Research

The Misdirected Email Problem

Every year, thousands of data breaches are caused by employees sending emails to the wrong person. These are the numbers behind the problem — sourced from independent research.

Regulatory Data

UK ICO Incident Trends 2024

Data security incident trends reported to the UK Information Commissioner’s Office in Q1 2024.

18%

Of all data security incidents were emails sent to the wrong recipient — the single most common incident type

#1

Misdirected email is the leading cause of accidental data loss, consistently ranking first across all 2024 quarters

2,970

Total data security incidents reported to the ICO in Q1 2024 — a 21% increase from Q1 2023

73%

Of reported incidents were non-cyber (human error), not malicious attacks

Industry Research

Data Loss Prevention on Email

Findings from the Ponemon Institute’s 2022 study of 614 IT and IT security practitioners on email data loss.

40%

Of data loss incidents caused by employee negligence — not following security policies

48h

Average time to detect and remediate an incident caused by a negligent employee

65%

Of IT security practitioners say email is the riskiest channel for data loss

41%

Say current DLP solutions fail to effectively prevent misdirected email data loss

3 in 5

Organizations experienced accidental data loss over email in the past year

18 mo

Average time to deploy and find value from traditional DLP solutions

Why It Matters

Outbound Email Risk

IT decision-makers recognize outbound email as a critical and under-addressed risk vector.

66%

Of IT leaders admit outbound mistakes cause more data loss than inbound attacks

212

Outbound email incidents per month at the average organization

39%

Less than 2 in 5 IT leaders prioritize outbound email security

60%

Of employees use workarounds to bypass security policies

Employee Behavior

The Human Factor

Employees are the front line of email security — and the most common source of mistakes.

54%

Of employees say they are more likely to make email mistakes when busy or overwhelmed

38%

Of employees don’t fully understand their organization’s email security policies

47%

Of IT leaders cite inbound threats like phishing as their primary concern — overlooking outbound risk

34%

Of outbound email incidents are formally reported — most go undetected

33%

Of employees have sent wrong attachments in work emails

32%

Of employees have sent emails to the wrong recipient

FAQ

Frequently asked questions

Common questions about the misdirected email problem — answered with verified research.

1

How common are misdirected emails?

Misdirected email is the #1 reported data security incident type. In Q1 2024, 18% of all 2,970 incidents reported to the UK ICO were emails sent to the wrong recipient — a 21% increase from Q1 2023.

UK ICO — Data Security Incident Trends (2024)

2

Are misdirected emails really a security issue?

73% of data security incidents reported to the ICO are non-cyber — caused by human error, not hackers. Misdirected emails consistently rank as the single most common incident type, ahead of phishing and ransomware.

Osterman Research — ICO 2024 Update

3

Why can't we just train employees better?

73% of employees are aware of security policies, but only 52% actually adhere to them. 54% say they make more email mistakes when busy or overwhelmed, and 38% don't fully understand their organization's email security policies.

Zivver — Email Security Trends Report 2025

4

Do most misdirected email incidents get caught?

No. Only 34% of outbound email incidents are formally reported — the majority go undetected. 33% of employees have sent wrong attachments and 32% have sent emails to the wrong recipient without reporting it.

Zivver — Email Security Trends Report 2025

5

Why not use existing DLP solutions?

Traditional DLP takes an average of 18 months to deploy and find value. Only 41% of IT security practitioners say current DLP solutions effectively prevent misdirected email data loss.

Ponemon Institute / Tessian — DLP on Email (2022)

6

Isn't email security mostly about inbound threats?

66% of IT leaders admit that outbound mistakes cause more data loss than inbound attacks. Yet 47% still cite inbound threats like phishing as their primary concern — leaving outbound risk under-addressed.

Dark Reading — Zivver Report Coverage

7

Is the problem getting worse?

Yes. The ICO reported a 21% increase in data security incidents from Q1 2023 to Q1 2024, and misdirected email rose from 18% to 21% of all incidents between Q1 and Q4 2024. In the Netherlands, 85% of data breaches in 2024 were caused by human email errors.

UK ICO — Data Security Incident Trends (2024)

8

How many employees bypass security policies?

60% of employees report using workarounds to bypass security policies. Among frequent mistake-makers, policy confusion climbs to 52%. Even though 73% of employees are aware of policies, only 52% actually adhere to them.

Zivver — Email Security Trends Report 2025

Ready to prevent accidental email data leaks?

Start securing your emails in minutes. Try it free.