The most expensive cyberattacks in history did not begin with elite hacking. They began with a reused password, an unchecked invoice, a software update nobody verified and a vendor login nobody monitored. Here are five of the biggest — what the human mistake actually was, what it cost, and what each one teaches a small business running a security awareness programme in 2026.
1. Target, 2013: the vendor login nobody watched
Attackers got into Target through a refrigeration and HVAC contractor's network credentials, moved into Target's own systems and harvested 40 million payment card numbers plus the personal records of roughly 70 million customers. The entry point was not a zero-day exploit — it was third-party access that existed for a legitimate business reason and was never segmented or monitored. Target's disclosed breach-related costs ran past $200 million, and the breach ultimately cost the CEO and CIO their jobs.
The lesson: human risk is not only your employees. Every vendor login is a person with a password, and the weakest one becomes your front door. List which third parties can reach your systems, and treat their credentials with the same scrutiny as your own staff's.
2. WannaCry, 2017: the patch that was never applied
In May 2017 the WannaCry ransomware worm infected more than 200,000 computers across 150 countries within days. It exploited a Windows vulnerability that Microsoft had already patched two months earlier — organisations were hit because the update was never applied. The UK's National Health Service took the sharpest damage: hospitals reverted to paper records, and on the order of 19,000 appointments and operations were cancelled.
The lesson: the failure was procedural, not technical. Somebody had not been given the time, the tooling or the accountability to patch. In an awareness programme, patching is a people control too — it needs an owner, a cadence and evidence that it happened, exactly the way training does.
3. NotPetya, 2017: the update nobody verified
NotPetya spread through a compromised software update of M.E.Doc, a Ukrainian accounting package thousands of companies used. Machines that trusted the vendor and installed the update were infected automatically — no click required. It went on to cause an estimated US$10 billion in damages, the costliest cyberattack on record, paralyzing shipping giant Maersk, pharmaceutical company Merck and delivery firm FedEx for weeks.
The lesson: trust chains are human decisions. Every automatic update and every trusted supplier connection is an assumption made by a person. Small businesses cannot audit every vendor, but they can inventory which suppliers have software touching their systems — the same inventory exercise a security gap assessment formalises.
4. The everyday phishing breach
Not every landmark incident has a brand name. Year after year, Verizon's Data Breach Investigations Report finds the human element — phishing, social engineering, stolen credentials and simple error — among the most frequent causes of breaches across organisations of every size, and its 2026 edition reports attackers shifting toward mobile devices precisely because click rates there run higher than on desktop email. The pattern inside the statistic never changes: an employee receives a convincing message, the moment of decision passes in under a second, and credentials or payment details change hands.
The lesson: the world's biggest breaches and your next Tuesday share the same first move. Recurring phishing simulations rehearse that moment safely, and a rising report rate — not a falling click rate alone — is the healthiest signal a programme produces.
5. The CEO fraud invoice
Business email compromise rarely makes headlines because victims often absorb the loss quietly. The FBI's Internet Crime Complaint Center (IC3) reported US$16.6 billion in reported cybercrime losses for 2024 — more than $50 billion across 2020–2024 — and business email compromise has consistently ranked among the costliest categories. Most of that money was lost to a single human moment: a finance person receiving an urgent payment-change request that appears to come from a senior executive and acting without verification.
The lesson: authority plus urgency defeats knowledge. The fix is a procedure, not more training slides — a rule that payment detail changes are always confirmed by phone on a known number. Write it down, and make following it the easy, expected behaviour.
What these five have in common
Strip away the technology and the same human failure repeats: an unverified assumption made under time pressure, by someone whose job was never security. No exotic malware skills were required to start any of them. That is why security awareness exists as a control, and why its weakest form — one long annual course — fails the same way the failures above did: the lesson decays long before the moment arrives.
How to turn the lessons into controls
Each failure maps to a checkable behaviour:
- Vendor and third-party access — list who can reach your systems, and review the list when relationships change.
- Patching — a named owner, a documented cadence, evidence it happened.
- Updates and trust chains — an inventory of software and suppliers that touch your environment.
- Phishing — monthly short lessons plus realistic simulations, with a follow-up lesson for anyone who clicks.
- Payment fraud — a written verification procedure that removes the judgment call.
Measure the people-facing ones per learner rather than by attendance: overdue lessons, simulation outcomes and repeat clickers tracked in a human risk report show whether the control is holding, not just whether it was delivered through security awareness training. If you are weighing platforms to run that loop, the compare page sets out the differences directly.
FAQ
What was the costliest cyberattack in history?
NotPetya in 2017, with damages estimated around US$10 billion. It spread through a compromised software update of a Ukrainian accounting package and crippled companies including Maersk, Merck and FedEx.
What is the most common human error in cyberattacks?
Clicking a phishing link or responding to a fraudulent request. Verizon's Data Breach Investigations Report keeps the human element — phishing, social engineering and stolen credentials — among the most frequent causes of breaches year after year.
Could better training have stopped WannaCry or NotPetya?
Not directly — those were patching and supply-chain failures, not clicks. But they are still people failures: procedures and accountability, not code, decide whether a two-month-old patch gets applied. Training programmes work the same way; cadence and ownership beat content volume.
How does business email compromise actually work?
An attacker impersonates a senior executive or supplier by email and requests an urgent payment or a change of bank details. The request pressures one person into one unverified action. Phone verification on a known number stops almost all of it.
What should a small business do first?
Baseline your people risk: run a first phishing simulation, get completion and behaviour into a per-learner view, and fix the two cheapest procedural gaps — payment verification and a reporting channel. Then extend the loop monthly.
One last thing
The five incidents above differ in scale by orders of magnitude — from a regional NHS outage to $10 billion in global damages — but the opening move is identical every time, and it is a move a five-minute monthly lesson rehearses. History's biggest breaches are not an argument that nothing works; they are the strongest case for making the human layer a measured, recurring control.
Sources
- Verizon 2026 Data Breach Investigations Report — human element among leading breach causes, mobile click-rate findings
- FBI Internet Crime Complaint Center (IC3) — reported cybercrime losses, business email compromise rankings
- Wikipedia: WannaCry ransomware attack — scale, NHS impact and patch timeline
- Wikipedia: NotPetya — M.E.Doc update vector and damage estimates
- Wikipedia: 2013 Target data breach — vendor credential entry point and card numbers affected