惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
I
InfoQ
H
Help Net Security
GbyAI
GbyAI
博客园 - 叶小钗
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
Y
Y Combinator Blog
L
LangChain Blog
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
F
Fortinet All Blogs
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
博客园 - Franky
D
Docker
Jina AI
Jina AI
罗磊的独立博客

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Cost of Insider Incidents Surges 20% to Nearly $20m
2026-02-24 · via www.infosecurity-magazine.com

Photo of Phil Muncaster

Employee negligence driven by shadow AI cost organizations more than any other type of insider risk last year, accounting for 53% of the $19.5m lost on average per business, according to DTEX.

The security vendor’s Cost of Insider Risks 2026 report was produced by the Ponemon Institute and based on interviews with 8750 IT and security practitioners in 354 global organizations.

Malicious incidents such as sabotage, data theft, fraud and unauthorized disclosure accounted for 27% ($4.7m) of the total lost to insider risks last year, DTEX claimed.

That pales in comparison to negligence (e.g. ignoring IT warnings) and mistakes (e.g. accidentally “pressing the wrong button”), which amounted to an average of $10.3m in losses per company.

A third category of “outsmarted” employees refers to those that may have been phished. This accounted for the smallest share of losses: 20% or $4.5m.

In total, the report catalogued 7490 incidents and recorded a 20% increase in insider-related losses since 2023.

Read more on insider threats: Foreign Interference Drives Record Surge in IP Theft.

Costs related to employee negligence have risen 17% year-on-year, the report found. The main causes were the use of personal webmail, file sharing sites and shadow AI.

Although 73% of respondents are worried that undocumented AI use is creating invisible data loss pathways, just 13% have formally adopted AI technology into their business strategy. Only 18% have fully integrated AI governance policies into their insider risk management program.

The Shadow AI Threat

The report pointed to several risks associated with shadow AI:

  • The inputting of internal documents into public models like ChatGPT
  • AI notetakers producing publicly accessible recordings and summaries containing sensitive internal discussions and PII
  • AI browsers that enable access to malicious sites, AI-assisted torrenting, and NSFW content generation
  • AI browsers and agents accessing corporate systems, performing tasks, and bypassing traditional controls and logging

Blocking AI tools merely encourages staff to use other ones, the report warned.

AI agents are seen as particularly problematic. Over two-fifths (44%) of respondents said that malicious use of agents will “significantly” or “moderately” increase data theft risks, but only 19% classify AI agents as equivalent to human insiders.

Improvements Being Made

However, agents can also be part of the solution. A fifth (19%) of respondents said they’ve deployed AI agents in daily workflows, and 71% rate them important or extremely important for early insider risk detection.

Behavioral analysis was cited as important or essential by 71% of responding organizations.

This is part of the reason why organizations took an average of 67 days to contain an insider incident, down from 86 days.

DTEX urged CISOs to “double down on what works”:

  • Behavioral intelligence to highly “early, non-obvious risk signals” before incidents can escalate
  • Identity-centric security for humans, service accounts and AI agents
  • Defensive AI that improves precision, reduces false positives, and enables risk-aware prevention at scale
  • Governance and data classification to close AI-driven exposure gaps
  • A mindset shift from “human-only risk” to “human-plus-machine risk,” treating AI as an “operational insider