People remain attractive because they are efficient entry points to credentials, email, and web applications. The report shows attackers prefer short paths and low-friction tactics like phishing and credential theft because they scale and deliver high payoff. When defenders improve technical controls but ignore human behavior, they leave the easiest route open. That is where most real-world compromise begins.
Why attackers keep choosing people as the first step
Financially motivated attackers are usually optimizing for speed, scale, and reliability. People are easier to reach than hardened systems, and they can be manipulated into revealing credentials, approving access, or opening a path into email and web applications. That makes the human layer a reusable entry point, not just a soft target.
The practical reason is that social engineering often bypasses the expensive parts of attack development. Instead of finding a technical exploit for every target, attackers can reuse one lure, one stolen credential set, or one impersonation pattern across many victims. That is why the attack path often starts with people even when the end goal is a system compromise.
For defenders, this means the question is not whether systems are protected at all, but whether the organisation has reduced the number of ways a person can be converted into access. If identity verification, email controls, and application hardening are treated separately, attackers will keep taking the shortest route between them.
Why human compromise scales better than pure technical exploitation
Human compromise scales because it turns one success into many follow-on opportunities. A stolen password, a malicious approval, or a convincing login prompt can open email, reset workflows, cloud portals, and internal applications without requiring a custom vulnerability for each environment. That makes the economics attractive for attackers who want repeatable returns.
It also works well against mixed environments. Many organisations have good technical controls in one layer but weaker controls in the adjacent layer, so a phished account can still be used to reach a mailbox, a ticketing system, or an exposed application. The 52 NHI Breaches Report shows the same economic logic in machine-facing compromise, where attackers repeatedly exploit the easiest authenticated path rather than the most elegant one.
Attackers also prefer paths that survive across campaigns. A credential theft method can be refreshed with new branding, new lures, or new impersonation themes, while the underlying objective stays the same: obtain trusted access with minimal effort. That is why the human layer remains a durable attack surface even as defensive tooling improves.
What this means for exposure, resilience, and control design
The important design lesson is that people are not a separate problem from systems, they are often the bridge into them. If the organisation only measures malware blocking or perimeter events, it can miss the far more common compromise pattern where a legitimate user action or captured credential creates the breach path. Financial attackers exploit that gap because it shortens the time from contact to cash-out.
Controls need to be judged by whether they interrupt that path in practice, not by whether they exist on paper. If phishing-resistant authentication, least privilege, session controls, mailbox hardening, and user reporting are not aligned, a single user compromise can still become broad access. The same short-path preference appears in credential-driven breach analysis, where exposed secrets and overbroad permissions create the fastest route to impact.
For a practitioner, the question becomes whether the organisation has made human compromise expensive enough that attackers must spend more time, more tooling, or more noisy steps to get equivalent access. When that is not true, people will remain the most efficient entry point.
Risk and Threat Considerations
People are attractive because they concentrate low-friction access in a form attackers can repeatedly abuse: credentials, approvals, email trust, and application sessions. The risk is not just initial compromise, but the speed with which that compromise can expand into business systems and monetisable data.
Failure mechanism: Attackers exploit trust, urgency, and credential reuse to convert a single human interaction into authenticated access, then move through email or web applications before defenders can react.
Impact: The result is usually account takeover, fraudulent payment or data access, and a wider compromise footprint than a pure technical exploit would have produced.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Targets people through deceptive delivery to gain access or credentials. |
| T1078 — Valid Accounts | Attackers often convert human compromise into legitimate authenticated access. | |
| Recommendation — Hunt for phishing-driven initial access and harden user-facing trust decisions. Detect and contain misuse of valid accounts after credential compromise. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Human-targeted attacks commonly aim to defeat user authentication. |
| Recommendation — Strengthen user authentication against phishing and credential theft. | ||
| CIS Controls v8 | CIS-5 — Account Management | Attackers exploit weak account controls after compromising people or credentials. |
| Recommendation — Tighten account lifecycle and access review to shrink attacker reuse opportunities. | ||
| OWASP ASVS | V6 — Authentication | Web apps are common payoff points after human credential capture. |
| Recommendation — Verify phishing-resistant authentication and robust login protections. | ||
Practitioner Guidance
What to prioritise: Reduce the number of human actions that can directly yield trusted access. That means treating email, authentication, and privilege boundaries as one attack path instead of separate control domains.
What to verify: Confirm that a stolen password, approved prompt, or compromised mailbox cannot immediately reach high-value systems without an additional, observable control point. If it can, the attacker still has a low-friction route.
Practitioner takeaway: The best defence is not to “secure the user” in the abstract, but to make the human path materially harder to convert into authenticated, monetisable access.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org