If you are searching for which of the following is responsible for most of the recent PII data breaches, the expected answer to the commonly reproduced cybersecurity training question is phishing.
Phishing attacks use deceptive emails, text messages, phone calls, QR codes, fake login pages, and other communications to trick people into revealing passwords, personal information, authentication codes, or access to protected systems. Once an attacker gains access to an account, personally identifiable information may also become exposed.
However, there is an important distinction. If a quiz asks which of the following is responsible for most of the recent PII data breaches, phishing is the intended answer. That does not mean phishing causes most data breaches in every modern cybersecurity dataset.
Verizon’s 2026 Data Breach Investigations Report says 31% of breaches in its dataset begin with exploitation of software vulnerabilities, making vulnerability exploitation its leading initial entry point.
This guide explains why phishing is the expected answer, what personally identifiable information means, how phishing can lead to PII exposure, what current 2026 breach research shows, and how individuals and organizations can reduce the risk.
Quick Answer: Which of the Following Is Responsible for Most of the Recent PII Data Breaches?
For the commonly reproduced question, which of the following is responsible for most of the recent PII data breaches, the correct training answer is:
Phishing
The question generally appears with choices similar to these:
| Answer Choice | Correct Answer? |
| Reconstruction of improperly disposed documents | No |
| Phishing | Yes |
| Insider threat | No |
| Physical breaking and entry | No |
All of these can create security risks, but phishing is the expected answer to this specific PII safeguarding question.
At a Glance
| Question | Quick Answer |
| Which of the following is responsible for most of the recent PII data breaches? | Phishing |
| Is phishing a form of social engineering? | Yes |
| Is every phishing attempt a PII breach? | No |
| Can phishing lead to PII exposure? | Yes |
| Can insiders expose PII? | Yes |
| Are software vulnerabilities important in 2026? | Yes |
| Verizon’s leading 2026 initial entry point | Vulnerability exploitation, 31% |
| IBM India’s leading 2026 initial vector | Phishing, 19% |
Key Takeaways
- Phishing is the expected answer to the commonly reproduced PII training question.
- PII is information that identifies or can reasonably be linked to an individual.
- Phishing can expose PII by compromising passwords, authentication sessions, accounts, or access to sensitive systems.
- A phishing message does not automatically mean that a PII breach occurred.
- Modern breaches can also involve vulnerabilities, ransomware, stolen credentials, insiders, cloud misconfiguration, and third-party compromise.
- Strong authentication, employee awareness, encryption, patching, monitoring, least-privilege access, and data minimization can reduce PII breach risk.
What Is Personally Identifiable Information?
Personally identifiable information, usually abbreviated as PII, is information that can identify a specific person or reasonably be linked to an individual.
PII can include information that directly identifies a person as well as information that becomes identifying when combined with other data.
Common Examples of PII
| Type of PII | Examples |
| Identity information | Full name, Social Security number, passport number |
| Contact information | Address, email address, phone number |
| Government identifiers | Driver’s license number, taxpayer ID |
| Financial information | Bank details, account information |
| Biometric information | Fingerprints, facial identifiers |
| Employment information | Personnel and employee records |
| Educational information | Student records |
| Medical information | Identifiable health information |
| Account information | Usernames and identifiers tied to a person |
Not every piece of PII presents the same level of risk.
A person’s name may already be publicly available. But combining a name with a Social Security number, date of birth, home address, bank information, and login credentials can create a much higher risk of fraud or identity theft.
What Is Sensitive PII?
Some types of personal information can cause greater harm if exposed.
Sensitive PII may include:
- Social Security numbers
- bank account details
- government ID numbers
- medical records
- authentication credentials
- biometric data
- tax information
- payment information
- combinations of several personal identifiers
The sensitivity of PII also depends on context.
A phone number displayed on a public business website may create relatively little privacy risk. The same phone number connected to medical, financial, or employment information may reveal significantly more about an individual.
What Counts as a PII Data Breach?
Understanding this distinction makes the question of which of the following is responsible for most of the recent PII data breaches much easier to interpret.
A phishing attempt is an attack.
A PII breach is what may happen after unauthorized access, loss, disclosure, or exposure of personal information occurs.
A PII breach may involve information being:
- accessed without authorization
- disclosed to an unauthorized person
- stolen
- lost
- improperly acquired
- publicly exposed
- or placed outside appropriate organizational control.
Examples include:
- an attacker accessing a customer database
- personal records being sent to the wrong recipient
- cloud storage accidentally becoming public
- an employee viewing records without authorization
- an unprotected laptop containing PII being stolen
- stolen credentials being used to access employee or customer data
Security Incident vs PII Breach
| Situation | Security Incident? | Potential PII Breach? |
| Phishing email received but ignored | Yes | Usually no |
| Password entered on a phishing site | Yes | Not automatically |
| Stolen account used to access PII | Yes | Yes |
| PII sent to the wrong recipient | Yes | Potentially |
| Unauthorized employee views records | Yes | Yes |
| Device containing PII is stolen | Yes | Depends on safeguards |
Phishing is an attack technique. A PII breach is the unauthorized exposure, access, acquisition, loss, or disclosure of personally identifiable information that may result from the attack.
Are All PII Data Breaches Equally Serious?
No.
The potential impact of a breach depends on factors such as:
- what information was exposed
- how sensitive the information is
- how many individuals were affected
- whether multiple identifiers can be combined
- whether the information was encrypted
- who gained access
- how long the exposure lasted
- whether data was copied
- how easily the information can be misused
PII Breach Risk Examples
| Exposed Information | Potential Concern |
| Social Security number | Identity fraud |
| Account password | Account takeover |
| Bank information | Financial fraud |
| Multiple identifiers | Impersonation |
| Medical records | Privacy harm |
| Authentication token | Unauthorized account access |
| Large customer database | Large-scale exposure |
A smaller breach containing highly sensitive information can sometimes create more risk than a larger breach containing less-sensitive data.
Why Is Phishing the Correct Answer?
When someone asks which of the following is responsible for most of the recent PII data breaches, the answer is phishing because phishing is a common method of manipulating legitimate users into exposing information or providing access.
Phishing attacks exploit trust, urgency, fear, authority, and familiarity.
Attackers may impersonate:
- banks
- employers
- government agencies
- IT administrators
- cloud-service providers
- senior executives
- vendors
- delivery companies
- coworkers
The victim may be asked to:
- click a fraudulent link
- enter a password
- verify an account
- open an attachment
- approve an MFA request
- provide sensitive data
- scan a malicious QR code
- call a fraudulent support number
- authorize a cloud application.
The victim may believe the request is legitimate because the communication appears to come from a trusted organization or person.
How Can Phishing Lead to a PII Data Breach?
Phishing often represents the beginning of an attack chain, not the entire breach.
1. The Attacker Contacts the Victim
The victim receives a deceptive:
- SMS message
- phone call
- QR code
- social-media message
- authentication request
2. The Attacker Creates Urgency
Common claims include:
- “Your password expires today.”
- “Your account has been suspended.”
- “Review this confidential document.”
- “A payment requires immediate approval.”
- “Suspicious activity was detected.”
- “IT needs you to verify your account.”
3. The Victim Takes Action
The user may:
- enter credentials into a fake website
- provide personal information
- approve a login
- download an attachment
- grant application permissions
4. The Attacker Gains Access
Stolen passwords, tokens, or authenticated sessions may allow an attacker to appear to be a legitimate user.
5. Additional Systems Are Reached
Depending on the compromised account’s permissions, attackers may reach:
- cloud storage
- HR platforms
- customer databases
- payroll systems
- financial platforms
- administrator tools
6. PII Is Located
The system may contain:
- customer data
- employee information
- patient records
- student information
- payment details
- tax records
7. PII Is Accessed or Stolen
Once personal information is accessed, copied, exposed, or disclosed without authorization, the incident may become a PII breach.
This attack chain explains why phishing is the expected answer when asking which of the following is responsible for most of the recent PII data breaches in the common training context.
What Types of Phishing Can Threaten PII?
Phishing is no longer limited to email.
| Phishing Type | How It Works |
| Email phishing | Fraudulent email sent to victims |
| Spear phishing | Highly targeted message |
| Smishing | Phishing through SMS or text |
| Vishing | Fraudulent phone or voice interaction |
| QR phishing | Malicious QR code leads to a fake site |
| Business email compromise | Business identity or account is impersonated |
| Social-media phishing | Fraudulent message through social platforms |
| OAuth phishing | User is tricked into granting application access |
| Device-code phishing | Authentication workflow is manipulated |
| Session/token theft | Attacker targets authenticated access |
The expansion of phishing beyond email is one reason cybersecurity teams increasingly focus on the broader category of social engineering.
What Does Current 2026 Data Breach Research Show?
The answer to which of the following is responsible for most of the recent PII data breaches should not be confused with a universal statistic covering every modern cyberattack.
Different breach reports measure different:
- industries
- countries
- organizations
- attack categories
- time periods
- reporting systems
- breach definitions
Verizon 2026 Data Breach Investigations Report
Verizon’s 2026 DBIR says 31% of breaches in its dataset begin with software vulnerability exploitation.
According to the report, vulnerability exploitation has overtaken stolen credentials as the leading initial entry point.
Verizon also reports that:
- ransomware is involved in 48% of breaches
- AI is contributing to multiple attack techniques
- attackers continue targeting third parties
- social engineering remains an important threat
This is why saying “phishing causes most data breaches” without context would be inaccurate.
IBM Cost of a Data Breach Report 2026
IBM’s 2026 research reports that the global average organizational cost of a data breach reached $4.99 million.
IBM also reports substantial growth in AI-driven attacks.
IBM’s 2026 India Findings
The results look different when focusing specifically on India.
IBM reports that phishing, including voice and SMS phishing, was the most common initial attack vector among Indian organizations in its study at 19%.
It was followed by:
- drive-by compromise at 16%
- supply-chain compromise at 15%.
IBM also reported that the average organizational breach cost in India reached approximately INR 255 million, or INR 25.5 crore, in 2026.
This shows why cybersecurity statistics need context.
Which of the Following Is Responsible for Most of the Recent PII Data Breaches: Training Answer vs Reality
| Question | Accurate Answer |
| Expected answer to the common PII training question | Phishing |
| Does phishing lead every 2026 breach dataset? | No |
| Verizon’s leading initial entry point | Vulnerability exploitation, 31% |
| IBM India’s leading initial vector | Phishing, 19% |
| Can phishing expose PII? | Yes |
| Can insiders expose PII? | Yes |
| Can vulnerabilities expose PII? | Yes |
| Can third-party compromise expose PII? | Yes |
The key takeaway is simple:
The training answer is phishing. Real-world cybersecurity is more complicated.
Recent 2026 Example: Apollo Global Data Breach
A recent incident illustrates how human-focused attacks can contribute to the exposure of personally identifiable information.
In August 2026, Apollo Global Management disclosed unauthorized access to certain cloud platforms.
Information potentially affected included:
- names
- dates of birth
- contact information
- home addresses
- Social Security numbers
The incident occurred amid a wider campaign involving attacks against financial companies and other organizations.
Attackers in the broader campaign reportedly used techniques including phone-based social engineering.
The example reinforces an important lesson:
Attackers do not always need highly sophisticated malware if they can manipulate legitimate users into granting access.
Why Phishing Remains Effective
It Targets Human Judgment
Organizations can install:
- firewalls
- antivirus software
- encryption
- access controls
- endpoint protection
Phishing attempts to persuade a legitimate person to help bypass those defenses.
It Can Look Professional
Modern phishing messages may include:
- correct names
- company logos
- professional grammar
- realistic websites
- known vendors
- familiar company language
It Creates Urgency
Common pressure tactics include:
- account suspension
- password expiration
- urgent invoices
- security alerts
- payroll changes
- executive requests
It Can Be Personalized
Spear-phishing messages may include information about:
- a person’s employer
- job role
- manager
- projects
- suppliers
- customers
One Account Can Provide Broad Access
A compromised employee account may provide access to:
- customer records
- payroll systems
- cloud documents
- internal email
- financial information
- employee records
These characteristics help explain why phishing remains central to the discussion around which of the following is responsible for most of the recent PII data breaches.
How AI Is Changing Phishing in 2026

Artificial intelligence is making some phishing campaigns easier to create, personalize, and scale.
AI can help attackers:
- produce professional-looking messages
- generate large numbers of variations
- translate phishing content
- imitate writing styles
- create synthetic voices
- generate deepfake impersonations
- automate research
- accelerate attack workflows
This means older advice such as “look for bad spelling” is no longer sufficient.
A professional-looking message can still be malicious.
Users should verify:
- who is making the request
- why the request was made
- where the link actually leads
- whether an authentication request was expected
- whether the request can be independently confirmed.
Can Phishing Bypass Multifactor Authentication?
Some phishing techniques can target weaker MFA methods.
Attackers may attempt to:
- steal one-time authentication codes
- persuade users to approve login prompts
- steal authenticated sessions
- capture access tokens
- abuse OAuth permissions
- manipulate device-code workflows
This does not mean MFA is ineffective
MFA is still safer than relying on passwords alone.
The important difference is that some authentication methods provide stronger phishing resistance than others.
MFA Methods Compared
| Authentication Method | General Phishing Resistance |
| Password only | Low |
| SMS code | Better than password alone, but phishable |
| Email code | Better than password alone, but phishable |
| Authenticator one-time code | Stronger, but still potentially phishable |
| Push approval | Stronger, but users can be manipulated |
| FIDO/WebAuthn security key | Phishing-resistant |
| FIDO-based passkey | Designed to resist credential phishing |
Organizations handling sensitive PII should consider phishing-resistant authentication where practical.
Why Are the Other Answers Not Correct?
If the question asks which of the following is responsible for most of the recent PII data breaches, the other choices are still security risks—but they are not the expected training answer.
| Option | Can Cause PII Exposure? | Expected Answer? |
| Phishing | Yes | Yes |
| Insider threat | Yes | No |
| Improper document disposal | Yes | No |
| Physical breaking and entry | Yes | No |
Insider Threat
An employee, contractor, administrator, or vendor may intentionally or accidentally expose personal information.
Examples include:
- unauthorized record access
- sending PII to the wrong person
- copying customer information
- incorrectly sharing files
- deliberately stealing records
Improper Disposal
Documents and electronic storage containing PII should be destroyed securely.
Sensitive information left in:
- paper documents
- abandoned hard drives
- USB devices
- backup media
may become accessible to unauthorized individuals.
Physical Theft
Physical theft may expose:
- laptops
- smartphones
- printed records
- hard drives
- portable storage
- backup media
Encryption and device-management controls can reduce the impact.
Phishing, Social Engineering, and Insider Threats Compared
| Threat | Meaning |
| Phishing | Deceptive communication designed to steal information or access |
| Social engineering | Broad category involving manipulation of people |
| Insider threat | Risk originating from someone with legitimate organizational access |
Phishing is a form of social engineering.
However:
Not every social-engineering attack is phishing.
Similarly, an employee who accidentally falls for a phishing message should not automatically be considered a malicious insider.
What PII Do Attackers Commonly Target?
Attackers may seek information that can be sold, combined with other data, or used for fraud.
Common targets include:
- Social Security numbers
- names
- dates of birth
- home addresses
- email addresses
- phone numbers
- passwords
- account details
- financial information
- payment-card information
- government IDs
- tax records
- medical records
- employee information
Why Combined PII Creates Greater Risk
Several pieces of personal information together can be much more valuable than one individual data point.
For example:
Name + date of birth + Social Security number + home address
may provide significantly more opportunities for identity fraud than a name alone.
What Can Happen After PII Is Exposed?
Risks to Individuals
PII exposure may contribute to:
- identity theft
- financial fraud
- account takeover
- fraudulent applications
- impersonation
- targeted phishing
- privacy loss
Risks to Organizations
Organizations may experience:
- forensic investigation costs
- operational disruption
- breach-notification expenses
- regulatory scrutiny
- legal expenses
- customer-support costs
- reputational damage
- lost business
The financial and reputational consequences can be significant, especially when a breach involves sensitive information belonging to large numbers of people.
Are PII Breaches Always Caused by Hackers?
No.
PII can be exposed through intentional attacks, human mistakes, weak processes, or technical failures.
Common causes include:
- phishing
- software vulnerabilities
- credential theft
- ransomware
- malicious insiders
- accidental disclosure
- cloud misconfiguration
- third-party compromise
- lost devices
- incorrect permissions
- insecure document disposal
This is why organizations should not build their entire privacy and security program around one threat.
Is Human Error Responsible for Most PII Breaches?
There is no universal answer because cybersecurity reports define the human element differently.
A single breach could involve:
- an employee receiving a phishing message
- credentials being stolen
- the attacker accessing a cloud account
- PII being accessed
- ransomware being deployed
One report might classify the incident as:
phishing
Another might emphasize:
credential compromise
Another may classify it as:
social engineering
And another may focus on:
ransomware
These terms may describe different stages of the same attack.
How Organizations Can Prevent PII Data Breaches
The strongest approach uses multiple layers of protection.
1. Use Strong Authentication
Organizations should move beyond password-only authentication.
Consider:
- MFA
- FIDO/WebAuthn
- security keys
- passkeys
- conditional-access policies
2. Train Employees
Security awareness training should cover:
- suspicious login requests
- unexpected attachments
- QR-code scams
- vishing
- suspicious MFA prompts
- fraudulent login pages
- urgent payment requests
Employees should also know how to report suspicious activity quickly.
3. Apply Least-Privilege Access
Users should only have access to systems and information required for their work. If one account becomes compromised, least privilege can limit how much PII attackers can reach.
4. Patch Vulnerabilities Quickly
Organizations should:
- maintain an asset inventory
- identify internet-facing systems
- prioritize critical vulnerabilities
- install security updates
- remove unsupported software
- confirm remediation
The importance of vulnerability management is especially clear in 2026 because current breach data shows software exploitation has become a major initial entry method.
5. Minimize PII Collection
Organizations should ask:
- Do we need this information?
- Why are we storing it?
- How long do we need to keep it?
- Who needs access?
- Can the data be anonymized?
- Can old information be deleted?
Less stored PII generally means less information is available to expose during a breach.
6. Encrypt Sensitive Information
Organizations should consider encryption for:
- databases
- backups
- laptops
- portable storage
- sensitive documents
- data in transit
7. Monitor Accounts and Systems
Possible warning signs include:
- unfamiliar logins
- impossible travel
- unusual downloads
- unexpected mailbox rules
- unusual privilege changes
- suspicious cloud activity
8. Control Third-Party Access
Organizations should regularly review:
- which vendors have access
- which systems they can reach
- what PII they can view
- how vendor accounts authenticate
- whether access is still required
What Should a Business Do After a PII Breach?
Organizations should respond quickly but carefully.
A practical response may include:
- Contain the incident.
- Secure affected accounts and systems.
- Preserve evidence.
- Determine how attackers gained access.
- Identify the information affected.
- Determine who may have been affected.
- Reset compromised credentials.
- Revoke stolen sessions or tokens.
- Fix vulnerabilities or process failures.
- Consult cybersecurity and legal professionals where appropriate.
- Evaluate breach-notification requirements.
- Inform affected individuals when required.
- Improve controls after the investigation.
Exact legal requirements depend on the jurisdiction, industry, and information involved.
What Should a PII Breach Notification Include?
A useful breach notification should tell affected individuals what happened and what they may need to do.
Depending on applicable rules and circumstances, a notification may include:
- what happened
- when the incident occurred
- when it was discovered
- what information was affected
- what the organization has done
- what affected individuals should do
- which protective services are available
- where to get additional information
How Can Individuals Protect Their PII From Phishing?
Individuals can reduce risk by using a few consistent security habits.
- Use a unique password for each important account.
- Use a reputable password manager.
- Enable MFA.
- Prefer phishing-resistant authentication where available.
- Avoid signing in through unexpected links.
- Navigate directly to trusted websites.
- Verify unusual requests through another communication method.
- Never approve unexpected MFA prompts.
- Be cautious with QR codes.
- Keep software updated.
- Review active sessions.
- Report suspicious messages.
A useful rule is:
Urgency should increase verification, not reduce it.
What Should You Do If Your PII Has Been Exposed?
The appropriate response depends on the type of information involved.
| Information Exposed | Possible Action |
| Password | Change it immediately |
| Reused password | Change it everywhere it was reused |
| Email credentials | Review sessions and strengthen authentication |
| Social Security number | Consider fraud alerts or a credit freeze |
| Bank information | Contact the bank |
| Payment card | Contact the card issuer and monitor activity |
| Government ID | Follow the issuing authority’s guidance |
| Multiple identifiers | Monitor carefully for identity misuse |
People should also watch for follow-up phishing after a breach. Once criminals possess real personal information, future phishing messages can become more convincing.
Why “Which of the Following Is Responsible for Most of the Recent PII Data Breaches?” Needs Context: The phrase ” Which of the following is responsible for most of the recent PII data breaches sounds like a universal cybersecurity statistic.
It is better understood as a specific multiple-choice training question.
For that question:
The expected answer is phishing.
Current 2026 cybersecurity research provides a broader picture.
For example:
- Vulnerability exploitation leads Verizon’s overall initial breach entry points
- phishing leads IBM’s India initial attack vectors
- ransomware remains heavily involved in breaches
- AI-enabled attack techniques are growing
These findings do not necessarily contradict one another.
They examine different:
- regions
- populations
- organizations
- attack categories
- methodologies
Conclusion: Which of the Following Is Responsible for Most of the Recent PII Data Breaches
Phishing remains a serious threat because it can lead to credential theft, account takeover, unauthorized access, and exposure of personally identifiable information. But when asking which of the following is responsible for most of the recent PII data breaches, it is important to separate the expected quiz answer from the broader 2026 cybersecurity landscape.
Modern PII breaches can also begin with:
- software vulnerabilities
- stolen credentials
- insider misuse
- ransomware
- third-party compromise
- cloud misconfiguration
- accidental disclosure
Memorizing phishing answers answers the training question. Protecting PII in the real world requires a much wider strategy.
Organizations that combine phishing awareness with strong authentication, rapid patching, least-privilege access, encryption, data minimization, monitoring, vendor management, and effective incident response are better prepared to reduce both the likelihood and impact of PII data breaches.
Which of the Following Is Responsible for Most of the Recent PII Data Breaches FAQs
1. Which of the Following Is Responsible for Most of the Recent PII Data Breaches?
For the commonly reproduced PII cybersecurity training question, the expected answer is phishing. Phishing can steal credentials or provide unauthorized access to systems containing personally identifiable information.
2. Why Is Phishing Responsible for PII Data Breaches?
Phishing tricks users into revealing passwords, authentication codes, or sensitive information. Stolen credentials can then be used to access systems containing PII.
3. What Information Is Considered PII in a Data Breach?
PII can include names, Social Security numbers, addresses, phone numbers, financial details, government IDs, medical information, and account credentials linked to an individual.
4. Are All PII Data Breaches Caused by Phishing?
No. PII breaches can also result from software vulnerabilities, stolen credentials, insider threats, ransomware, cloud misconfigurations, accidental disclosures, and third-party compromises.
5. How Can Organizations Prevent PII Data Breaches?
Organizations can reduce PII breach risk through phishing-resistant MFA, employee security training, rapid patching, encryption, least-privilege access, monitoring, and data minimization.