Insider Threat Statistics
Insider Threat by Industry
Latest Statistics
68% of business admins say employees entering sensitive data into AI is their biggest concern.
48% of security leaders rank AI agents operating with excessive, compromised, or unintended access as the greatest threat to their organization, while 28% rank external threat actors, 12% rank compromised insiders, and 12% rank malicious insiders.
47% of enterprise identity-based attacks are discovered manually: 22% via coworker reports, 15% via internal audits, and 10% via external notifications
Prior to day one, HR leaders claim ownership of identity risk in 53% of cases while IT and security teams claim 17%
Nearly 90% of HR leaders report heightened concern over hiring fraud
69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.
Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments
41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.
68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.
40% of CISOs fear employees are sharing sensitive information with generative AI platforms.
38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.
12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.
80% of organizations report shadow AI (employees connecting AI tools without security or IT review).
17% of Nordic CISOs cited insiders & human error as their primary concern.
Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.
Shadow AI is now the third most common non-malicious insider action detected in Verizon's data loss prevention (DLP) dataset in 2025
13% of employees say they’ve sold or know someone who has sold company login details – often under the belief it’s harmless
45% of organizations classify AI copilots and generative AI tools as insider risk.
90% of organizations experienced at least one insider incident in the past 12 months.
74% of organizations rank negligent insiders as their top concern, surpassing compromised accounts (65%) and malicious insiders (59%).
50% of enterprises' cyberattacks involved malicious insiders.
More than 8.2 million phishing emails targeted VIPs in 2025, representing over a quarter of all phishing activity that year.
Only 19% of organizations classify AI agents as equivalent to human insiders.
The average annual cost of insider risk reached $19.5 million in 2025, up 20% over two years.
Organizations experienced an average of 25 insider incidents in 2025.
46.6% of organizations report Insider Access misuse
60% of insider threat incidents involved personal cloud application instances in 2025.
Malicious insiders accounted for incidents at 36% of organizations.
93% of cybersecurity leaders reported incidents caused by cybercriminals exploiting employees.
58% of organizations attribute their most significant data loss events to careless employees or third-party contractors.
43% of security professionals are concerned about third-party partners or contractors with access to their environment.
Only 33% of organizations using DLP agree they gained immediate insight into data usage.
37% of organizations reported detecting between 6 and 20 insider-related data loss incidents in the past 18 months.
18% of leaders at financial services firms say they are unprepared to recover effectively from an Insider threat or data compromise.
25% of healthcare organizations cite employees sending PII or PHI to an unintended recipient via email as a primary root cause of incidents.
35% of healthcare organizations cite employee negligence because of not following policies as a primary root cause of incidents.
25% of healthcare organizations cite privilege access abuse as a primary root cause of incidents.