Not all breaches begin after threat actors exploit a zero-day vulnerability or launch an increasingly sophisticated phishing campaign — some start with an employee who decides to help attackers walk right through the front door.
A rise in malicious insider threats reflects a good news, bad news situation: organizations are bolstering their security protocols, but cybercriminals are exploiting the one thing that firewalls and VPNs can't defend against—people with legitimate access. Incidents stemming from insider threats can result in ransomware deployment, direct financial loss, compliance violations, and full data exfiltration, just to name a few damaging outcomes.
The annual cost of insider threats hit $19.5 million per organization in 2026, according to SentinelOne. The security company attributed 56% of incidents to negligent insiders falling for phishing lures or losing company devices. They also tied incidents to a rise in shadow artificial intelligence (AI) risks as employees increasingly use unapproved tools.
Related:The Guardrails Debate: Security Researcher Changes His Mind
However, SentinelOne researchers issued another warning: breaches tied to malicious insiders with elevated privileges cost organizations on average around $4.9 million per event, "among the most expensive scenarios tracked."
As the financial fallout climbs, so do rogue insiders. Mimecast's "The State of Human Risk 2026" report found that organizations saw a 42% increase from malicious insiders over the past year.
While negligent insiders remain more common, the growing threat from malicious actors makes it increasingly critical to address both.
'You Don't Want to Piss Off the Guy Who's in Charge of Your Network'
Disgruntled employees have historically accounted for many malicious inside threat scenarios. In 2020 the U.S. Attorney’s Office for the Northern District of Georgia sentenced Christopher Dobbins to federal prison for hacking his former employer, a medical packaging company, and sabotaging its electronic shipping records. His actions cost the company more than $200,000 in damages and delayed shipment of personal protective equipment during the COVID-19 pandemic, according to a press release.
While examining recruitment trends across the Dark Web in July, Flashpoint found that "over 75% of unique threat actor posts came from insiders advertising their access to malicious third parties."
... continue reading