The Process Is the Insider
In this series, we examine recent insider incidents and identify the patterns that matter for insider risk, security, fraud, legal, HR, finance, and business leaders.
The goal is not to retell every case. The goal is to understand what these incidents are telling us and what organizations should do differently.
“The message from June is hard to ignore: the insider threat is not always a person hiding in the shadows. Sometimes it is a business process that was trusted for too long.”
Trust is the foundational layer of operations, but June shows exactly how normal access is repurposed across diverse avenues:
A benefits specialist can create and approve fraudulent claims. A bank employee can turn customer information into a fraud pipeline. A branch manager can manipulate cash audits. A finance lead can alter reports. A contractor can smuggle contraband. An IT employee can leave with credentials and return after termination. A chatbot can be given authority to reset accounts. A vendor integration can quietly become the path into customer data. A manager can control overtime, schedules, approvals, and fear.
That is the real lesson from June. Insider risk is not just about bad people. It is about trusted people operating inside weak systems.
The June 2026 Insider Threat Incidents Report reinforces the same pattern we saw in April and May: insider risk is much broader than data theft, and it is now deeply embedded across fraud, procurement, identity, third-party access, workplace violence, AI, technical privilege, and financial authority.
The uncomfortable question for leaders is not simply, "Do we have malicious insiders?" The better question is: Where have we designed the organization so one trusted person can cause too much damage? That is where the real exposure lives.
!June's Big Theme: Trusted Processes Are Being Exploited
Most organizations think of insider risk as an event: a download, a login, a transfer, a termination, a suspicious email, or a policy violation. But June's incidents point to something more structural. The problem is not only what the insider did. The problem is what the organization allowed the insider to do without enough friction, oversight, detection, or independent review.
A former Social Security Administration employee was convicted after using her position to submit and approve false claims tied to deceased individuals, directing more than $1.8 million in benefits to herself over a 12-year period.
This was not a "hack" in the traditional sense. It was process abuse. She knew the system, had authority inside the system, and allegedly used the system's own workflows against it.
That should get every insider risk team's attention. The lesson is not just "watch employees." The lesson is: watch the process.
- • Who can create the transaction vs. who can approve it?
- • Who has the authority to edit or override the system record?
- • Who can override controls or hide changes without triggering reviews?
- • Who is operating for months or years without an independent review?
Six Critical Threat Patterns Identified in June 2026
Financial Authority Is Still Under-Managed Insider Risk
June was packed with financial abuse cases: embezzlement, payroll manipulation, procurement fraud, bribes, kickbacks, PPP fraud, stolen benefits, false invoices, bank theft, and customer-account exploitation. Financial authority is privileged access.
The problem is that many organizations still do not treat it that way. They apply strong governance to domain administrators and cloud engineers, but far less rigor to the people who can create vendors, approve invoices, modify payroll, handle cash, redirect payments, manage donations, approve overtime, alter financial reports, or move customer funds. That is a blind spot.
- • Can one person create AND approve a payment?
- • Can one person modify vendor banking details?
- • Can one person approve overtime and benefit from it?
- • Can one person reconcile the transactions they initiated?
Fraud often survives because it looks like normal work. That is why insider risk programs need to expand beyond file movement and endpoint alerts. The money trail is an insider risk signal.
Access Has a Resale Value
May's theme was the insider marketplace. June continued that story. Bank employees allegedly helped fraudsters by providing customer information, opening or unblocking accounts, issuing debit cards, falsifying records, or accepting bribes.
Many insider risk programs are still built around the lone insider. That model is too narrow. Today, an insider may be part of a larger ecosystem. They may be recruited, bribed, coerced, manipulated, or used by an external criminal group because they have exactly what the outsider needs: credentials, customer information, shipment data, internal workflows, payment authority, system knowledge, badges, or reset capabilities.
Ask this central question: What access inside our organization would someone else pay for? This moves your team away from generic monitoring and toward proactive exposure management:
- Who has marketable access that could be sold, rented, or traded?
- Which employees are visible targets for external recruitment or coercion?
- Which support roles can reset accounts, view customer data, or alter records?
AI Is Creating a New Class of Trusted Intermediary
One of the more important June items involved allegations that attackers used Meta's AI support chatbot to take over high-profile Instagram accounts by asking the bot to change the email address associated with target accounts.
When AI is given authority inside a workflow, it becomes part of the insider risk surface. As organizations move AI into customer support, help desk workflows, HR support, finance operations, and identity management, they create speed, but they also create authority. And authority without governance is exposure.
AI governance cannot stay at the policy level. It must reach the workflow level:
- Which AI tools have access to sensitive data repositories?
- Which AI systems can take action instead of merely providing answers?
- Can AI-driven workflows alter account recovery or password settings?
- Does a high-risk function allow AI to recommend, but not execute?
Third-Party Integrations Are Insider Access by Another Name
The LastPass and Klue incident is a useful reminder that third-party tools do not need to be "inside" your company to create insider-like exposure.
LastPass was notified on June 12 of an incident involving Klue, a third-party platform integrated with Salesforce and Gong. An unauthorized actor obtained OAuth tokens held by Klue and used those credentials to access LastPass customer data in Salesforce. The organization trusted the integration. That trust created access, and access created risk.
The insider risk team should not limit its population to employees. It must understand which vendors, integrations, tokens, service accounts, and connected applications have meaningful access to sensitive environments.
The question is not only "Who has access?" It is also: What has access?Offboarding Is Still a High-Risk Moment
June included a familiar but important technical sabotage case. A former school IT employee was sentenced after sabotaging his former employer's systems over a year and a half.
He had been terminated from the IT department of Saydel Community School District and later used downloaded usernames and passwords to access school systems, disrupt operations, revoke access, delete accounts, and cause outages.
When an employee with technical access is terminated or resigns under conflict, the organization cannot treat access removal as an administrative checklist. It is a risk event. Controls must include:
- Pre-termination access review for high-risk roles.
- Immediate credential, session token, and VPN revocation.
- Review of shared administrator credentials, scripts, and API keys.
- Monitoring for post-employment access attempts.
Workplace Violence Belongs in the Insider Risk Conversation
June's report also included workplace violence and violence-related incidents, including the murder of a coworker at an Amazon fulfillment center and multiple government and military-related violence cases.
Some insider risk teams still treat workplace violence as separate from insider threat. That is a mistake. The harm may be physical rather than digital, but the underlying risk pathway often overlaps with other insider concerns: grievance, conflict, stress, fixation, domestic issues brought into the workplace, threatening behavior, facility access, knowledge of routines, familiarity with security processes, and escalation after discipline, termination, relationship conflict, or perceived humiliation.
The same person who might sabotage a system could damage property. The same grievance that might lead to data theft could lead to violence. The same ignored warning signs that appear "HR-related" may later become a security crisis.
Practical Use Cases & Applied Scenarios
The Finance Employee Who Can Create and Conceal Payments
Scenario
A mid-sized company has a senior finance employee who can create vendors, update vendor banking details, approve invoices under a certain threshold, and reconcile monthly payment reports.
Over time, several small payments are made to a new vendor sounding similar to a legitimate supplier. The employee updates records so payments do not appear unusual during reconciliation. Nothing triggers a cyber alert—no files were downloaded, no malware was used. But the company is being stolen from.
What June Teaches
This is insider risk. The employee is using trusted authority, process knowledge, and weak separation of duties to convert business process into personal gain.
Start by identifying finance and procurement roles with concentrated authority.
- Build a simple exposure review: Which users can create AND approve vendor payments?
- Which vendor banking changes occurred close to payment runs?
- Which payments fall just below the executive review thresholds?
The Departing IT Employee With Dormant Power
Scenario
An IT administrator is terminated after performance issues. The organization disables the employee's main user account but misses several access paths: a shared admin password, an old VPN credential, a service account, an API token, and documentation containing credentials.
Weeks later, systems experience unexplained changes: locked accounts, missing logs, compromised social accounts, and altered cloud configurations. Former insider is using retained access.
What June Teaches
Privileged access must be treated as a living risk condition. Termination does not remove risk unless the organization understands every access path the person had, not just their primary account.
Create an offboarding exposure checklist for high-risk technical roles:
- Inventory identity, shared admin, service, API, and SSH accounts.
- Check password vaults, domain registrars, and backup systems.
- Validate after departure: Were there unusual failed login attempts?
What Insider Risk Teams Should Do Now
- 1Expand the Insider Risk PopulationEmployees and contractors matter, but so do service accounts, SaaS integrations, AI agents, OAuth tokens, and shared accounts. If something has trusted access, it belongs in the program.
- 2Map High-Value Process AuthorityDo not only map sensitive data repositories. Map business processes where trust can be monetized: payments, payroll, procurement, benefits, refunds, customer accounts, and account recovery.
- 3Treat Financial Authority Like Privileged AccessApply the same seriousness to payment authority that you apply to domain admin rights. A person who can move money can create enterprise-level damage.
- 4Operationalize AI GovernanceDo not stop at "approved tools." Identify where AI can take action, influence decisions, access records, or become part of account recovery workflows.
- 5Connect Insider Risk and Third-Party RiskA vendor token, SaaS integration, or managed service provider account may create the same practical exposure as an internal privileged user. Inventory and govern them.
- 6Redesign Offboarding for Privileged RolesHigh-risk exits require pre-exit access review, credential rotation, token revocation, logging review, and post-exit monitoring.
- 7Bring Workplace Violence Into the Program ModelCyber, HR, legal, physical security, employee relations, and threat management should have a shared process for assessing escalation around grievances, domestic spillover, and termination.
June's incidents tell a simple story: the insider threat is not just the person. It is the access, the authority, the workflow, the approval chain, the vendor integration, the AI support function, the shared account, the offboarding gap, and the process nobody has questioned in years.
Organizations often ask, "How do we find the bad insider?" That is the wrong starting point. The better starting point is: Where have we created too much trust without enough control?
Because most insider incidents do not begin with a dramatic betrayal. They begin with normal access, inside a normal process, used in a way the organization failed to anticipate. Trust is necessary. But unmanaged trust is exposure.