Insider Threat Statistics

144 stats26 sources

Latest Statistics

Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·1mo ago
Insider Threat

50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments

Insider RiskAI GovernanceFederal agenciesAgentic AI

41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.

Insider ThreatAIHuman Risk

68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.

Human RiskAIInsider Threat

40% of CISOs fear employees are sharing sensitive information with generative AI platforms.

Data SecurityGenerative AIInsider RiskHuman Risk

38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.

Insider ThreatDetectionCritical Alerts

12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.

Access ControlInsider RiskPrivileged Access

80% of organizations report shadow AI (employees connecting AI tools without security or IT review).

Shadow AIInsider RiskAI Security

17% of Nordic CISOs cited insiders & human error as their primary concern.

TruesecNordic CISO Report 2026·2mo ago
The NordicsInsider RiskHuman ErrorSecurity Concerns

Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.

Shadow AIAI AdoptionInsider RiskAgentic AI

Shadow AI is now the third most common non-malicious insider action detected in Verizon's data loss prevention (DLP) dataset in 2025

Shadow AIInsider Risk

13% of employees say they’ve sold or know someone who has sold company login details – often under the belief it’s harmless

CredentialsLogin DetailsInsider ThreatInsider Risk

90% of organizations experienced at least one insider incident in the past 12 months.

Gurucul2026 Insider Risk Report·5mo ago
Insider RiskInsider Incidents

74% of organizations rank negligent insiders as their top concern, surpassing compromised accounts (65%) and malicious insiders (59%).

Gurucul2026 Insider Risk Report·5mo ago
Insider RiskCompromised AccountsMalicious InsiderNegligent Insiders

45% of organizations classify AI copilots and generative AI tools as insider risk.

Gurucul2026 Insider Risk Report·5mo ago
AIInsider RiskAI CopilotsGen AI

50% of enterprises' cyberattacks involved malicious insiders.

Insider ThreatsCyber Attacks

More than 8.2 million phishing emails targeted VIPs in 2025, representing over a quarter of all phishing activity that year.

DarktraceAnnual Threat Report 2026·5mo ago
PhishingInsider RiskEmail Security

46.6% of organizations report Insider Access misuse

Insider ThreatAccess MisuseInsider Access Misuse

The average annual cost of insider risk reached $19.5 million in 2025, up 20% over two years.

Insider RiskInsider Risk Cost

Organizations took an average of 67 days to contain an insider incident, down from 86 days in 2023.

Insider RiskInsider IncidentInsider Incident Containment

Organizations experienced an average of 25 insider incidents in 2025.

Insider RiskInsider Incident

60% of insider threat incidents involved personal cloud application instances in 2025.

Insider ThreatCloud ApplicationsPersonal Cloud Application Instances

Malicious insiders accounted for incidents at 36% of organizations.

Insider ThreatsRisk ManagementMalicious Insiders

93% of cybersecurity leaders reported incidents caused by cybercriminals exploiting employees.

Human RiskInsider Threats

58% of organizations attribute their most significant data loss events to careless employees or third-party contractors.

Proofpoint2025 Data Security Landscape·9mo ago
Data lossInsider riskEmployeesThird-party contractors

Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskSensitive dataSaaSShadow IT

21% of security professionals are concerned about whistleblowers sharing or exposing data.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskData exposure

35% say insufficient budget is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·10mo ago
Insider riskMaturityBudget

18% of leaders at financial services firms say they are unprepared to recover effectively from an Insider threat or data compromise.

Financial services RecoveryInsider threatData compromise

25% of healthcare organizations cite employees sending PII or PHI to an unintended recipient via email as a primary root cause of incidents.

HealthcareInsider threat

35% of healthcare organizations cite employee negligence because of not following policies as a primary root cause of incidents.

HealthcareInsider threatEmployee negligence

25% of healthcare organizations cite privilege access abuse as a primary root cause of incidents.

HealthcareInsider threatPrivilege access abuse

41% of organizations believe AI-driven insider threats are among the most likely AI incidents to impact their organization in the next 12 months.

Acuvity AI2025 State of AI Security·10mo ago
AIInsider threat

Insider threats accounted for 0.8% of initial access vectors.

EuropeInsider threatInitial access vector

46% of financial services leaders highlight insider threats as a top concern.

Financial servicesPen testInsider threat

44% of organizations are prepared for insider threats or account takeover.

Insider threatAccount takeover

Human error remains the top cybersecurity vulnerability in 2025, with 66% of CISOs citing people as their greatest risk.

Proofpoint2025 Voice of the CISO·12mo ago
CISOsHuman errorInsider threat

43% of cybersecurity professionals identified distraction as a primary reason employees fall victim to cyberattacks.

Cyber attackInsider threatHuman error

Nearly a third of organisations still lack dedicated insider risk resources.

Proofpoint2025 Voice of the CISO·12mo ago
CISOsInsider riskInsider threat

92% of organisations attribute at least some data loss to departing employees. This is up from 73% last year.

Proofpoint2025 Voice of the CISO·12mo ago
CISOsData lossCyber riskInsider threat