Insider Threat Statistics
Insider Threat by Industry
Latest Statistics
Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments
41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.
68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.
40% of CISOs fear employees are sharing sensitive information with generative AI platforms.
38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.
12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.
80% of organizations report shadow AI (employees connecting AI tools without security or IT review).
17% of Nordic CISOs cited insiders & human error as their primary concern.
Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.
Shadow AI is now the third most common non-malicious insider action detected in Verizon's data loss prevention (DLP) dataset in 2025
13% of employees say they’ve sold or know someone who has sold company login details – often under the belief it’s harmless
90% of organizations experienced at least one insider incident in the past 12 months.
74% of organizations rank negligent insiders as their top concern, surpassing compromised accounts (65%) and malicious insiders (59%).
45% of organizations classify AI copilots and generative AI tools as insider risk.
50% of enterprises' cyberattacks involved malicious insiders.
More than 8.2 million phishing emails targeted VIPs in 2025, representing over a quarter of all phishing activity that year.
46.6% of organizations report Insider Access misuse
The average annual cost of insider risk reached $19.5 million in 2025, up 20% over two years.
Organizations took an average of 67 days to contain an insider incident, down from 86 days in 2023.
Organizations experienced an average of 25 insider incidents in 2025.
60% of insider threat incidents involved personal cloud application instances in 2025.
Malicious insiders accounted for incidents at 36% of organizations.
93% of cybersecurity leaders reported incidents caused by cybercriminals exploiting employees.
58% of organizations attribute their most significant data loss events to careless employees or third-party contractors.
Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.
21% of security professionals are concerned about whistleblowers sharing or exposing data.
35% say insufficient budget is the biggest barrier to maturing their insider risk program.
18% of leaders at financial services firms say they are unprepared to recover effectively from an Insider threat or data compromise.
25% of healthcare organizations cite employees sending PII or PHI to an unintended recipient via email as a primary root cause of incidents.
35% of healthcare organizations cite employee negligence because of not following policies as a primary root cause of incidents.
25% of healthcare organizations cite privilege access abuse as a primary root cause of incidents.
41% of organizations believe AI-driven insider threats are among the most likely AI incidents to impact their organization in the next 12 months.
Insider threats accounted for 0.8% of initial access vectors.
46% of financial services leaders highlight insider threats as a top concern.
44% of organizations are prepared for insider threats or account takeover.
Human error remains the top cybersecurity vulnerability in 2025, with 66% of CISOs citing people as their greatest risk.
43% of cybersecurity professionals identified distraction as a primary reason employees fall victim to cyberattacks.
Nearly a third of organisations still lack dedicated insider risk resources.
92% of organisations attribute at least some data loss to departing employees. This is up from 73% last year.