could have used.

Watch on YouTube (opens in a new tab)

Case studies FAQ

  • Are the Security+ case study videos free?
    Yes. Every case study on this page is free to watch, here or on YouTube, with no account and no payment. They are extra context around the exam objectives, not a replacement for the lessons.
  • How do the case studies map to the exam?
    Each one is filed under the SY0-701 objective it illustrates, shown on the card as the objective code. Most sit in Domain 2 (threats, vectors, and indicators of malicious activity), with the rest under Domain 3 architecture and Domain 4 operations topics like identity, hardening, and incident response.
  • Are these real incidents?
    Yes. Each video walks through a documented breach, scheme, or scam, names the technique behind it, and finishes on the control that stops it. Figures and dates come from public reporting and are given as reported.
  • Can I pass Security+ from the case studies alone?
    No, and they are not meant for that. Case studies make an attack memorable; the exam asks you to pick the right control under time pressure. Work the structured lessons and practice questions for each objective, and use these as the story that makes the concept stick.

Turn the stories into a pass

Case studies show you what an attack looks like. The exam asks you to pick the control that stops it. SecPlus Mastery teaches every objective, then drills you on it with over 1,000 practice questions, timed mock exams, and spaced review.

One-time payment · no subscription · yours to keep

New accounts get 50% off both plans for 7 days: the 90-Day Pass is $19.50 instead of $39.

CompTIA and Security+ are trademarks of CompTIA, used here for identification only. SecPlus Mastery is an independent study resource and is not affiliated with or endorsed by CompTIA.