3 Common Mistakes That Lead to a Security Breach

Updated: August 28, 2026 Time to read: ~

TL;DR

Most security breaches trace back to predictable, preventable mistakes — weak or reused passwords, everyday human errors, and gaps in security processes or technology. Understanding these root causes is the first step toward building stronger defenses. Organizations can significantly reduce their exposure by adopting adaptive multi-factor authentication, enforcing patch management, and encrypting data on mobile devices.

Why do security breaches happen?

Security breaches are rampant today, negatively impacting organizations and users across the globe on a daily basis. Identifying the underlying events and incidents that cause these breaches not only helps us understand how they occur, it also provides valuable insights for countering this growing threat.

Verizon's investigative report into the leading causes of security breaches revealed:

  • 62% of data breaches resulted from hacking.
  • 81% of those hacking breaches leveraged stolen, weak, or default passwords.
  • 43% of attacks involved social engineering.
  • 51% of data breaches involved credential-stealing malware.
  • 28% of breaches were caused by human error.

What are the most common causes of security breaches?

A cursory analysis of these statistics shows that human error is the weakest link in the chain, even when it comes to risks like password attacks and social engineering. These are four of the most common scenarios where an inadvertent mistake can lead to some far-reaching ramifications.

How do poor password practices lead to security breaches?

Compromised passwords obtained via credential harvesting are a leading cause of data breaches. Obtaining user credentials is the easiest way to gain access to a system, so it stands to reason that attackers will try and exploit the path of least resistance.

The following password attack types represent the most common threats organizations face:

  • Credential harvesting: Weak or default passwords are low hanging fruit to attackers. The tendency to choose convenience over security has been a long-identified consumer trait — even vendors are guilty of this. Recent studies have shown that over 50% of Internet of Things (IoT) device manufacturers will battle to address security threats that result from the weak authentication practices they've used in the past.
  • Credential stuffing (password reuse): Password reuse is another common risk — a common symptom in organizations that enforce password complexity policies. As users are forced to remember more complex passwords for multiple applications, the more likely they are to reuse a single complex password. This puts the organization at risk of a credential stuffing attack — 73% of passwords are duplicates, according to the TeleSign 2016 Consumer Account Security Report.
  • Password spraying: Password spraying also takes advantage of the humans in the security chain. In essence, this type of attack involves brute-forcing authentication with a small list of commonly used passwords. Think 123456 or password, which (surprisingly) still top the list of the most frequently used passwords.

How does human error contribute to security breaches?

Basic human error is responsible for over one quarter of all security breaches. Examples of this include employees leaving laptops or other mobile devices in vulnerable locations where they can easily be stolen and employees inadvertently emailing sensitive information to unauthorized third parties. 

Another example of simple human error resulting in a serious security breach is when someone misconfigures an application or database, which can mistakenly expose sensitive information online. For example, this was the case when sensitive information was stored in an unsecured Amazon S3 bucket.

How do process and technology failures create security vulnerabilities?

A chain is only as strong as its weakest link and in security the chain is made up of people, processes, and technology. Failures in basic security processes such as poor patch management can cause security breaches. Like passwords, unpatched systems are prime targets for attackers as the effort involved in successfully breaching the system is very low.
 
Technology is not perfect, and it too can fail from time to time, resulting in exposed data or a compromised system. For example, a software update could create a software vulnerability such as a Structured Query Language (SQL) injection, which may give attackers that opening they're looking for.

How to protect your organization from a security breach

How can process and technology improvements reduce breach risk?

When implemented and managed correctly, basic security hygiene processes (such as basic patch management) can mitigate many breaches attributed to hacking. Ensuring security regression testing as an integral part of any deployment process can help prevent technology failures that could lead to a security breach, and encrypting data on mobile devices can also help prevent a breach involving a lost or stolen device.

Organizations can take the following steps to reduce their exposure:

  • Patch management: Implement basic patch management to mitigate hacking-related breaches.
  • Security regression testing: Integrate it into every deployment process to prevent technology failures.
  • Mobile device encryption: Encrypt data on mobile devices to protect against loss or theft.
  • Adaptive MFA: Strengthen authentication with an adaptive multi-factor authentication solution for contextual defense.

Why is adaptive multi-factor authentication a critical defense?

And while many organizations believe passwords are critical for valid and secure authentication, they remain the achilles heel of secure authentication practices. To mitigate the real threat of a security breach caused by weak passwords, organizations should consider strengthening their authentication with an adaptive multi-factor authentication solution that provides further defense with contextual awareness. This not only protects against weak passwords, but also provides an additional layer of protection and visibility for IT teams in an ever-growing threat landscape.

Frequently asked questions

What percentage of security breaches are caused by weak or stolen passwords?

According to Verizon's investigative report, 81% of hacking-related breaches leveraged stolen, weak, or default passwords, making poor password hygiene one of the single largest contributors to data breaches.

What is credential stuffing and why is it dangerous?

Credential stuffing occurs when attackers use reused passwords — often obtained from previous breaches — to gain unauthorized access to other accounts. Because 73% of passwords are duplicates, a single compromised credential can expose multiple systems.

How does human error contribute to security breaches?

Human error accounts for more than a quarter of all security breaches. Common examples include employees losing unencrypted devices, accidentally emailing sensitive data to the wrong recipients, or misconfiguring databases and cloud storage buckets in ways that expose information publicly.

What is password spraying?

Password spraying is a brute-force attack technique where attackers try a small set of commonly used passwords — such as '123456' or 'password' — across many accounts, exploiting the tendency of users to choose convenience over security.

How can organizations protect themselves from process and technology failures?

Organizations can reduce risk by implementing consistent patch management practices, incorporating security regression testing into every deployment cycle, and encrypting data stored on mobile devices to limit exposure from lost or stolen hardware.

Why is adaptive multi-factor authentication important for preventing breaches?

Adaptive multi-factor authentication adds a contextual layer of defense beyond passwords alone. By evaluating situational signals at login, it helps IT teams detect suspicious access attempts and provides additional protection even when credentials have been compromised.

Continue your Identity journey