HomeTechnologyWhich of the Following Is Responsible for Most of the Recent PII...

Which of the Following Is Responsible for Most of the Recent PII Data Breaches? Explained

Table of contents [show]

If you are searching for which of the following is responsible for most of the recent PII data breaches, the expected answer to the commonly reproduced cybersecurity training question is phishing.

Phishing attacks use deceptive emails, text messages, phone calls, QR codes, fake login pages, and other communications to trick people into revealing passwords, personal information, authentication codes, or access to protected systems. Once an attacker gains access to an account, personally identifiable information may also become exposed.

However, there is an important distinction. If a quiz asks which of the following is responsible for most of the recent PII data breaches, phishing is the intended answer. That does not mean phishing causes most data breaches in every modern cybersecurity dataset.

Verizon’s 2026 Data Breach Investigations Report says 31% of breaches in its dataset begin with exploitation of software vulnerabilities, making vulnerability exploitation its leading initial entry point.

This guide explains why phishing is the expected answer, what personally identifiable information means, how phishing can lead to PII exposure, what current 2026 breach research shows, and how individuals and organizations can reduce the risk.

Quick Answer: Which of the Following Is Responsible for Most of the Recent PII Data Breaches?

For the commonly reproduced question, which of the following is responsible for most of the recent PII data breaches, the correct training answer is:

Phishing

The question generally appears with choices similar to these:

Answer Choice Correct Answer?
Reconstruction of improperly disposed documents No
Phishing Yes
Insider threat No
Physical breaking and entry No

All of these can create security risks, but phishing is the expected answer to this specific PII safeguarding question.

At a Glance

Question Quick Answer
Which of the following is responsible for most of the recent PII data breaches? Phishing
Is phishing a form of social engineering? Yes
Is every phishing attempt a PII breach? No
Can phishing lead to PII exposure? Yes
Can insiders expose PII? Yes
Are software vulnerabilities important in 2026? Yes
Verizon’s leading 2026 initial entry point Vulnerability exploitation, 31%
IBM India’s leading 2026 initial vector Phishing, 19%

Key Takeaways

  • Phishing is the expected answer to the commonly reproduced PII training question.
  • PII is information that identifies or can reasonably be linked to an individual.
  • Phishing can expose PII by compromising passwords, authentication sessions, accounts, or access to sensitive systems.
  • A phishing message does not automatically mean that a PII breach occurred.
  • Modern breaches can also involve vulnerabilities, ransomware, stolen credentials, insiders, cloud misconfiguration, and third-party compromise.
  • Strong authentication, employee awareness, encryption, patching, monitoring, least-privilege access, and data minimization can reduce PII breach risk.

What Is Personally Identifiable Information?

Personally identifiable information, usually abbreviated as PII, is information that can identify a specific person or reasonably be linked to an individual.

PII can include information that directly identifies a person as well as information that becomes identifying when combined with other data.

Common Examples of PII

Type of PII Examples
Identity information Full name, Social Security number, passport number
Contact information Address, email address, phone number
Government identifiers Driver’s license number, taxpayer ID
Financial information Bank details, account information
Biometric information Fingerprints, facial identifiers
Employment information Personnel and employee records
Educational information Student records
Medical information Identifiable health information
Account information Usernames and identifiers tied to a person

Not every piece of PII presents the same level of risk.

A person’s name may already be publicly available. But combining a name with a Social Security number, date of birth, home address, bank information, and login credentials can create a much higher risk of fraud or identity theft.

What Is Sensitive PII?

Some types of personal information can cause greater harm if exposed.

Sensitive PII may include:

  • Social Security numbers
  • bank account details
  • government ID numbers
  • medical records
  • authentication credentials
  • biometric data
  • tax information
  • payment information
  • combinations of several personal identifiers

The sensitivity of PII also depends on context.

A phone number displayed on a public business website may create relatively little privacy risk. The same phone number connected to medical, financial, or employment information may reveal significantly more about an individual.

What Counts as a PII Data Breach?

Understanding this distinction makes the question of which of the following is responsible for most of the recent PII data breaches much easier to interpret.

A phishing attempt is an attack.

A PII breach is what may happen after unauthorized access, loss, disclosure, or exposure of personal information occurs.

A PII breach may involve information being:

  • accessed without authorization
  • disclosed to an unauthorized person
  • stolen
  • lost
  • improperly acquired
  • publicly exposed
  • or placed outside appropriate organizational control.

Examples include:

  • an attacker accessing a customer database
  • personal records being sent to the wrong recipient
  • cloud storage accidentally becoming public
  • an employee viewing records without authorization
  • an unprotected laptop containing PII being stolen
  • stolen credentials being used to access employee or customer data

Security Incident vs PII Breach

Situation Security Incident? Potential PII Breach?
Phishing email received but ignored Yes Usually no
Password entered on a phishing site Yes Not automatically
Stolen account used to access PII Yes Yes
PII sent to the wrong recipient Yes Potentially
Unauthorized employee views records Yes Yes
Device containing PII is stolen Yes Depends on safeguards

Phishing is an attack technique. A PII breach is the unauthorized exposure, access, acquisition, loss, or disclosure of personally identifiable information that may result from the attack.

Are All PII Data Breaches Equally Serious?

No.

The potential impact of a breach depends on factors such as:

  • what information was exposed
  • how sensitive the information is
  • how many individuals were affected
  • whether multiple identifiers can be combined
  • whether the information was encrypted
  • who gained access
  • how long the exposure lasted
  • whether data was copied
  • how easily the information can be misused

PII Breach Risk Examples

Exposed Information Potential Concern
Social Security number Identity fraud
Account password Account takeover
Bank information Financial fraud
Multiple identifiers Impersonation
Medical records Privacy harm
Authentication token Unauthorized account access
Large customer database Large-scale exposure

A smaller breach containing highly sensitive information can sometimes create more risk than a larger breach containing less-sensitive data.

Why Is Phishing the Correct Answer?

When someone asks which of the following is responsible for most of the recent PII data breaches, the answer is phishing because phishing is a common method of manipulating legitimate users into exposing information or providing access.

Phishing attacks exploit trust, urgency, fear, authority, and familiarity.

Attackers may impersonate:

  • banks
  • employers
  • government agencies
  • IT administrators
  • cloud-service providers
  • senior executives
  • vendors
  • delivery companies
  • coworkers

The victim may be asked to:

  • click a fraudulent link
  • enter a password
  • verify an account
  • open an attachment
  • approve an MFA request
  • provide sensitive data
  • scan a malicious QR code
  • call a fraudulent support number
  • authorize a cloud application.

The victim may believe the request is legitimate because the communication appears to come from a trusted organization or person.

How Can Phishing Lead to a PII Data Breach?

Phishing often represents the beginning of an attack chain, not the entire breach.

1. The Attacker Contacts the Victim

The victim receives a deceptive:

  • email
  • SMS message
  • phone call
  • QR code
  • social-media message
  • authentication request

2. The Attacker Creates Urgency

Common claims include:

  • “Your password expires today.”
  • “Your account has been suspended.”
  • “Review this confidential document.”
  • “A payment requires immediate approval.”
  • “Suspicious activity was detected.”
  • “IT needs you to verify your account.”

3. The Victim Takes Action

The user may:

  • enter credentials into a fake website
  • provide personal information
  • approve a login
  • download an attachment
  • grant application permissions

4. The Attacker Gains Access

Stolen passwords, tokens, or authenticated sessions may allow an attacker to appear to be a legitimate user.

5. Additional Systems Are Reached

Depending on the compromised account’s permissions, attackers may reach:

  • email
  • cloud storage
  • HR platforms
  • customer databases
  • payroll systems
  • financial platforms
  • administrator tools

6. PII Is Located

The system may contain:

  • customer data
  • employee information
  • patient records
  • student information
  • payment details
  • tax records

7. PII Is Accessed or Stolen

Once personal information is accessed, copied, exposed, or disclosed without authorization, the incident may become a PII breach.

This attack chain explains why phishing is the expected answer when asking which of the following is responsible for most of the recent PII data breaches in the common training context.

What Types of Phishing Can Threaten PII?

Phishing is no longer limited to email.

Phishing Type How It Works
Email phishing Fraudulent email sent to victims
Spear phishing Highly targeted message
Smishing Phishing through SMS or text
Vishing Fraudulent phone or voice interaction
QR phishing Malicious QR code leads to a fake site
Business email compromise Business identity or account is impersonated
Social-media phishing Fraudulent message through social platforms
OAuth phishing User is tricked into granting application access
Device-code phishing Authentication workflow is manipulated
Session/token theft Attacker targets authenticated access

The expansion of phishing beyond email is one reason cybersecurity teams increasingly focus on the broader category of social engineering.

What Does Current 2026 Data Breach Research Show?

The answer to which of the following is responsible for most of the recent PII data breaches should not be confused with a universal statistic covering every modern cyberattack.

Different breach reports measure different:

  • industries
  • countries
  • organizations
  • attack categories
  • time periods
  • reporting systems
  • breach definitions

Verizon 2026 Data Breach Investigations Report

Verizon’s 2026 DBIR says 31% of breaches in its dataset begin with software vulnerability exploitation.

According to the report, vulnerability exploitation has overtaken stolen credentials as the leading initial entry point.

Verizon also reports that:

  • ransomware is involved in 48% of breaches
  • AI is contributing to multiple attack techniques
  • attackers continue targeting third parties
  • social engineering remains an important threat

This is why saying “phishing causes most data breaches” without context would be inaccurate.

IBM Cost of a Data Breach Report 2026

IBM’s 2026 research reports that the global average organizational cost of a data breach reached $4.99 million.

IBM also reports substantial growth in AI-driven attacks.

IBM’s 2026 India Findings

The results look different when focusing specifically on India.

IBM reports that phishing, including voice and SMS phishing, was the most common initial attack vector among Indian organizations in its study at 19%.

It was followed by:

  • drive-by compromise at 16%
  • supply-chain compromise at 15%.

IBM also reported that the average organizational breach cost in India reached approximately INR 255 million, or INR 25.5 crore, in 2026.

This shows why cybersecurity statistics need context.

Which of the Following Is Responsible for Most of the Recent PII Data Breaches: Training Answer vs Reality

Question Accurate Answer
Expected answer to the common PII training question Phishing
Does phishing lead every 2026 breach dataset? No
Verizon’s leading initial entry point Vulnerability exploitation, 31%
IBM India’s leading initial vector Phishing, 19%
Can phishing expose PII? Yes
Can insiders expose PII? Yes
Can vulnerabilities expose PII? Yes
Can third-party compromise expose PII? Yes

The key takeaway is simple:

The training answer is phishing. Real-world cybersecurity is more complicated.

Recent 2026 Example: Apollo Global Data Breach

A recent incident illustrates how human-focused attacks can contribute to the exposure of personally identifiable information.

In August 2026, Apollo Global Management disclosed unauthorized access to certain cloud platforms.

Information potentially affected included:

  • names
  • dates of birth
  • contact information
  • home addresses
  • Social Security numbers

The incident occurred amid a wider campaign involving attacks against financial companies and other organizations.

Attackers in the broader campaign reportedly used techniques including phone-based social engineering.

The example reinforces an important lesson:

Attackers do not always need highly sophisticated malware if they can manipulate legitimate users into granting access.

Why Phishing Remains Effective

It Targets Human Judgment

Organizations can install:

  • firewalls
  • antivirus software
  • encryption
  • access controls
  • endpoint protection

Phishing attempts to persuade a legitimate person to help bypass those defenses.

It Can Look Professional

Modern phishing messages may include:

  • correct names
  • company logos
  • professional grammar
  • realistic websites
  • known vendors
  • familiar company language

It Creates Urgency

Common pressure tactics include:

  • account suspension
  • password expiration
  • urgent invoices
  • security alerts
  • payroll changes
  • executive requests

It Can Be Personalized

Spear-phishing messages may include information about:

  • a person’s employer
  • job role
  • manager
  • projects
  • suppliers
  • customers

One Account Can Provide Broad Access

A compromised employee account may provide access to:

  • customer records
  • payroll systems
  • cloud documents
  • internal email
  • financial information
  • employee records

These characteristics help explain why phishing remains central to the discussion around which of the following is responsible for most of the recent PII data breaches.

How AI Is Changing Phishing in 2026

Which of the following is responsible for most of the recent pii data breaches? Professional using a laptop, illustrating phishing risks and credential theft that can expose personal data.
Which of the following is responsible for most of the recent pii data breaches Phishing can trick users into revealing credentials or sensitive information potentially enabling unauthorized access to systems containing pii Cisa specifically warns that phishing messages may request pii or use deceptive links to compromise users

Artificial intelligence is making some phishing campaigns easier to create, personalize, and scale.

AI can help attackers:

  • produce professional-looking messages
  • generate large numbers of variations
  • translate phishing content
  • imitate writing styles
  • create synthetic voices
  • generate deepfake impersonations
  • automate research
  • accelerate attack workflows

This means older advice such as “look for bad spelling” is no longer sufficient.

A professional-looking message can still be malicious.

Users should verify:

  • who is making the request
  • why the request was made
  • where the link actually leads
  • whether an authentication request was expected
  • whether the request can be independently confirmed.

Can Phishing Bypass Multifactor Authentication?

Some phishing techniques can target weaker MFA methods.

Attackers may attempt to:

  • steal one-time authentication codes
  • persuade users to approve login prompts
  • steal authenticated sessions
  • capture access tokens
  • abuse OAuth permissions
  • manipulate device-code workflows

This does not mean MFA is ineffective

MFA is still safer than relying on passwords alone.

The important difference is that some authentication methods provide stronger phishing resistance than others.

MFA Methods Compared

Authentication Method General Phishing Resistance
Password only Low
SMS code Better than password alone, but phishable
Email code Better than password alone, but phishable
Authenticator one-time code Stronger, but still potentially phishable
Push approval Stronger, but users can be manipulated
FIDO/WebAuthn security key Phishing-resistant
FIDO-based passkey Designed to resist credential phishing

Organizations handling sensitive PII should consider phishing-resistant authentication where practical.

Why Are the Other Answers Not Correct?

If the question asks which of the following is responsible for most of the recent PII data breaches, the other choices are still security risks—but they are not the expected training answer.

Option Can Cause PII Exposure? Expected Answer?
Phishing Yes Yes
Insider threat Yes No
Improper document disposal Yes No
Physical breaking and entry Yes No

Insider Threat

An employee, contractor, administrator, or vendor may intentionally or accidentally expose personal information.

Examples include:

  • unauthorized record access
  • sending PII to the wrong person
  • copying customer information
  • incorrectly sharing files
  • deliberately stealing records

Improper Disposal

Documents and electronic storage containing PII should be destroyed securely.

Sensitive information left in:

  • paper documents
  • abandoned hard drives
  • USB devices
  • backup media

may become accessible to unauthorized individuals.

Physical Theft

Physical theft may expose:

  • laptops
  • smartphones
  • printed records
  • hard drives
  • portable storage
  • backup media

Encryption and device-management controls can reduce the impact.

Phishing, Social Engineering, and Insider Threats Compared

Threat Meaning
Phishing Deceptive communication designed to steal information or access
Social engineering Broad category involving manipulation of people
Insider threat Risk originating from someone with legitimate organizational access

Phishing is a form of social engineering.

However:

Not every social-engineering attack is phishing.

Similarly, an employee who accidentally falls for a phishing message should not automatically be considered a malicious insider.

What PII Do Attackers Commonly Target?

Attackers may seek information that can be sold, combined with other data, or used for fraud.

Common targets include:

  • Social Security numbers
  • names
  • dates of birth
  • home addresses
  • email addresses
  • phone numbers
  • passwords
  • account details
  • financial information
  • payment-card information
  • government IDs
  • tax records
  • medical records
  • employee information

Why Combined PII Creates Greater Risk

Several pieces of personal information together can be much more valuable than one individual data point.

For example:

Name + date of birth + Social Security number + home address

may provide significantly more opportunities for identity fraud than a name alone.

What Can Happen After PII Is Exposed?

Risks to Individuals

PII exposure may contribute to:

  • identity theft
  • financial fraud
  • account takeover
  • fraudulent applications
  • impersonation
  • targeted phishing
  • privacy loss

Risks to Organizations

Organizations may experience:

  • forensic investigation costs
  • operational disruption
  • breach-notification expenses
  • regulatory scrutiny
  • legal expenses
  • customer-support costs
  • reputational damage
  • lost business

The financial and reputational consequences can be significant, especially when a breach involves sensitive information belonging to large numbers of people.

Are PII Breaches Always Caused by Hackers?

No.

PII can be exposed through intentional attacks, human mistakes, weak processes, or technical failures.

Common causes include:

  • phishing
  • software vulnerabilities
  • credential theft
  • ransomware
  • malicious insiders
  • accidental disclosure
  • cloud misconfiguration
  • third-party compromise
  • lost devices
  • incorrect permissions
  • insecure document disposal

This is why organizations should not build their entire privacy and security program around one threat.

Is Human Error Responsible for Most PII Breaches?

There is no universal answer because cybersecurity reports define the human element differently.

A single breach could involve:

  1. an employee receiving a phishing message
  2. credentials being stolen
  3. the attacker accessing a cloud account
  4. PII being accessed
  5. ransomware being deployed

One report might classify the incident as:

phishing

Another might emphasize:

credential compromise

Another may classify it as:

social engineering

And another may focus on:

ransomware

These terms may describe different stages of the same attack.

How Organizations Can Prevent PII Data Breaches

The strongest approach uses multiple layers of protection.

1. Use Strong Authentication

Organizations should move beyond password-only authentication.

Consider:

  • MFA
  • FIDO/WebAuthn
  • security keys
  • passkeys
  • conditional-access policies

2. Train Employees

Security awareness training should cover:

  • suspicious login requests
  • unexpected attachments
  • QR-code scams
  • vishing
  • suspicious MFA prompts
  • fraudulent login pages
  • urgent payment requests

Employees should also know how to report suspicious activity quickly.

3. Apply Least-Privilege Access

Users should only have access to systems and information required for their work. If one account becomes compromised, least privilege can limit how much PII attackers can reach.

4. Patch Vulnerabilities Quickly

Organizations should:

  • maintain an asset inventory
  • identify internet-facing systems
  • prioritize critical vulnerabilities
  • install security updates
  • remove unsupported software
  • confirm remediation

The importance of vulnerability management is especially clear in 2026 because current breach data shows software exploitation has become a major initial entry method.

5. Minimize PII Collection

Organizations should ask:

  • Do we need this information?
  • Why are we storing it?
  • How long do we need to keep it?
  • Who needs access?
  • Can the data be anonymized?
  • Can old information be deleted?

Less stored PII generally means less information is available to expose during a breach.

6. Encrypt Sensitive Information

Organizations should consider encryption for:

  • databases
  • backups
  • laptops
  • portable storage
  • sensitive documents
  • data in transit

7. Monitor Accounts and Systems

Possible warning signs include:

  • unfamiliar logins
  • impossible travel
  • unusual downloads
  • unexpected mailbox rules
  • unusual privilege changes
  • suspicious cloud activity

8. Control Third-Party Access

Organizations should regularly review:

  • which vendors have access
  • which systems they can reach
  • what PII they can view
  • how vendor accounts authenticate
  • whether access is still required

What Should a Business Do After a PII Breach?

Organizations should respond quickly but carefully.

A practical response may include:

  1. Contain the incident.
  2. Secure affected accounts and systems.
  3. Preserve evidence.
  4. Determine how attackers gained access.
  5. Identify the information affected.
  6. Determine who may have been affected.
  7. Reset compromised credentials.
  8. Revoke stolen sessions or tokens.
  9. Fix vulnerabilities or process failures.
  10. Consult cybersecurity and legal professionals where appropriate.
  11. Evaluate breach-notification requirements.
  12. Inform affected individuals when required.
  13. Improve controls after the investigation.

Exact legal requirements depend on the jurisdiction, industry, and information involved.

What Should a PII Breach Notification Include?

A useful breach notification should tell affected individuals what happened and what they may need to do.

Depending on applicable rules and circumstances, a notification may include:

  • what happened
  • when the incident occurred
  • when it was discovered
  • what information was affected
  • what the organization has done
  • what affected individuals should do
  • which protective services are available
  • where to get additional information

How Can Individuals Protect Their PII From Phishing?

Individuals can reduce risk by using a few consistent security habits.

  • Use a unique password for each important account.
  • Use a reputable password manager.
  • Enable MFA.
  • Prefer phishing-resistant authentication where available.
  • Avoid signing in through unexpected links.
  • Navigate directly to trusted websites.
  • Verify unusual requests through another communication method.
  • Never approve unexpected MFA prompts.
  • Be cautious with QR codes.
  • Keep software updated.
  • Review active sessions.
  • Report suspicious messages.

A useful rule is:

Urgency should increase verification, not reduce it.

What Should You Do If Your PII Has Been Exposed?

The appropriate response depends on the type of information involved.

Information Exposed Possible Action
Password Change it immediately
Reused password Change it everywhere it was reused
Email credentials Review sessions and strengthen authentication
Social Security number Consider fraud alerts or a credit freeze
Bank information Contact the bank
Payment card Contact the card issuer and monitor activity
Government ID Follow the issuing authority’s guidance
Multiple identifiers Monitor carefully for identity misuse

People should also watch for follow-up phishing after a breach. Once criminals possess real personal information, future phishing messages can become more convincing.

Why “Which of the Following Is Responsible for Most of the Recent PII Data Breaches?” Needs Context: The phrase ” Which of the following is responsible for most of the recent PII data breaches sounds like a universal cybersecurity statistic.

It is better understood as a specific multiple-choice training question.

For that question:

The expected answer is phishing.

Current 2026 cybersecurity research provides a broader picture.

For example:

  • Vulnerability exploitation leads Verizon’s overall initial breach entry points
  • phishing leads IBM’s India initial attack vectors
  • ransomware remains heavily involved in breaches
  • AI-enabled attack techniques are growing

These findings do not necessarily contradict one another.

They examine different:

  • regions
  • populations
  • organizations
  • attack categories
  • methodologies

Conclusion: Which of the Following Is Responsible for Most of the Recent PII Data Breaches

Phishing remains a serious threat because it can lead to credential theft, account takeover, unauthorized access, and exposure of personally identifiable information. But when asking which of the following is responsible for most of the recent PII data breaches, it is important to separate the expected quiz answer from the broader 2026 cybersecurity landscape.

Modern PII breaches can also begin with:

  • software vulnerabilities
  • stolen credentials
  • insider misuse
  • ransomware
  • third-party compromise
  • cloud misconfiguration
  • accidental disclosure

Memorizing phishing answers answers the training question. Protecting PII in the real world requires a much wider strategy.

Organizations that combine phishing awareness with strong authentication, rapid patching, least-privilege access, encryption, data minimization, monitoring, vendor management, and effective incident response are better prepared to reduce both the likelihood and impact of PII data breaches.

Which of the Following Is Responsible for Most of the Recent PII Data Breaches FAQs

1. Which of the Following Is Responsible for Most of the Recent PII Data Breaches?

For the commonly reproduced PII cybersecurity training question, the expected answer is phishing. Phishing can steal credentials or provide unauthorized access to systems containing personally identifiable information.

2. Why Is Phishing Responsible for PII Data Breaches?

Phishing tricks users into revealing passwords, authentication codes, or sensitive information. Stolen credentials can then be used to access systems containing PII.

3. What Information Is Considered PII in a Data Breach?

PII can include names, Social Security numbers, addresses, phone numbers, financial details, government IDs, medical information, and account credentials linked to an individual.

4. Are All PII Data Breaches Caused by Phishing?

No. PII breaches can also result from software vulnerabilities, stolen credentials, insider threats, ransomware, cloud misconfigurations, accidental disclosures, and third-party compromises.

5. How Can Organizations Prevent PII Data Breaches?

Organizations can reduce PII breach risk through phishing-resistant MFA, employee security training, rapid patching, encryption, least-privilege access, monitoring, and data minimization.

author avatar
Sofia Francis
Sofia Francis is a writer at Tycoonstory Media, specializing in business, startups, entrepreneurship, and marketing. She writes practical, research-based articles that help entrepreneurs, business owners, startup founders, and professionals understand market trends, growth strategies, digital marketing, and business opportunities. Her content focuses on making business knowledge simple, useful, and accessible for readers.

Must Read

Recent Published Startup Stories