Data Breaches — 61% Come from Inside a Company
Published September 30, 2025 at 11:21 AM · News Releases and Bulletins

A report from the Ponemon Institute for OPSWAT found 61% of U.S. companies have been victims of data breaches caused by people inside the company. Businesses admitting to the data breaches have averaged eight of them from unauthorized access to confidential information and sensitive information.
Most are malicious.
The average cost to the businesses from those insider assaults is $2.7 million. The sum is derived from fines by regulators, workplace productivity falling off and the loss of data provided by customers.
Here is a tabulation on the damages:
- Diminished employee productivity — 50%
- Loss of customer data — 50%
- Diminished workplace productivity — 49%
- Loss of IP, including trade secrets — 39%
- Ransomware — 36%
- Diminished brand reputation — 26%
- Fines and penalties — 21%
- Other — 6%
Businesses list malicious leakage from insiders as the most serious risk but others rank close to as high:
- 45% data leakage by malicious insiders
- 39% worry about access to visibility and control
- 33% are affected by files and applications taken from 3rd party vendors
Source link: InforSecurity Magazine — https://bit.ly/4pBTBuV
