Photo by - Landsmann - on Unsplash
The Common Belief
Fourteen percentage points. That is the entire distance between two of the most-cited breach statistics in the industry, and almost nobody writing about PII breaches stops to ask why the gap exists. The Verizon 2024 Data Breach Investigations Report puts the human element at 68% of breaches. IBM's 2024 X-Force Threat Intelligence Index puts human error at approximately 82%. Both are credible. Both are quoted constantly. They cannot both be measuring the same thing.
According to Google News, the underlying question — which single factor is responsible for most recent PII data breaches — has been circulating in coverage aggregated from outlets including Tycoonstory Media, and the near-universal answer is some version of "people." That answer is correct and nearly useless. The actionable version is narrower: credential abuse and phishing are the delivery mechanisms, misconfiguration is the silent multiplier, and the control that stops the most damage per dollar is not the one most organizations buy first.
As of August 26, 2026, the most recent published figures remain the 2024 reporting cycles from Verizon, IBM, and the Identity Theft Resource Center, and those figures still frame most vendor pitches you will hear this quarter. So it is worth pulling them apart properly.
Where the Numbers Break Down
Start with the divergence, because it is the most informative thing in the data.
Verizon's "human element" is a broad bucket: social engineering, errors, and misuse. IBM's roughly 82% figure counts human error under a different categorical definition. The 14-point spread is not one report being wrong — it is two methodologies drawing the boundary in different places. A skeptic would push back here and say the whole "humans cause breaches" framing is a tautology, since software is written and configured by humans, so of course every incident traces back to a person eventually. That objection is fair, and it is exactly why the broad number is a poor budgeting input.
The narrower numbers are far more useful. IBM's Cost of a Data Breach Report 2024 attributes 16% of breaches to phishing and 15% to stolen or compromised credentials. The Thales Data Threat Report attributes 19% of all 2024 breaches to misconfigured cloud storage and databases. Add those three and you get 50% of breaches concentrated in three named, fixable failure modes — roughly three-quarters of Verizon's 68% human-element bucket, sitting in categories a security team can actually assign an owner to.
Here is the comparison the single-source articles do not make: misconfiguration is individually the largest named cause at 19%, larger than phishing at 16% and larger than credential theft at 15% — yet security awareness training budgets overwhelmingly target the second and third while cloud posture review gets treated as a quarterly chore.
Chart: The broad "human element" category (Verizon DBIR 2024) versus the three named causes that sit inside it — misconfiguration (Thales Data Threat Report), phishing and compromised credentials (IBM Cost of a Data Breach Report 2024). Figures as of the 2024 reporting cycle, current as of August 26, 2026.
And the data being stolen is overwhelmingly personal. Verizon's DBIR 2024 found 74% of breaches involved access to personal data, making PII the most commonly compromised data type. The Identity Theft Resource Center counted over 3,200 data compromises in 2023 affecting more than 350 million individuals in the United States — a ratio of roughly 109,000 exposed individuals per compromise, which tells you the modern breach is not a smash-and-grab on one small database but an aggregation event.
Blast Radius: Who Should Actually Care
Not every organization carries the same exposure, and the honest read is that most small businesses are not the target — they are the delivery route.
IBM put the average breach cost at $4.88 million in 2024, a 10% increase from 2023. Healthcare absorbed an average of $10.93 million, the highest of any industry for the fourteenth consecutive year. Primary data supports the sector concentration: the U.S. Department of Health and Human Services Office for Civil Rights reported 725 healthcare data breaches affecting 500 or more individuals in 2024, with hacking and IT incidents accounting for 79.6% of them.
The under-covered vector is third parties. The Identity Theft Resource Center tracked supply chain and third-party breaches rising 68% year-over-year. That is the number that should reframe how a small firm thinks about its own risk. A twelve-person accounting practice will probably never be worth a targeted campaign, but its file-transfer vendor is — as the MOVEit vulnerability exploitation demonstrated when it reached 2,000-plus organizations, and as the National Public Data breach showed at 2.9 billion exposed records. The blast radius of your vendor is your blast radius.
The regulatory floor moved too. The SEC's cybersecurity disclosure rules, adopted in 2023, require public companies to report material breaches within four business days. The FTC's amended Safeguards Rule, effective June 2023, expanded requirements for financial institutions to include incident response plans and encryption. Meanwhile the FBI's Internet Crime Complaint Center received 880,418 complaints in 2023 with potential losses exceeding $12.5 billion, with phishing, vishing, and smishing as the top crime type by volume.
The AI Angle Cuts Both Ways
AI has made the phishing side cheaper and the detection side better, and for once the defender math is quantified. IBM Security reported that organizations with extensive use of security AI and automation saved an average of $1.76 million per breach compared to those without. Against a $4.88 million average, that is a 36% reduction in cost per incident — the single largest cost-mitigating factor in the report.
Threat actors are running the same playbook in reverse, using generative models for higher-quality phishing and deepfake-assisted social engineering, which is precisely why detection is shifting toward behavioral analytics and anomaly detection rather than content inspection. When the lure is grammatically perfect, you stop grading the email and start grading the login. This is the same cost-versus-capability tradeoff AI Trends documented in enterprise LLM selection — the expensive tier is not automatically the one that pays for itself.
Harden This Today
One control, not thirty.
Misconfiguration is the largest single named cause at 19%, and unlike phishing it requires no adversary skill to exploit — only a scanner. Enumerate every object storage bucket, database, and file share your organization owns, and confirm none permit anonymous or public read. Most cloud providers surface this in a native posture dashboard at no extra cost. It is a one-afternoon control that closes the largest named gap in the data, and it does not depend on any employee making a good decision under time pressure.
After that, in order: enforce phishing-resistant multi-factor authentication on every identity that touches PII (this compresses the 15% credential-theft category more than password rotation ever did), and add a contractual breach-notification clause plus a security questionnaire to every vendor holding your customer data. Security awareness training still belongs in the stack — it is a compensating control, not the primary one.
Bottom line: our analysis is that the 68%-versus-82% argument is a distraction, and the more useful reading of the 2024 data is that half of all breaches trace to three specific, ownable failures — misconfiguration, phishing, and credential abuse. On balance, organizations that treat cloud posture with the same seriousness they give employee training will see the steepest drop in PII exposure, because misconfiguration is the one category where the fix is deterministic and the adversary needs no talent at all. The rest of cybersecurity best practices — threat intelligence feeds, incident response tabletops, data protection tooling — matter, but they matter more once the front door is shut.
Frequently Asked Questions
What is the most common cause of PII data breaches right now?
Broadly, the human element — Verizon's DBIR 2024 attributes 68% of breaches to social engineering, errors, or misuse. Among specifically named causes, misconfigured cloud storage and databases lead at 19% (Thales Data Threat Report), followed by phishing at 16% and stolen or compromised credentials at 15% (IBM, 2024). Figures current as of August 26, 2026.
How much does a data breach cost a company on average?
IBM's Cost of a Data Breach Report 2024 put the global average at $4.88 million, up 10% from 2023. Healthcare was the most expensive sector at $10.93 million per breach, its fourteenth consecutive year at the top. Organizations using security AI and automation extensively saved an average of $1.76 million per incident.
What percentage of data breaches are caused by human error?
It depends on the definition. IBM's 2024 X-Force Threat Intelligence Index puts human error at approximately 82%, while Verizon's DBIR uses a narrower "human element" category at 68%. The discrepancy comes from different categorical boundaries and methodologies, not from either figure being inaccurate. Treat both as directional rather than precise.
How can a small business prevent PII data breaches without a security team?
Start with the two controls that need no headcount: confirm no cloud storage bucket or database is publicly readable, and enforce phishing-resistant multi-factor authentication on every account that touches customer data. Then vet vendors, since third-party and supply chain breaches rose 68% year-over-year per the Identity Theft Resource Center. A written incident response plan is also a regulatory expectation under the FTC's amended Safeguards Rule for financial institutions.
Disclaimer: This article is editorial commentary for informational purposes only and does not constitute professional security consulting advice. No independent product testing was conducted. Always consult a qualified cybersecurity professional for your specific environment. Research based on publicly available sources current as of August 26, 2026.