Attack vector
Malicious-insider breaches are the costliest, at $4.92M.
A breach whose initial vector was a malicious insider, an employee or contractor abusing the access they were trusted with, averaged $4.92M per incident in the IBM Cost of a Data Breach Report 2025. That is the highest average of any initial attack vector IBM ranks, above supply-chain compromise ($4.91M) and phishing ($4.8M), because an insider starts inside every control the perimeter was built to enforce.
Average cost
$4.92M
IBM 2025, Figure 9
Rank
#1
Costliest initial vector
Cost premium
+11%
vs $4.44M all-breach avg
vs phishing
+$120K
Phishing is commoner, not costlier
Section MI.1
Why the insider vector costs the most
Every other initial vector describes how an attacker gets in. The insider is already in, holding valid credentials, working inside the trust boundary, with a legitimate reason to touch the data. That is why it sits at the top of IBM's cost table.
A malicious insider does not have to defeat a firewall, phish a password, or find an unpatched flaw. The access is granted. An administrator copying a database, a departing engineer taking source code, a support agent pulling customer records they are cleared to see, none of that trips the controls calibrated to catch an outsider forcing entry. The activity looks like the job. There is no anomalous login from a strange country, no exploit signature, no malware to detonate, because the person is authorised and the action is, on its face, ordinary work.
That invisibility is the cost driver. IBM's data is consistent every edition: the longer a breach goes unidentified and uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (29%) premium. An insider who knows where the monitoring is, and knows what normal looks like because they help define it, accumulates the kind of dwell time that pushes an incident into the expensive half of that distribution, and often does not surface until the data is already out or, as at Ubiquiti, until the same person is helping investigate the breach they caused.
Section MI.2
Malicious insider against the other initial vectors
IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Malicious insider sits at the very top, narrowly ahead of supply-chain compromise and phishing, and it is the vector defenders find hardest to reason about because the threat holds a badge.
The dollar figures are the IBM 2025 initial-vector averages. Malicious insider tops the table at $4.92M; the spread from top to bottom is narrow ($0.68M), which is the point: no initial vector is cheap, and the one that costs the most is the one that starts with trust already granted.
Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector). Malicious insider is the highest-cost initial vector at $4.92M.
Section MI.3
Two cases: the extortionist and the leakers
The insider threat is not one behaviour. It runs from a lone administrator who turns the access into a payday, to trusted staff who walk data out the door. Two disclosed cases show both ends.
Ubiquiti 2020-21 / the inside extortionist
6 years
Prison sentence; $1.6M restitution ordered
Nickolas Sharp, a senior Ubiquiti engineer responsible for cloud infrastructure, used his administrative access to exfiltrate gigabytes of data from the company's AWS and GitHub servers in late 2020, then, while assigned to the team investigating the very breach he had caused, posed as an anonymous hacker and demanded roughly $1.9M in bitcoin. An internet outage briefly exposed his real IP. He pleaded guilty to insider hacking, was sentenced to six years, and ordered to pay $1.6M in restitution. The definitive illustration of why the insider vector defeats external-intrusion detection: the investigator was the attacker.
Tesla 2023 / the trusted leakers
75,735
Current and former employees exposed
In August 2023 Tesla disclosed that two former employees had misappropriated the personal data, including names, addresses, phone numbers, employment records and Social Security numbers, of 75,735 current and former staff, in violation of Tesla's IT-security and data-protection policies, and handed it to the German outlet Handelsblatt. No firewall was breached and no malware ran. Authorised people took data they were cleared to see and moved it outside, which is the entire threat model the insider vector describes.
Primary source:Ubiquiti: US DOJ prosecution of Nickolas Sharp (guilty plea to insider hacking; six-year sentence, $1.6M restitution, ~$1.9M bitcoin extortion demand). Tesla: company breach disclosure of an insider incident affecting 75,735 individuals, reported August 2023.
Section MI.4
The 2026 update
In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026) the overall global average rose to a record $4.99M and the US average to $11.5M, and AI moved to the centre of the story: roughly one in four malicious breaches now involves attacker use of AI, and an AI-enabled breach averaged $6M. That shift raises the stakes on the insider problem rather than lowering them. The same generative tools that write a better phishing lure also let a malicious insider find, package, and move sensitive data faster and more quietly, and IBM found that most breached organisations still lack AI governance and access controls. The $4.92M figure on this page is the 2025 report's per-vector average, the edition in which IBM ranked initial vectors most explicitly; the lever it points to, containment speed against a threat that starts with trust, only gets harder as the tooling on both sides improves.
Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): global average $4.99M, US average $11.5M, AI-enabled breach average $6M, roughly 1 in 4 malicious breaches AI-enabled. Malicious-insider initial-vector cost ($4.92M) from the IBM Cost of a Data Breach Report 2025, Figure 9.
Cross-references
Vector / Supply chain
→$4.91M average, 267-day lifecycle. The next-costliest vector, and the slowest to contain.
Vector / Phishing
→$4.8M average, 254-day lifecycle. The most common initial vector of all.
Case / Capital One 2019
→$300M+. A former cloud-provider employee turned a misconfiguration into 100M records.
Prevention / Control ROI
→Where IAM, monitoring, and insider-threat controls rank on cost saved per breach.
Reference / Global statistics
→Full attack-vector cost table, lifecycle data, year-over-year trends.
Ransomware / Extortion economics
→$5.08M attacker-disclosed breach. Where insider access meets external extortion.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Malicious-insider initial-vector cost and the under/over-200-day lifecycle premium from the IBM Cost of a Data Breach Report 2025 (Figures 9 and 12); 2026 headline figures from the IBM Cost of a Data Breach Report 2026; Ubiquiti and Tesla case facts as cited above.