Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
Vector File MI / Malicious InsiderIBM 2025, Figure 9

Attack vector

Malicious-insider breaches are the costliest, at $4.92M.

A breach whose initial vector was a malicious insider, an employee or contractor abusing the access they were trusted with, averaged $4.92M per incident in the IBM Cost of a Data Breach Report 2025. That is the highest average of any initial attack vector IBM ranks, above supply-chain compromise ($4.91M) and phishing ($4.8M), because an insider starts inside every control the perimeter was built to enforce.

Average cost

$4.92M

IBM 2025, Figure 9

Rank

#1

Costliest initial vector

Cost premium

+11%

vs $4.44M all-breach avg

vs phishing

+$120K

Phishing is commoner, not costlier

Section MI.1

Why the insider vector costs the most

Every other initial vector describes how an attacker gets in. The insider is already in, holding valid credentials, working inside the trust boundary, with a legitimate reason to touch the data. That is why it sits at the top of IBM's cost table.

A malicious insider does not have to defeat a firewall, phish a password, or find an unpatched flaw. The access is granted. An administrator copying a database, a departing engineer taking source code, a support agent pulling customer records they are cleared to see, none of that trips the controls calibrated to catch an outsider forcing entry. The activity looks like the job. There is no anomalous login from a strange country, no exploit signature, no malware to detonate, because the person is authorised and the action is, on its face, ordinary work.

That invisibility is the cost driver. IBM's data is consistent every edition: the longer a breach goes unidentified and uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (29%) premium. An insider who knows where the monitoring is, and knows what normal looks like because they help define it, accumulates the kind of dwell time that pushes an incident into the expensive half of that distribution, and often does not surface until the data is already out or, as at Ubiquiti, until the same person is helping investigate the breach they caused.

Section MI.2

Malicious insider against the other initial vectors

IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Malicious insider sits at the very top, narrowly ahead of supply-chain compromise and phishing, and it is the vector defenders find hardest to reason about because the threat holds a badge.

Malicious Insider$4.92M
Supply Chain Compromise$4.91M
Phishing$4.80M
Credential Theft$4.67M
Denial-of-Service$4.41M
Vulnerability Exploitation$4.24M

The dollar figures are the IBM 2025 initial-vector averages. Malicious insider tops the table at $4.92M; the spread from top to bottom is narrow ($0.68M), which is the point: no initial vector is cheap, and the one that costs the most is the one that starts with trust already granted.

Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector). Malicious insider is the highest-cost initial vector at $4.92M.

Section MI.3

Two cases: the extortionist and the leakers

The insider threat is not one behaviour. It runs from a lone administrator who turns the access into a payday, to trusted staff who walk data out the door. Two disclosed cases show both ends.

Ubiquiti 2020-21 / the inside extortionist

6 years

Prison sentence; $1.6M restitution ordered

Nickolas Sharp, a senior Ubiquiti engineer responsible for cloud infrastructure, used his administrative access to exfiltrate gigabytes of data from the company's AWS and GitHub servers in late 2020, then, while assigned to the team investigating the very breach he had caused, posed as an anonymous hacker and demanded roughly $1.9M in bitcoin. An internet outage briefly exposed his real IP. He pleaded guilty to insider hacking, was sentenced to six years, and ordered to pay $1.6M in restitution. The definitive illustration of why the insider vector defeats external-intrusion detection: the investigator was the attacker.

Tesla 2023 / the trusted leakers

75,735

Current and former employees exposed

In August 2023 Tesla disclosed that two former employees had misappropriated the personal data, including names, addresses, phone numbers, employment records and Social Security numbers, of 75,735 current and former staff, in violation of Tesla's IT-security and data-protection policies, and handed it to the German outlet Handelsblatt. No firewall was breached and no malware ran. Authorised people took data they were cleared to see and moved it outside, which is the entire threat model the insider vector describes.

Primary source:Ubiquiti: US DOJ prosecution of Nickolas Sharp (guilty plea to insider hacking; six-year sentence, $1.6M restitution, ~$1.9M bitcoin extortion demand). Tesla: company breach disclosure of an insider incident affecting 75,735 individuals, reported August 2023.

Section MI.4

The 2026 update

In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026) the overall global average rose to a record $4.99M and the US average to $11.5M, and AI moved to the centre of the story: roughly one in four malicious breaches now involves attacker use of AI, and an AI-enabled breach averaged $6M. That shift raises the stakes on the insider problem rather than lowering them. The same generative tools that write a better phishing lure also let a malicious insider find, package, and move sensitive data faster and more quietly, and IBM found that most breached organisations still lack AI governance and access controls. The $4.92M figure on this page is the 2025 report's per-vector average, the edition in which IBM ranked initial vectors most explicitly; the lever it points to, containment speed against a threat that starts with trust, only gets harder as the tooling on both sides improves.

Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): global average $4.99M, US average $11.5M, AI-enabled breach average $6M, roughly 1 in 4 malicious breaches AI-enabled. Malicious-insider initial-vector cost ($4.92M) from the IBM Cost of a Data Breach Report 2025, Figure 9.

Cross-references

Schedule F / Reference Q&A

Frequently Asked Questions

Primary source:Malicious-insider initial-vector cost and the under/over-200-day lifecycle premium from the IBM Cost of a Data Breach Report 2025 (Figures 9 and 12); 2026 headline figures from the IBM Cost of a Data Breach Report 2026; Ubiquiti and Tesla case facts as cited above.