Threat intelligence data from Orange Cyberdefense reveals a significant shift in the cyber security landscape. For the first time, incidents originating from inside organizations have overtaken external incidents. Analysing over 139,000 triaged security events between 1st October 2024 to 31st August 2025, Orange Cyberdefense found that internal incidents surged from a 47% share to 57% in just 11 months.
A significant driver of this change is employee misuse, which has risen from 29% to 45% of all confirmed incidents over this period. By contrast, hacking remained at 31%, largely unchanged from 2024. Misuse is often not malicious, but rather a case of employees circumventing security protocols; this can take the shape of shadow IT, such as unapproved software workarounds or web access misuse, or it can be through the abuse of privileged access and controls. Crucially, all of this activity can play to the advantage of attackers.
This shift suggests that, for many organizations, the immediate risk is not only a hacker cracking their firewalls, but an employee bypassing a policy.
Orange Cyberdefense does note, however, that organizations are increasingly deploying Extended Detection and Response (XDR) tools, which many analysts describe as ‘trigger-happy’, and can often flag false positives from day-to-day employee behaviour that can appear malicious.
Regardless of whether these incidents are confirmed breaches or technical false positives, this internal activity mostly involves employee endpoint hardware. The data reveals that end-user devices such as mobiles and laptops are now the most impacted assets, involved in around 53% of all incidents – up from 39% from the year prior. Furthermore, account incidents, relating to identity and credential access, also climbed from 10% to 17%. Collectively, this data suggests that attackers are increasingly aware of the patterns of misuse that employees fall into, and are on the hunt to exploit these behaviours.
Interestingly, the organization sizes worst hit by cybersecurity incidents involving misuse are small businesses (43%) and large enterprises (45%). For both, this is likely due to how internal access works at their relative scale, creating the same challenge but at opposite sides of the spectrum. Small businesses often have fewer resources and less restrictive policies, granting employees more access than required and increasing the likelihood of mistakes or malicious activity. In larger organizations, the sheer volume of employees and systems makes it easier for insider misuse to slip past even strong security measures.
By contrast, medium-sized businesses tend to deal with far more hacking incidents, which account for 47% of their incidents compared with 31% attributed to misuse. While these firms’ headcounts may be at a ‘sweet spot’ for managing internal access, they still occupy an attractive space for attackers; they often hold more valuable access than small businesses, but without the advanced security systems of large enterprises.






