---
title: "Human Error: the leading cause of data breaches | Firevault"
url: https://fire-vault.com/threats/human-error
description: "74% of breaches involve human error. Phishing, weak passwords and insider mistakes cannot expose data Firevault keeps physically offline."
lang: en-GB
---

Back to the threat counter (https://fire-vault.com/threats)

Threat brief

# Human error. The weakest link.

A firewall cannot stop a convincing email, and encryption does not help when somebody hands over the password. Human psychology remains the most exploited weakness in security.

The headline number

74%

of breaches involve human error

Social engineering involved

98%

Weak or reused passwords

81%

Phishing as entry point

36%

74%

Breaches involving human error

98%

Attacks using social engineering

81%

Breaches involving weak passwords

34%

Incidents from insiders

The pattern

## Unglamorous mistakes, expensive consequences

Human error still causes the majority of data incidents recorded in the United Kingdom. The recurring patterns are unglamorous: a misdirected email, a mis-typed cloud storage policy, an accidental deletion on a shared drive, a lost laptop, or a support agent pasting a customer record into the wrong ticket. None of these are exotic attacks, and all of them are cheap to make and expensive to remediate.

The blast radius of any mistake tracks the reach of the account that made it. In a modern environment a single identity often holds read access across production, staging, backups and analytics at the same time. One accidental action can therefore expose or destroy considerably more than the operator ever intended. Reducing standing permissions is the single highest leverage control an organisation can apply against accidental disclosure and accidental loss.

Offline Secure Storage® caps the damage by keeping crown jewel data physically offline. A misdirected email cannot attach a file that lives inside a disconnected vault. An accidental delete on a connected system does not touch the offline copy. A misconfigured cloud policy has no effect on hardware that has no route to the internet. The mistake still happens, it just does not become a headline.

Attack vectors

## How people are exploited

Four routes account for the overwhelming majority of incidents that begin with a person rather than a payload.

### Phishing Attacks

36%

Deceptive emails that trick employees into revealing credentials or downloading malware. Attackers impersonate trusted sources like executives, IT support, or vendors.

- CEO fraud emails
- Fake invoice attachments
- Password reset scams

### Weak Passwords

81%

Password123, company name + year, or reused credentials across systems. Weak passwords can be cracked in seconds, giving attackers full system access.

- Password reuse across sites
- Simple dictionary passwords
- Default credentials left unchanged

### Social Engineering

98%

Manipulation tactics that exploit human psychology. Attackers build trust, create urgency, or impersonate authority figures to bypass security measures.

- Pretexting calls to help desk
- Tailgating into buildings
- Baiting with infected USB drives

### Insider Threats

34%

Employees, contractors, or partners with legitimate access who misuse it, whether maliciously or through negligence.

- Disgruntled employee data theft
- Accidental data sharing
- Shadow IT usage

Real cases

## Large organisations, simple mistakes

These were not sophisticated zero day exploits. They were phone calls and emails.

### MGM Resorts

£79 million 2023

A 10-minute phone call to the help desk. Attackers impersonated an employee using LinkedIn info to reset credentials.

### Uber

57M users exposed 2016

Social engineering attack on a contractor. The hacker simply asked for access and was given it.

### Twitter

£200K+ in Bitcoin stolen 2020

Spear phishing employees via phone, convincing them to hand over internal tool access.

## You cannot train away human nature.

Awareness training helps, but it cannot eliminate mistakes. The reliable way to protect data from human error is to remove day to day access by keeping the copy physically offline.

See how Offline Secure Storage® protects: https://fire-vault.com/vault
Why OSS is different: https://fire-vault.com/why-oss

Get started

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/threats/human-error#webpage",
    "url": "https://fire-vault.com/threats/human-error",
    "name": "Human Error: the leading cause of data breaches",
    "description": "74% of breaches involve human error. Phishing, weak passwords and insider mistakes cannot expose data Firevault keeps physically offline.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-threats.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/threats/human-error#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/threats/human-error#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Threats",
        "item": "https://fire-vault.com/threats"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Human Error: the leading cause of data breaches",
        "item": "https://fire-vault.com/threats/human-error"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```