---
title: "Human Error: the leading cause of data breaches | Firevault"
description: "74% of breaches involve human error. Phishing, weak passwords and insider mistakes cannot expose data Firevault keeps physically offline."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/threats/human-error#webpage",
      "url": "https://fire-vault.com/threats/human-error",
      "name": "Human Error: the leading cause of data breaches",
      "description": "74% of breaches involve human error. Phishing, weak passwords and insider mistakes cannot expose data Firevault keeps physically offline.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-threats.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/threats/human-error#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/threats/human-error#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Threats",
          "item": "https://fire-vault.com/threats"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Human Error: the leading cause of data breaches",
          "item": "https://fire-vault.com/threats/human-error"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Back to the threat counter](/threats)

Threat brief 

# Human error. The weakest link. 

A firewall cannot stop a convincing email, and encryption does not help when somebody hands over the password. Human psychology remains the most exploited weakness in security.

The headline number 

74%

of breaches involve human error

Social engineering involved

98%

Weak or reused passwords

81%

Phishing as entry point

36%

74%

Breaches involving human error

98%

Attacks using social engineering

81%

Breaches involving weak passwords

34%

Incidents from insiders

The pattern 

## Unglamorous mistakes, expensive consequences

Human error still causes the majority of data incidents recorded in the United Kingdom. The recurring patterns are unglamorous: a misdirected email, a mis-typed cloud storage policy, an accidental deletion on a shared drive, a lost laptop, or a support agent pasting a customer record into the wrong ticket. None of these are exotic attacks, and all of them are cheap to make and expensive to remediate.

The blast radius of any mistake tracks the reach of the account that made it. In a modern environment a single identity often holds read access across production, staging, backups and analytics at the same time. One accidental action can therefore expose or destroy considerably more than the operator ever intended. Reducing standing permissions is the single highest leverage control an organisation can apply against accidental disclosure and accidental loss.

Offline Secure Storage® caps the damage by keeping crown jewel data physically offline. A misdirected email cannot attach a file that lives inside a disconnected vault. An accidental delete on a connected system does not touch the offline copy. A misconfigured cloud policy has no effect on hardware that has no route to the internet. The mistake still happens, it just does not become a headline.

Attack vectors 

## How people are exploited

Four routes account for the overwhelming majority of incidents that begin with a person rather than a payload.

### Phishing Attacks

36% 

Deceptive emails that trick employees into revealing credentials or downloading malware. Attackers impersonate trusted sources like executives, IT support, or vendors.

-   CEO fraud emails
-   Fake invoice attachments
-   Password reset scams

### Weak Passwords

81% 

Password123, company name + year, or reused credentials across systems. Weak passwords can be cracked in seconds, giving attackers full system access.

-   Password reuse across sites
-   Simple dictionary passwords
-   Default credentials left unchanged

### Social Engineering

98% 

Manipulation tactics that exploit human psychology. Attackers build trust, create urgency, or impersonate authority figures to bypass security measures.

-   Pretexting calls to help desk
-   Tailgating into buildings
-   Baiting with infected USB drives

### Insider Threats

34% 

Employees, contractors, or partners with legitimate access who misuse it, whether maliciously or through negligence.

-   Disgruntled employee data theft
-   Accidental data sharing
-   Shadow IT usage

Real cases 

## Large organisations, simple mistakes

These were not sophisticated zero day exploits. They were phone calls and emails.

### MGM Resorts

£79 million 2023 

A 10-minute phone call to the help desk. Attackers impersonated an employee using LinkedIn info to reset credentials.

### Uber

57M users exposed 2016 

Social engineering attack on a contractor. The hacker simply asked for access and was given it.

### Twitter

£200K+ in Bitcoin stolen 2020 

Spear phishing employees via phone, convincing them to hand over internal tool access.

## You cannot train away human nature. 

Awareness training helps, but it cannot eliminate mistakes. The reliable way to protect data from human error is to remove day to day access by keeping the copy physically offline.

[See how Offline Secure Storage® protects](/vault)[Why OSS is different](/why-oss)