Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Back to Threat Counter
74%

of breaches involve human error

Human Error
The Weakest Link

Firewalls can't stop a convincing email. Encryption won't help if someone hands over the password. Human psychology is the most exploited vulnerability in cybersecurity.

Human error still causes the majority of data incidents recorded in the United Kingdom. The recurring patterns are unglamorous: a misdirected email, a mis-typed cloud storage policy, an accidental deletion on a shared drive, a lost laptop, or a support agent pasting a customer record into the wrong ticket. None of these are exotic attacks; all of them are cheap to make and expensive to remediate.

The blast radius of any mistake tracks the reach of the account that made it. In a modern environment a single identity often holds read access across production, staging, backups and analytics at the same time. One accidental action can therefore expose or destroy considerably more than the operator ever intended. Reducing standing permissions is the single highest-leverage control an organisation can apply against accidental disclosure and accidental loss.

Firevault caps the damage by keeping crown-jewel data physically offline. A misdirected email cannot attach a file that lives inside a disconnected vault. An accidental delete on a connected system does not touch the offline copy. A misconfigured cloud policy has no effect on hardware that has no route to the internet. The mistake still happens; it just does not become a headline.

Attack Vectors

How humans are exploited

Phishing Attacks

36%

Deceptive emails that trick employees into revealing credentials or downloading malware. Attackers impersonate trusted sources like executives, IT support, or vendors.

CEO fraud emailsFake invoice attachmentsPassword reset scams

Weak Passwords

81%

Password123, company name + year, or reused credentials across systems. Weak passwords can be cracked in seconds, giving attackers full system access.

Password reuse across sitesSimple dictionary passwordsDefault credentials left unchanged

Social Engineering

98%

Manipulation tactics that exploit human psychology. Attackers build trust, create urgency, or impersonate authority figures to bypass security measures.

Pretexting calls to help deskTailgating into buildingsBaiting with infected USB drives

Insider Threats

34%

Employees, contractors, or partners with legitimate access who misuse it, whether maliciously or through negligence.

Disgruntled employee data theftAccidental data sharingShadow IT usage
Real Cases

Billion-dollar companies, simple mistakes

These weren't sophisticated zero-day exploits. They were phone calls and emails.

MGM Resorts

£79 million2023

A 10-minute phone call to the help desk. Attackers impersonated an employee using LinkedIn info to reset credentials.

Uber

57M users exposed2016

Social engineering attack on a contractor. The hacker simply asked for access and was given it.

Twitter

£200K+ in Bitcoin stolen2020

Spear phishing employees via phone, convincing them to hand over internal tool access.

You can't train away
human nature

Awareness training helps, but it cannot eliminate mistakes. The only way to fully protect data from human error is to remove human access by taking it offline.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy