Two TD Bank insiders. $9M in fraud. Zero malware involved.
They didn't hack in. They logged in, used the systems they were trusted with, and walked out with millions.
The warning signs were in the behavior. Not the transaction log.
New article: https://t.co/FR0eqWAuLT
Big news: Johnny Collins is joining InnerActiv as CTO. 20+ years hunting threats at Mandiant, KPMG, and Halcyon, and he's been using our platform in real investigations for years. Now he's building what comes next.
https://t.co/NUrKL3Y64x
51% of employees are operating outside their org's AI governance framework.
Not maliciously. Just... working.
The data loss looks the same either way.
New: why intent is not a security control β and what is.
https://t.co/b1jw7MDHQT
#AI#InsiderThreat#DataGovernance
Nobody buys smoke detectors after the building has burned down.
But that's how most organizations approach insider risk -- waiting until the damage is done to decide visibility was worth it.
The breach isn't the risk. The gap before it is.
https://t.co/605S5FZhRQ
#InsiderThreat
Voice phishing just overtook email as the #1 attack vector. No spam filter for a phone call. No way to screen a spoofed caller. Once access is gained, the hand-off to active fraud takes 22 seconds. Call centers and BPOs are the new target. https://t.co/BK4sIdobg3
#datasecurity
AI governance built on browser plugins and proxies only sees what routes through them.
AI embedded in your OS, your dev tools, your productivity suite? Invisible.
That's not a gap. That's the whole attack surface. https://t.co/bu2MkCPIV0
#AISecurity
Criminal forums are hiring. $15K for access. No malware needed. That's how Coinbase and Kraken were breached. A bribed support agent with valid credentials is invisible to traditional security. Behavioral monitoring isn't. https://t.co/MTWpIPwkOS
54% of orgs had an AI-related insider incident in the past year. 77% of employees are pasting company data into AI tools, mostly on personal accounts.
The prediction window has closed. New post on what that actually means for your security stack:
https://t.co/7QuBSbTcgx
#AI
AI didn't create the endpoint visibility gap. It just made ignoring it unaffordable. If your security stack relies on network-level controls, you're watching the wrong layer. Read more here: https://t.co/1On28pj7Aw
Thousands of AI-infused products at RSAC. Pick one. Install it. Employees are already typing into it, pasting into it, feeding it data β before IT has asked a single question about it.
Who's governing the AI inside any of it?
https://t.co/RTzueY8zdR
InnerActiv wins again with TWO new Global InfoSec awards:
ποΈ Editor's Choice for DLP
ποΈ Trailblazing Company for Insider Threat
Thank you to @Cyber-Defense-Magazine for the amazing recognition, and if you want to learn how we let AI Feedom Ring, visit booth N-6559 at RSAC!
RSAC 2026 has 600+ vendors on the floor. Half pitching AI. None talking about what happens when your employees beat them to it.
We did. https://t.co/UIwdZc2YyV
1 in 5 employees knows their company's AI policy.
The other 80% are pasting sensitive data into AI tools with zero oversight.
That's not a policy problem. It's a governance problem.
ποΈ https://t.co/tHHbUqMnLS
#AIGovernance#InsiderRisk#DataSecurity
Layoffs give insiders a reason to act. AI tools give them the means to do it fast.
Insider threats spike 40% during workforce reductions. Are you built to see it in time?
https://t.co/QtLPxqSGco
#InsiderThreat#AIRisk#CyberSecurity#InnerActiv
The most dangerous insiders aren't disgruntled employees. They're paid to steal your data.
Telecom. Financial services. Authorized access. And most security tools are completely blind to it.
AI is making it faster and harder to catch. π https://t.co/RlX2OkEccg
68% of employees use free AI tools through personal accounts. 57% enter sensitive company data while doing it.
That's not shadow AI. That's blind AI. And it has a fix.
https://t.co/8sUuwFTMPn
77% of employees are pasting company data into GenAI tools.
Most companies won't find out for 247 days.
That gap isn't a policy problem. It's a visibility problem.
New article breaking down why traditional security can't see it and what changes that π
https://t.co/VDSSYtsHEi
Everyone's being told to use more AI. Leadership wants it. Vendors are pushing it.
But most orgs have zero visibility into how employees are actually using it.
That's a security problem hiding in plain sight.
https://t.co/X5X9nE2PQE
Zero Trust can't protect against what it can't see.
AI tools like ChatGPT and Gemini operate outside your security perimeter. Every prompt, every upload, every shared file is invisible to traditional monitoring.
How to close the AI blind spot: https://t.co/e3TXVxZy0w
2026 insider threat reality: AI agents now outnumber humans 82 to 1, and orgs average 223 GenAI policy violations/month. Most security programs aren't ready for autonomous systems with broad access operating at machine speed.
https://t.co/UMDpsgaWcP