Why attackers target people first
The previous lesson revealed a blunt truth: attackers usually log in rather than break in. This lesson is about why, and what to do about it, because the human layer is where most real breaches begin.
The reason is simple economics. Finding and exploiting a novel software flaw is hard, expensive, and uncertain. Tricking a person into clicking a link or reusing a password is cheap, reliable, and works at scale. Given a choice between attacking a well-built lock and asking someone to hand over the key, attackers overwhelmingly choose the key.
The data confirms it. Verizon's 2025 Data Breach Investigations Report found the human element, errors and social engineering, involved in around 60 percent of breaches, with social engineering actions appearing in about 24 percent and stolen credentials the top initial access vector. People, not firewalls, are the front line.
This is not because people are foolish. It is because attackers are skilled at exploiting normal human behavior, trust, helpfulness, urgency, habit, which no amount of technology fully removes. The umbrella term for manipulating people into compromising security is social engineering, and understanding its techniques is the most practical security skill most people can learn, because it is the attack they are personally most likely to face.

