of breaches involve human error
Human Error
The Weakest Link
Firewalls can't stop a convincing email. Encryption won't help if someone hands over the password. Human psychology is the most exploited vulnerability in cybersecurity.
Human error still causes the majority of data incidents recorded in the United Kingdom. The recurring patterns are unglamorous: a misdirected email, a mis-typed cloud storage policy, an accidental deletion on a shared drive, a lost laptop, or a support agent pasting a customer record into the wrong ticket. None of these are exotic attacks; all of them are cheap to make and expensive to remediate.
The blast radius of any mistake tracks the reach of the account that made it. In a modern environment a single identity often holds read access across production, staging, backups and analytics at the same time. One accidental action can therefore expose or destroy considerably more than the operator ever intended. Reducing standing permissions is the single highest-leverage control an organisation can apply against accidental disclosure and accidental loss.
Firevault caps the damage by keeping crown-jewel data physically offline. A misdirected email cannot attach a file that lives inside a disconnected vault. An accidental delete on a connected system does not touch the offline copy. A misconfigured cloud policy has no effect on hardware that has no route to the internet. The mistake still happens; it just does not become a headline.
How humans are exploited
Phishing Attacks
36%Deceptive emails that trick employees into revealing credentials or downloading malware. Attackers impersonate trusted sources like executives, IT support, or vendors.
Weak Passwords
81%Password123, company name + year, or reused credentials across systems. Weak passwords can be cracked in seconds, giving attackers full system access.
Social Engineering
98%Manipulation tactics that exploit human psychology. Attackers build trust, create urgency, or impersonate authority figures to bypass security measures.
Insider Threats
34%Employees, contractors, or partners with legitimate access who misuse it, whether maliciously or through negligence.
Billion-dollar companies, simple mistakes
These weren't sophisticated zero-day exploits. They were phone calls and emails.
MGM Resorts
A 10-minute phone call to the help desk. Attackers impersonated an employee using LinkedIn info to reset credentials.
Uber
Social engineering attack on a contractor. The hacker simply asked for access and was given it.
Spear phishing employees via phone, convincing them to hand over internal tool access.