Insider Threat Statistics

166 stats28 sources

Latest Statistics

68% of business admins say employees entering sensitive data into AI is their biggest concern.

Data SecurityInsider RiskAI Risks

48% of security leaders rank AI agents operating with excessive, compromised, or unintended access as the greatest threat to their organization, while 28% rank external threat actors, 12% rank compromised insiders, and 12% rank malicious insiders.

Agentic AIInsider RiskAccess Control

47% of enterprise identity-based attacks are discovered manually: 22% via coworker reports, 15% via internal audits, and 10% via external notifications

Incident DetectionInternal ReportingHiring FraudInsider Threat

Prior to day one, HR leaders claim ownership of identity risk in 53% of cases while IT and security teams claim 17%

Identity AttacksHiring FraudInsider Threat

Nearly 90% of HR leaders report heightened concern over hiring fraud

Hiring FraudInsider Threat

69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.

Proofpoint2026 Voice of the CISO·4w ago
Employee BehaviorInsider ThreatUK

Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.

Proofpoint2026 Voice of the CISO·4w ago
Insider ThreatData LossUK

95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.

Proofpoint2026 Voice of the CISO·4w ago
Insider ThreatData LossUK

Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·2mo ago
Insider Threat

50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments

Insider RiskAI GovernanceFederal agenciesAgentic AI

41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.

Insider ThreatAIHuman Risk

68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.

Human RiskAIInsider Threat

40% of CISOs fear employees are sharing sensitive information with generative AI platforms.

Data SecurityGenerative AIInsider RiskHuman Risk

38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.

Insider ThreatDetectionCritical Alerts

12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.

Access ControlInsider RiskPrivileged Access

80% of organizations report shadow AI (employees connecting AI tools without security or IT review).

Shadow AIInsider RiskAI Security

17% of Nordic CISOs cited insiders & human error as their primary concern.

TruesecNordic CISO Report 2026·4mo ago
The NordicsInsider RiskHuman ErrorSecurity Concerns

Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.

Shadow AIAI AdoptionInsider RiskAgentic AI

Shadow AI is now the third most common non-malicious insider action detected in Verizon's data loss prevention (DLP) dataset in 2025

Shadow AIInsider Risk

13% of employees say they’ve sold or know someone who has sold company login details – often under the belief it’s harmless

CredentialsLogin DetailsInsider ThreatInsider Risk

45% of organizations classify AI copilots and generative AI tools as insider risk.

Gurucul2026 Insider Risk Report·6mo ago
AIInsider RiskAI CopilotsGen AI

90% of organizations experienced at least one insider incident in the past 12 months.

Gurucul2026 Insider Risk Report·6mo ago
Insider RiskInsider Incidents

74% of organizations rank negligent insiders as their top concern, surpassing compromised accounts (65%) and malicious insiders (59%).

Gurucul2026 Insider Risk Report·6mo ago
Insider RiskCompromised AccountsMalicious InsiderNegligent Insiders

50% of enterprises' cyberattacks involved malicious insiders.

Insider ThreatsCyber Attacks

More than 8.2 million phishing emails targeted VIPs in 2025, representing over a quarter of all phishing activity that year.

DarktraceAnnual Threat Report 2026·7mo ago
PhishingInsider RiskEmail Security

Only 19% of organizations classify AI agents as equivalent to human insiders.

Insider RiskAgentic AI

The average annual cost of insider risk reached $19.5 million in 2025, up 20% over two years.

Insider RiskInsider Risk Cost

Organizations experienced an average of 25 insider incidents in 2025.

Insider RiskInsider Incident

46.6% of organizations report Insider Access misuse

Insider ThreatAccess MisuseInsider Access Misuse

60% of insider threat incidents involved personal cloud application instances in 2025.

Insider ThreatCloud ApplicationsPersonal Cloud Application Instances

Malicious insiders accounted for incidents at 36% of organizations.

Insider ThreatsRisk ManagementMalicious Insiders

93% of cybersecurity leaders reported incidents caused by cybercriminals exploiting employees.

Human RiskInsider Threats

58% of organizations attribute their most significant data loss events to careless employees or third-party contractors.

Proofpoint2025 Data Security Landscape·11mo ago
Data lossInsider riskEmployeesThird-party contractors

43% of security professionals are concerned about third-party partners or contractors with access to their environment.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskThird-party partnersThird-party contractors

Only 33% of organizations using DLP agree they gained immediate insight into data usage.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskDLP

37% of organizations reported detecting between 6 and 20 insider-related data loss incidents in the past 18 months.

Fortinet2025 Insider Risk Report·11mo ago
Insider riskData loss

18% of leaders at financial services firms say they are unprepared to recover effectively from an Insider threat or data compromise.

Financial services RecoveryInsider threatData compromise

25% of healthcare organizations cite employees sending PII or PHI to an unintended recipient via email as a primary root cause of incidents.

HealthcareInsider threat

35% of healthcare organizations cite employee negligence because of not following policies as a primary root cause of incidents.

HealthcareInsider threatEmployee negligence

25% of healthcare organizations cite privilege access abuse as a primary root cause of incidents.

HealthcareInsider threatPrivilege access abuse