60 % of data breaches involve human error (Verizon DBIR 2025). Discover why you are the target, assess your own risk in 5 minutes, and apply immediate actions to turn that vulnerability into a strong defense — on Windows, macOS or Linux.
Table of contents
Demystifying Cybersecurity for the General Public
Introduction – What if the weakest link was me?
The latest Verizon DBIR 2025 is unequivocal. After analyzing more than 22,000 incidents and 12,000 confirmed breaches across 139 countries, the researchers conclude that 60% of data breaches involve a non‑malicious human element – mishandling, haste, misplaced trust. Attackers are not only targeting sophisticated software vulnerabilities: their main entry point is still a simple human click.
Take a few seconds to think about your own digital behavior. Have you ever clicked on a link without checking its real destination? Do you use the same password for your email and your bank account? If the answer is yes, you may have been, at some point, that “weakest link”. And that’s perfectly normal. We all are, at one time or another.
Anatomy of human risk: Why your brain clicks before it thinks
2.1 Cognitive biases: the hacker in your head
Attackers are not just IT experts. They are, above all, amateur psychologists. They know the shortcuts our brain uses to make quick decisions. These shortcuts, called cognitive biasesAutomatic mental shortcuts that influence our decisions without us being aware of them., are predictable and universal.
2.2 Social engineeringA set of psychological manipulation techniques used to deceive a person and obtain confidential information or compromising actions. techniques
2.3 Cognitive and decision fatigue
Even the most vigilant person eventually lowers their guard. Cognitive fatigueThe progressive exhaustion of our attention and decision‑making capacities after too many digital solicitations. is a real phenomenon: at the end of the day, after hours of notifications and digital solicitations, we click “OK” mechanically, without reading.
Personal life = Professional risk: Adopt Personal Zero Trust
Many people think their personal digital security has no impact on their professional life. This is a fundamental mistake. The boundary between the two worlds has become extremely porous.
“My Facebook account has no value for a hacker. I am not an important person.”
False. A hacker is interested in your email address, your friends list, your employer. Each piece of information is a piece of the puzzle.
Real case analyzed: The fake bank advisor scam
To make these concepts more tangible, here is the story of a real compromise, anonymized but representative of thousands of similar cases.
Problem: She uses the same password for her bank, Amazon, and her personal email.
| Day | Event | Analysis |
|---|---|---|
| D‑30 | Data leak from an e‑commerce site. Sophie’s credentials exposed. | Sophie ignores the leak. |
| D‑7 | Attempt to connect to her professional email. Failed thanks to MFA. | ✅ MFA played its barrier role. |
| D‑3 | Call from the fake bank advisor who knows personal details. | ⚠️ Sophie is in a state of trust and stress. |
| D‑0 | The fake advisor asks for the MFA code received by SMS. Sophie gives it. | ❌ Fatal mistake. |
| D+5 | Fraudulent transfer of €4,500. | ❌ No phone verification of the bank account details. |
SMS‑ or app‑based MFA (TOTP) is no longer foolproof. Cybercriminals now use Adversary‑in‑the‑Middle (AitM) attacks via malicious reverse proxies (e.g., Evilginx). These tools create a perfect copy of the legitimate site, intercept your password, your MFA code, and steal the valid session cookie. Only physical security keys or Passkeys (FIDO2/WebAuthn) resist this attack because they cryptographically bind the authentication to the real domain name of the site.
Your personal action plan (15 minutes)
Enough theory. Let’s take action. Honestly answer the 10 questions below, then check your score and the recommended actions.
Choosing a password manager
Here is a comparison of the main password managers, suitable for all operating systems.
• Beginner: Bitwarden (free, simple, automatic sync).
• Total control: KeePassXC (local file, compatible with KeePassDX/Strongbox).
• Maximum security: Choose a manager that supports Passkeys (FIDO2).
Passkeys represent a major advance: an authentication that is completely resistant to phishing and AitM attacks. Unlike passwords or MFA codes, Passkeys are never exposed on the network and cryptographically bind the authentication to the real domain name of the site.
Tools & Appendices
7.1 Glossary
| Term | Definition |
|---|---|
| MFA / 2FA | Multi‑Factor Authentication: requires at least two proofs of identity (password + code). |
| FIDO2 / Passkeys | Passwordless authentication, resistant to phishing and AitM attacks. |
| Credential stuffing | Automated attack by reusing stolen credentials. |
| AitM (Adversary‑in‑the‑Middle) | Session interception attack that bypasses classic MFA. |
| Ransomware | Malware that encrypts data for ransom. |
7.2 Free verification tools
7.3 English‑language resources
Prospective conclusion: AI is coming, humanity remains
The threat is evolving. Generative AI is becoming a formidable weapon. ENISA warns: more than 80% of phishing campaigns were AI‑assisted in early 2025. CERT‑FR confirms that this trend is accelerating. The Mimecast 2026 report also points out that 42% of internal incidents are now intentional.
Humans are not the weakest link. They are the sensitive link – the one who feels, doubts, adapts. And it is precisely this sensitivity that becomes the ultimate rampart.
Faced with this sophistication, our weapons remain simple and human:
Take back control. Today.
A dedicated article on mitigation strategies for enterprises is in preparation. In the meantime, here are the key axes:
• Reporting culture: reward reporting, do not punish.
• Useful friction: explicit confirmations for critical actions.
• Phishing simulations: educational feedback, not "name and shame".
• Continuous training: regular micro‑learnings.
• Least privilege: access limited to the strictly necessary.
• Passkeys (FIDO2): deployment of phishing‑ and AitM‑resistant authentication.
Verified sources
| Source | Year | Key data |
|---|---|---|
| Verizon DBIR | 2025 | 60% of breaches involve a human factor. 22% of initial accesses = compromised credentials. |
| ENISA Threat Landscape | 2025 | Phishing = 60% of initial intrusions. >80% of phishing AI‑assisted. |
| Infosecurity Magazine (ANSSI data) | 2025 | 196 exfiltration incidents (+51%). 128 ransomware incidents. |
| Infosecurity Magazine | 2025 | Phishing reports +70% in France. |
| Mimecast | 2026 | 96% of organizations have incomplete protection. 42% of insider incidents are intentional. |
| IBM (citing Proofpoint) | 2024 | 74% of CISOs: human error = main vulnerability. |
| FIDO Alliance / NIST | 2025‑2026 | Passkeys = authentication resistant to phishing and AitM attacks. |
| CERT‑FR | 2026 | Threat landscape in France. Increase in AI‑assisted phishing. |
Further reading from SafeITExperts
About the author
Marc is the editor‑in‑chief of SafeITExperts, a bilingual FR/EN technical blog dedicated to cybersecurity, Linux, and digital sovereignty.
| Network | Link |
|---|---|
| Website | safeitexperts.com |
| X (Twitter) | @crisisdav |
| SafeITExperts | |
| Bluesky | @crisis23.bsky.social |
| Mastodon (Infosec) | @safeitexperts |
| safeitexperts@safeitexperts.com |