Human error and manipulation, what Verizon calls the human element, was present in 62% of confirmed data breaches in 2026, according to the 19th edition of Verizon's Data Breach Investigations Report (DBIR), up from 60% the year before. That figure covers three distinct causes though: people tricked by an attacker, people who mistakenly misconfigure or misdirect something themselves, and insiders who misuse legitimate access, and the gap between them matters more than the headline number suggests.
What Percentage of Data Breaches Involve Human Error in 2026?
Verizon's 2026 DBIR analyzed more than 31,000 real-world security incidents and confirmed more than 22,000 as actual data breaches, drawn from contributors across 145 countries with a dataset spanning October 2024 through November 2025. Within that dataset, the human element, Social Engineering, Miscellaneous Errors, and Privilege Misuse combined, showed up in 62% of confirmed breaches.
That headline figure sits well above the narrower "pure accident" number. Miscellaneous Errors, the VERIS category for a mistake made with no attacker deception involved, such as sending data to the wrong recipient, accounted for only 8% of breaches in 2026. The rest of the human element figure comes from people being actively manipulated or misusing access they already had, not from carelessness alone.
| Breach pattern | 2026 | 2025 | 2024 |
|---|---|---|---|
| System Intrusion | 61% | 53% | 36% |
| Social Engineering | 17% | 17% | 22% |
| Basic Web Application Attacks | 10% | 18% | 9% |
| Miscellaneous Errors | 8% | 12% | 25% |
| Privilege Misuse | 3% | 7% | 8% |
Table 1: Verizon's top-level VERIS breach patterns by dataset year. Source: Verizon 2026 Data Breach Investigations Report Executive Summary.
What Counts as Human Error Versus the Human Element in a Breach?
Verizon classifies breaches using the VERIS framework, and three of its patterns involve people rather than pure technical exploitation, each with a different mechanism. Only one of the three is "error" in the everyday sense of an accidental mistake.
Figure 1: 2026 breach patterns by VERIS category, sorted by share of breaches. Source: Verizon 2026 Data Breach Investigations Report Executive Summary.
Social Engineering, at 17% of 2026 breaches, means an attacker actively deceived someone, through phishing, pretexting, or a fraudulent call, into taking an action that compromised security. Miscellaneous Errors, at 8%, means no attacker was involved at all: someone misconfigured a server, misdirected an email, or published something that should have stayed private. Privilege Misuse, at 3%, means an insider abused access they were legitimately granted. Reporters and vendors often collapse all three into "human error," which inflates the number well past what a strict reading of the DBIR supports.
Figure 2: How Verizon's VERIS framework splits human involvement into three distinct patterns. Source: Verizon 2026 Data Breach Investigations Report, VERIS framework documentation.
How Has Human Error's Share of Breaches Changed Since 2024?
The narrow Miscellaneous Errors category has fallen fast: from 25% of breaches in the 2024 dataset to 12% in 2025 and 8% in 2026, a drop of more than two-thirds in two years. That decline has not happened because organizations suddenly stopped making mistakes; it has happened because System Intrusion, driven by exploited vulnerabilities and ransomware, has grown so quickly that it now dominates the pattern mix and pushes every other category's share down in relative terms.
Figure 3: Miscellaneous Errors' share of all confirmed breaches, 2024 to 2026 datasets. Source: Verizon Data Breach Investigations Report, 2024 to 2026 editions.
The attacker's preferred entry point has shifted too. Credential abuse, using a stolen or reused password to log in directly, was the leading initial access vector in earlier DBIR datasets. By the 2026 dataset it had fallen to 13%, overtaken by exploitation of software vulnerabilities at 31%, now the single most common way attackers first get in.
Figure 4: How attackers' preferred first foothold changed over four DBIR datasets. Source: Verizon 2026 Data Breach Investigations Report Executive Summary, n=19,905 for the 2026 dataset.
Two related findings explain part of the shift. Only 26% of critical vulnerabilities in the CISA Known Exploited Vulnerabilities catalog were fully remediated by affected organizations in the 2026 dataset, down from 38% the year before, and the median time to full resolution rose to 43 days from 32 days. Slower patching gives exploitation of vulnerabilities more time to work as an access route, which shows up directly in the initial-access mix.
Which Industries Have the Most Human-Error-Driven Breaches?
Human element share varies widely by industry, from under half of breaches in small and medium-sized businesses to more than two-thirds in the public sector and education. The pattern generally tracks how much unstructured, high-volume correspondence a sector handles day to day.
Figure 5: Share of breaches involving the human element, by industry, 2026 dataset. Source: Verizon 2026 Data Breach Investigations Report Executive Summary.
| Industry | Human element share | Confirmed breaches analyzed |
|---|---|---|
| Public Administration | 69% | 2,410 |
| Educational Services | 68% | 1,252 |
| Financial and Insurance | 65% | 1,300 |
| Retail | 58% | 806 |
| Manufacturing | 56% | 2,713 |
| Healthcare | 54% | 1,438 |
| Small and medium-sized businesses | 45% | 7,152 |
Table 2: Human element share by industry, 2026 DBIR dataset. Source: Verizon 2026 Data Breach Investigations Report Executive Summary.
Public Administration's 69% figure is driven largely by an unusually high rate of Misdelivery, sending records or correspondence to the wrong recipient, which Verizon attributes directly to the sheer volume of routine correspondence government agencies handle. Healthcare sits lower at 54% but still lists "staff mistakes and misconfigurations" as a chronic, recurring source of breaches rather than an occasional one. Small and medium-sized businesses show the lowest human element share, at 45%, largely because 100% of their breaches trace to External attackers running System Intrusion, Basic Web Application Attacks, or Social Engineering, leaving little room in the mix for internal error or misuse. If your organization has not reviewed how it discloses data handling and breach notification obligations recently, you can generate an updated privacy policy that reflects current retention, security, and third-party disclosure practices.
Does Human Error Vary by Region?
Regional differences are smaller than industry differences but still notable. Asia-Pacific and Europe, Middle East and Africa both report human element shares above 70%, while the Americas sit closer to the global average.
Figure 6: Share of breaches involving the human element, by macro-region, 2026 dataset. Source: Verizon 2026 Data Breach Investigations Report Executive Summary.
Asia-Pacific's 71% and EMEA's 70% both outpace Northern America's 59% and Latin America and the Caribbean's 57%. Verizon attributes part of the regional gap to differences in which breach patterns dominate locally: EMEA's top three patterns, System Intrusion, Social Engineering, and Miscellaneous Errors, together cover 92% of its breaches, a tighter concentration than in Northern America, where Basic Web Application Attacks displaces Miscellaneous Errors from the top three entirely. For a broader look at how many individual records and people these breaches actually expose, see how many people have had their data breached and the full data breach statistics roundup.
Mobile devices are becoming a bigger part of the human-error story too. In simulated social engineering campaigns, the median successful click rate on mobile-centric vectors, voice calls and text messages, ran 40% higher than on email. Pretexting, building a false but trusted scenario to manipulate a target, reached 6% as an initial access vector specifically for ransomware and extortion attacks in 2026, while phishing held steady at 16% of all breaches, unchanged from 2025.
The Bottom Line
The honest answer to "what percentage of data breaches involve human error" depends entirely on which definition a source is using. Verizon's broad human element figure, 62% in 2026, includes people being actively deceived and insiders misusing access, not just accidental mistakes. The narrower, more literal reading of "error", a mistake made with no attacker involved, sits at just 8%, and that figure has been falling for two straight years as System Intrusion attacks driven by exploited vulnerabilities and ransomware have taken over as the dominant cause of breaches. Both numbers are real and both come from the same report; the practical takeaway is that reducing pure accidents (misdelivery, misconfiguration) addresses a shrinking slice of the problem, while defending against social engineering and unpatched vulnerabilities addresses the much larger and still-growing one.
Frequently Asked Questions
What percentage of data breaches involve human error in 2026? The human element, which Verizon defines as error, social engineering, or misuse combined, was present in 62% of confirmed data breaches in 2026, according to the 19th edition of Verizon's Data Breach Investigations Report. That is up slightly from 60% in the 2025 edition. A narrower measure, pure accidental mistakes with no attacker involved, accounted for just 8% of breaches.
What is the difference between human error and the human element in a data breach? Human element is Verizon's umbrella term covering three separate causes: Social Engineering, where an attacker manipulates a person into acting (17% of 2026 breaches), Miscellaneous Errors, an accidental mistake with no attacker deception involved, such as misdelivery (8%), and Privilege Misuse, an insider abusing legitimate access (3%). Human error in the strict sense refers only to the second category.
Has human error in data breaches gotten better or worse? The narrow Miscellaneous Errors category has fallen sharply, from 25% of breaches in 2024 to 12% in 2025 and 8% in 2026, per Verizon's DBIR. But the broader human element figure has held roughly flat, at 68% in 2024, 60% in 2025, and 62% in 2026, because Social Engineering has stayed a consistent top-three breach pattern even as pure accidents have declined.
Which industry has the most human-error-related data breaches? Public Administration has the highest human element share of any sector Verizon tracks in detail, at 69% of breaches in 2026, driven largely by high-volume Misdelivery errors in correspondence. Educational Services follows at 68% and Financial and Insurance at 65%, while small and medium-sized businesses have the lowest share, at 45%.
Where the Numbers Come From
- Verizon Business. (2026). "2026 Data Breach Investigations Report, Executive Summary." 19th edition; more than 31,000 security incidents and 22,000-plus confirmed data breaches analyzed across 145 countries, dataset October 2024 through November 2025.
- Verizon Business. (2026). "2026 Data Breach Investigations Report" (full report landing page). Industry, regional, and initial-access-vector breakdowns cited throughout this post.
- VERIS Framework. "Vocabulary for Event Recording and Incident Sharing (VERIS)." The classification framework Verizon uses to define System Intrusion, Social Engineering, Miscellaneous Errors, and Privilege Misuse as distinct breach patterns.
Note: All figures verified as of July 2026 against the 2026 DBIR Executive Summary. Headline human element and breach pattern figures are refreshed at least twice a year to track new DBIR editions as they publish.