How do human mistakes put my personal information at risk?
Human mistakes—specifically categorized as “Errors”—are a massive threat to personal privacy, acting as causal events in 22% of all analyzed breaches . These accidental slip-ups put personal information at risk in two primary ways:
Misconfiguration of Cloud Storage: This occurs when technical staff or system administrators set up database or cloud storage instances on the internet but neglect to implement basic access controls to limit access . This leaves sensitive datasets entirely open and public, where they are easily found by security researchers or malicious actors scanning the web for exposed systems .
Misdelivery of Sensitive Information: This happens when careless employees accidentally send private records to the wrong person . This can be electronic—such as an email autocomplete mistake sending a sensitive document attachment to an incorrect recipient—or physical, such as mass paper mailings where envelopes and their highly personal contents get out of sync during the mailing process .
Ultimately, the “one-two punch” of hacking and these “benign” human errors makes personal data (such as email addresses, demographics, or medical records) the most commonly compromised attribute variety in data breaches . Because these errors represent short, direct paths to exposure, everyday employee carelessness represents as large a threat to your personal information as the active external hackers trying to steal it .
Who is stealing our data and what do they want?
The vast majority of data theft is carried out by external threat actors, who are responsible for 70% of confirmed data breaches. These external adversaries are primarily professional cybercriminals and organized crime groups. However, a notable portion of threats also comes from within, with internal actors (such as disgruntled or negligent employees) accounting for 30% of breaches.
When it comes to what these attackers want, their primary driver is almost exclusively money. A staggering 86% of breaches are financially motivated, where thieves steal information to cash in through ransomware extortion, financial fraud, or selling stolen details on the dark web. A smaller portion of breaches is driven by espionage, where actors target trade secrets, state-level intelligence, or intellectual property. The specific assets they are looking to steal most are personal data (which is compromised in 58% of breaches) and login credentials (such as usernames and passwords), which serve as easy keys to unlock further accounts and financial systems.
What are the easiest ways hackers get into our accounts?
Cybercriminals prioritize efficiency and always seek the quickest and easiest route to their victims . Rather than relying on complex techniques, they overwhelmingly exploit stolen or brute-forced credentials, which represent the single largest driver of hacking and data breaches overall . In fact, over 80% of hacking-related breaches involve brute force or the use of lost or stolen passwords . Attackers love credentials because they make their jobs much easier, allowing them to simply waltz through the front door of web applications, cloud services, and email accounts . This approach eliminates the need for them to write or deploy malware to maintain access to a system . To gather these passwords, criminals leverage previous data breaches from other companies, amassing vast databases of leaked credentials to test against new victims in automated attacks .
Another extremely common entry point is phishing, which hackers use to trick users into giving away their login information . These deceptive social engineering attacks—which arrive via email 96% of the time—remain highly lucrative because credentials are by far the most common data variety compromised in phishing breaches . Finally, if hackers cannot easily log in with a password, they will look for unpatched vulnerabilities in public web applications . Exploiting vulnerabilities like SQL injection provides a quick and easy way to compromise exposed systems for financial gain . Because attackers prefer short paths with as few steps as possible, implementing multifactor authentication (MFA) is highly recommended to make stolen credentials virtually worthless against an organization’s infrastructure .
Why is money almost always the main motive for cyber attacks?
The primary driver behind the vast majority of malicious data breaches is simply profit, fueled by greed rather than national security or geopolitical objectives . While traditional hacker motives like fun, ideology, or grudges receive significant media and cinematic coverage, they are extremely rare in the real world compared to financial crimes, which account for 86% of all analyzed breaches .
Cybercriminals favor cyber attacks because they have developed direct, highly efficient ways to turn compromised systems and human weaknesses into immediate cash . Rather than dealing with the inefficiency of stealing and trying to sell complex datasets, modern attackers frequently ask for money directly, using financially motivated social engineering or business email compromise schemes to trick victims into initiating bank wire transfers . They also leverage highly effective extortion tactics, holding critical IT infrastructure hostage using ransomware until a cryptocurrency ransom is paid .
Furthermore, if organizations leave their internet-facing systems unsecured, attackers can easily automate the takeover of this hardware to host illicit profitable “services,” transforming the victim’s own infrastructure into a multi-tenant environment at the company’s expense . Ultimately, criminals target digital assets because it represents the quickest, easiest, and most lucrative path to direct payout .
Why is stealing passwords now more popular than spreading malware?
For cybercriminals, stealing passwords (credentials) has become far more popular than spreading malware because it is a much faster, easier, and more efficient way to achieve their goals .
According to the report, malware has been on a consistent and steady decline as a percentage of data breaches over the last five years . This decline has occurred because other common attack methods, such as hacking and social engineering, heavily benefit from stolen credentials . When attackers steal a valid username and password, they no longer need to deploy complex malware to maintain persistence or keep a foothold in a victim’s network .
Ultimately, credentials act like a “set of free keys” to an organization’s digital assets . When hackers can easily obtain these keys, they can simply “waltz in the front door” of cloud email and web applications rather than wasting time and effort trying to break in . Consequently, malware has largely become a tool that “sits idle in the attacker’s toolbox” during simpler, more efficient attacks .
How do simple system errors cause massive corporate data breaches?
Miscellaneous Errors represent a massive portion of data breaches, proving that companies do not always need an external hacker to compromise their security . These incidents are overwhelmingly driven by employee carelessness and play out through two primary mistakes: misconfiguration and misdelivery .
Misconfigurations have surged in popularity, largely because corporations are rapidly moving their data and operations to cloud services . A typical misconfiguration happens when a privileged internal employee—like a system administrator or database administrator—stands up a massive database or storage bucket in the cloud but forgets to enable any security or access controls . This leaves highly sensitive corporate datasets exposed and directly accessible to anyone on the internet . Because these unsecured folders are wide open, security researchers and malicious actors actively crawl the web using automated search tools to locate them . While ethical researchers will report their findings to the company, malicious threat actors will exfiltrate the exposed data and monetize it on the dark web .
The other dominant error is misdelivery, where employees carelessly send sensitive information to the wrong recipients . This often happens electronically when an email autocomplete autofills the incorrect address or physically when a mass mailing’s address envelopes get out of sync with their sensitive contents .
Unlike complex hacking campaigns that involve multiple steps, these simple human errors act as extremely short paths to a data breach . The moment the mistake is committed, the data is immediately exposed to unauthorized parties, resulting in a swift and confirmed disclosure of confidentiality .
Source institutions:Verizon
This content is for reading and understanding research reports. It does not constitute investment advice or trading signals.
Read in App
Read global research reports on mobile.
This content is for research reading and does not constitute investment advice.