Verizon: 74% of Data Breaches Involve the “Human Element”

Stu Sjouwerman | Jun 8, 2023

Data Breach Human ElementPeople are one of the most common factors contributing to successful data breaches. Let’s dive in deeper into the latest Verizon Data-Breach Investigations Report (DBIR) to find out how and why users are a contributor to the problem.

In this year’s newly-released Data Breach Investigations Report, they outline how attackers gain initial access to an organization: “The three primary ways in which attackers access an organization are stolen credentials, phishing and exploitation of vulnerabilities.”

In the figure below, it’s evident that the first two are the primary problem:

5-11-23 Image

Source: Verizon

In fact, use of stolen credentials tops the list of action varieties in data breaches. And while this and phishing are categorized separately in the report, they are intertwined tightly.

According to the report, approximately 90% of initial access involves social engineering and people. Putting this together, it becomes evident that social engineering is used primarily to obtain credentials from a victim that has no idea they are being scammed.

To put it bluntly – your organization needs to ensure it doesn’t become a victim of a credential harvesting attack. Otherwise, you may just become part of the statistics in the report.

Security Awareness Training is key in helping to reduce the likelihood users will fall for social engineering scams – whether in email, on the web, in a text, etc. – designed to harvest credentials (or any other malicious outcome).

In essence, Security Awareness Training is your countermeasure to the “Human Element.”

Topics: Data Breach

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.