One in five workers share passwords externally
One in five employees have shared work login details or passwords with someone outside their organisation, according to new research by Gallagher. The findings raise concerns that everyday shortcuts in the workplace could be making businesses more vulnerable to cyber-attacks.
A government survey at the beginning of the year found that 43% of UK businesses experienced a cyber-attack in 2025. But while headline-grabbing hacking groups and cyber criminals have inflicted major damage on large corporations with the latest technology, the study also found that human error contributed to 95% of all breaches.
Now, a shocking paper from Gallagher has shown just how basic some of these errors may be. One of the things which might have been taken for granted as common sense, is that most people would know it was a bad idea to share work passwords with people outside of the company. But in actual fact, one-in-five respondents to the firm’s UK survey said they had done precisely that – including sharing passwords with family or friends to allow them to use devices, or sharing logins for social media accounts, client portals, subscriptions and admin systems with freelancers, suppliers, agencies and IT providers.
Meanwhile, a further 26% said they have moved company data onto personal devices or storage accounts. And presuming they do not have the same level of cybersecurity that their employers do, this could also hand cyber criminals the kind of access point they need to disrupt operations or expose sensitive data.
Andrew Marvin, client service director at Gallagher, said, “Most employees are not intentionally trying to put their organisation at risk, but everyday shortcuts can create exactly the kinds of openings cyber criminals look for. Sharing passwords, reusing login details or moving company data onto personal devices may feel harmless, but these behaviours can quickly undermine even robust cyber security systems.
At the same time, 45% of those polled told Gallagher that they always or often use the same or similar passwords across personal and work accounts, creating a risk that credentials compromised through phishing or data breaches could be used to exploit workplace systems. Recent Gallagher and CEBR analysis found this fallout can be substantial, with cyber-attacks costing large UK businesses an estimated £11.7 billion in 2025, including £5.4 billion in operational disruption and £3.7 billion in litigation costs.
Convenience outweighs security considerations
These behaviours may appear minor in isolation, but they can create the access points cyber criminals need to compromise systems, disrupt operations and expose businesses to significant financial and reputational fallout.
The litigation risk is heightened for businesses when the cause of an incident can be linked back to preventable employee actions or weak internal controls. With human error reported to have contributed to 95% of data breaches in 2024, Gallagher’s findings suggest behaviours such as sharing passwords externally, reusing login details or moving company data onto personal devices could leave businesses more exposed if a cyber incident leads to legal action.
The research also points to a wider pattern of employees prioritising convenience over these safeguards. A further 25% workers regularly delay installing security updates on work devices, even though software patches are often designed to fix known vulnerabilities that cyber criminals may already be exploiting. Meanwhile, a similar number said they viewed the use of cloud services or AI tools involving company data as low risk, despite growing concerns around data leakage, unauthorised access and the handling of confidential business information.
Marvin added, “The challenge for businesses is that cyber risk is no longer just about defending against sophisticated attacks. It is also about making sure employees understand how routine decisions can expose the organisation to disruption, data loss and reputational damage. Training, clear policies and strong controls all have an important role to play. But businesses should also understand what happens if those controls fail, including how their insurance would respond if human error contributed to a cyber incident.”

