Last Updated on June 13, 2026 by Arnav Sharma
When I started in security, the insider threat conversation always circled back to the same mental image. A disgruntled employee, a USB stick, a quiet Friday afternoon. That picture is now a museum piece.
The insider threat of 2026 logs in from a kitchen table in another time zone. It pastes confidential code into a chatbot at 11pm. Or it never actually existed in the first place, because the “employee” is three people in Pyongyang sharing a stolen identity.
Most insider threat programs I’ve audited were built around assumptions that stopped being true around 2020. That visibility came from signals clustering in one place (it doesn’t, not when data lives across SaaS tenants and unmanaged personal devices). That identity was just one control among many (with no LAN to hide behind, every insider incident is now an identity event). And that the person on the other end of an account creation form was who they claimed to be and planned to stay.
Ponemon’s 2025 report pegs the annual cost at $17.4 million per organization, and the average containment drags out to 85 days. But the number I keep coming back to is this one: 72% of security leaders say they can’t fully see how users interact with sensitive data across their stack. That’s most programs admitting they’re partially blind and betting the gap won’t get tested. It usually does.
Shadow AI Made Everything Worse
I want to get into generative AI before the case studies because it’s the context that makes all of them scarier.
Here’s the uncomfortable version of what’s happening on the ground. IBM’s 2025 breach data puts unauthorized AI use behind 20% of all breaches last year, with those breaches running $670,000 more expensive on average than non-AI ones. And that number almost certainly undercounts it, because the LayerX data shows that 82% of data pasted into AI chatbots goes through personal accounts that most security teams can’t even see. People are pasting PII, PCI data, source code, internal docs, all of it going to servers your DLP doesn’t know about and your CASB can’t touch.
Everyone cites Samsung in 2023, engineers pasting semiconductor source code into ChatGPT three times in 20 days, and fair enough, it’s a good cautionary tale. But the one that made me genuinely angry was the CISA incident in August 2025. Madhu Gottumukkala, the acting director, uploaded classified government documents to public ChatGPT and set off DHS’s own automated alerts. I don’t know how to say this diplomatically: the person running America’s cybersecurity agency couldn’t stop himself from doing the exact thing his agency publishes guidance against. What hope does your acceptable-use policy have after that?
The Cases That Matter
The Coinbase breach ran from December 2024 through May 2025 and the final remediation estimate landed somewhere between $180 and $400 million, which is a range wide enough to tell you how messy it got. What happened was straightforward in hindsight: cybercriminals bribed BPO support agents at TaskUs, an outsourcer Coinbase had used since 2017, and those agents used their legitimate system access to copy customer records. The part that should worry architects is that the agents could query and export data that their actual job didn’t require them to see. That’s not a technology failure, that’s a role-design failure, and it’s the kind of thing that survives every audit because “customer support needs access to customer data” sounds reasonable until someone gets bribed.
M&S lost about £300 million in April 2025 when Scattered Spider talked a remote TCS contractor into resetting an employee password. Help-desk authority plus weak identity verification plus remote access. That combination keeps showing up and nobody seems to want to fix it.
The Yahoo case is the one I bring up whenever someone tells me their offboarding process is solid. A senior researcher downloaded 570,000 pages of product data to personal storage within 45 minutes of getting a job offer from a competitor. DLP didn’t flag it because the files were compressed. The access termination happened on the last day of employment, which was weeks after the damage was done.
The DPRK Problem
This is the part of the conversation where people’s faces change, because the scale doesn’t seem real until you look at the numbers. North Korea has been running an operation where skilled IT workers, based mostly in the DPRK, China, and Russia, apply for remote jobs at Western companies using stolen or completely fabricated identities. A facilitator in the US receives the company laptop, the real operator remotes in from overseas, and to the company’s systems it looks like a normal employee logging in from Ohio. They use mouse jigglers and IP-KVM devices to simulate activity and Astrill VPN to mask their actual location. CrowdStrike, who tracks this cluster as FAMOUS CHOLLIMA, handled 304 related incidents in 2024 alone, and the total revenue for the regime is estimated between $250M and $600M a year.
The KnowBe4 case is the one that should end every “we’d catch that” conversation. KnowBe4 sells security awareness training. That is their entire business. And they hired a DPRK operative who got through standard vetting with morphed photos and fake credentials. The only reason anyone noticed was that the issued laptop started behaving maliciously after onboarding. No data was breached, but the point stands.
The scheme is spreading, too, with Iranian groups now running similar operations and cases popping up in the UK, Romania, and Poland. There’s also a sanctions angle that most companies haven’t thought through: if you unknowingly pay a DPRK worker, you can face liability under OFAC and DOJ’s Domestic Enabler initiative. What starts as an HR problem becomes a legal one before anyone realises what happened.
Where the Gaps Are
I’ve been asked “so what do we actually do about this” enough times to have a short answer and a long one. The short answer is that you stack controls and accept that each one has holes. The long answer is that three specific holes keep showing up at nearly every organization I work with.
Most teams assume their Zero Trust deployment covers insider behaviour. It doesn’t, and this is the gap that burns people. ZT confirms you are who you say you are. It stops there. If a verified employee starts downloading the entire customer database at 3am or accessing systems they’ve never touched before, ZT has no opinion about it. That’s what UEBA is for, and only 44% of organizations have deployed it. I’ve had conversations where the security lead genuinely believed their identity provider was doing behavioural analysis because the vendor deck mentioned “adaptive risk.” It wasn’t. They were doing step-up auth on suspicious IPs. Different thing entirely. IBM’s 2025 data shows a $1.9M per-breach cost gap between organizations running serious behavioural analytics and those that aren’t.
The identity conversation has also moved on from where a lot of teams think it is. Asking “do you have MFA” is like asking “do you have locks on the doors.” The question now is whether your MFA can survive a fatigue attack, whether your PAM solution does just-in-time elevation or hands out standing privileges, and whether your session credentials are bound to hardware through TPM or whether someone can lift a cookie off an unmanaged laptop and replay it from another country.
And offboarding keeps coming up because the gap between policy and practice is enormous. I’ve worked with teams that have a beautiful offboarding checklist on paper and then execute it two days after the employee has already left, by which point the SaaS tokens are still live and the behavioural analytics weren’t tuned to watch the notice period. Ponemon keeps publishing data showing the notice period is the highest-risk window. Most teams I talk to still treat it like any other two weeks.
For the DPRK-specific hiring risk, the controls are simpler than people expect. Match the face to the ID during a camera-on interview. Verify the laptop’s geolocation after shipping. Don’t accept VoIP numbers. And here’s one I picked up from the CrowdStrike case studies: on the first IT onboarding call, ask the new hire to read the serial number off the bottom of the laptop. If you’re sitting at a desk with the machine, that takes five seconds. If you’re remoting in through a laptop farm in another country, it’s a surprisingly hard question to answer.
What’s Coming
There are two things I think will define this space over the next year or two. The first is AI agents. Only 19% of firms govern them the way they’d govern a human insider, which is a problem when machine identities may outnumber humans 82:1 in some environments. These agents already have delegated authority and cross-system access and persistence, but almost nobody runs them through the same risk framework as a contractor or employee. That’s going to bite someone badly.
The second is that the Coinbase playbook is being adopted by other groups. Iranian actors are copying the DPRK remote-worker scheme, Scattered Spider has made BPO bribery a primary tactic, and the SEC’s disclosure rules mean insider incidents are now landing in public 8-K filings. Boards are about to see this problem in their own liability disclosures.
The program your company wrote five years ago was designed for a world that doesn’t exist anymore. The fixes are well enough understood that I don’t think ignorance is the issue. Getting the organisational buy-in to actually deploy them is.
I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.
Frequently Asked Questions
The five categories are: Negligent Insiders (55-62% of incidents, often unintentional data exposure), Malicious Insiders (25% of incidents, involving theft or sabotage), Compromised Insiders (20% of incidents, where external attackers use stolen credentials), Third-Party Insiders (14% of incidents, contractors with legitimate access), and Synthetic Insiders (fraudulently obtained employment, like the DPRK IT worker schemes). All five categories share identity misuse as a common vulnerability.
Hybrid work has eliminated traditional security perimeters and visibility controls that once clustered endpoint, network, and physical signals together. Remote workers lack colleague oversight, operate on unmanaged personal devices with delayed security updates, and connect through consumer-grade home networks. Data now exists across multiple SaaS platforms and unmanaged devices simultaneously, making it impossible to triangulate 'normal' behavior.
According to Ponemon's 2025 report, the average annual cost of insider threats is $17.4 million per organization, up from $15.4 million in 2022. North American firms average $22.2 million and EMEA averages $20.3 million. Credential theft is the most expensive per-incident category at $779,797, and costs escalate significantly if containment takes longer than 31 days.
According to Ponemon's 2025 Cost of Insider Risks Global Report, 83% of organizations had at least one insider attack in 2024. The average organization experiences 13.5 negligent, 6.3 malicious, and 4.8 credential-theft insider events annually, with an average containment time of 85 days.
Without a network perimeter to hide behind, every modern insider incident is fundamentally an identity event involving credential theft, session hijacking, or trust abuse. Identity is now the critical control because data is distributed across endpoints, SaaS platforms, browsers, and unmanaged devices, making it impossible to rely on traditional network-based security controls. Every insider threat—regardless of type—ultimately exploits identity vulnerabilities.