Your people are your greatest asset—and, when it comes to security, often your greatest risk. As AI makes attacks more convincing than ever, a single mistake can expose sensitive data. This blog post explains why data leaks happen, the attacks to watch for, and the training and best practices that help your organization prevent them.
So, what qualifies as a data leak? According to CyberDefenders, it’s the unintentional exposure of data—information left accessible through misconfiguration, errors, or negligence. The key word is “unintentional”: a leak is usually accidental, caused by a single mistake or a lack of security awareness.
Imagine a day in the life of an engineer supporting a Centers for Medicare & Medicaid Services (CMS) environment. You’re monitoring alerts, responding to tickets, and coordinating across teams inside one of the nation’s most sensitive ecosystems—one that supports 147M+ beneficiaries, processes $1.5T+ per year, and exchange billions of patient records. In the middle of an incident, an email arrives that appears to be from a trusted partner asking for quick access or a configuration change. It feels urgent, it looks legitimate — and it’s exactly the type of AI-generated phishing attempt attackers use to target engineers across the industry. Even highly trained professionals can be targeted, and AI makes it increasingly difficult to distinguish what’s real. Security is everyone’s responsibility, and strong awareness and training is one of the most cost-effective ways to reduce that risk.
Why Humans Are the Weakest Link
An analysis by TrendMicro found that 2,130 AI vulnerabilities were disclosed in 2025 alone – a 34.6% increase over 2024 – underscoring the rapid acceleration of AI-targeted attacks. At the same time, an IBM study found that 63% of organizations lacked AI governance policies to manage AI usage or prevent the proliferation of shadow AI, leaving many vulnerable to both external threats and internal misuse. These risks were highlighted by CMS’ 2025 National Health Care Fraud Takedown, which stopped schemes—many involving AI-generated attacks—totaling $14.6B in intended loss.
Internal misuse is often the root cause of data leaks. Many of us have faced phishing or social-engineering tactics, yet it is easy to overlook the risk of uploading sensitive information to public tools or leaving systems misconfigured with over-permissive policies.
Without consistent training and awareness, a single misstep – one click, one upload, one response – can expose internal information, expand the attack surface, and, in the case of PII/PHI, lead to identity theft or fraud. Phishing and social engineering remain the most common attacks because they target human behavior—relying on urgency, pressure, and distraction to influence decisions. Reducing their impact starts with understanding the common root causes.
Common Causes
Most data leaks come down to human error or negligence. Common examples include:
• Sending data to the wrong recipient
• Using the wrong AI tool for a sensitive task
• Uploading sensitive information to public environments without verifying
• Committing secrets to a public code repository
Many attacks also use social engineering, or psychological manipulation, often relying on urgency or fear. AI has amplified this problem, making messages more convincing and harder to distinguish from legitimate communication. The most common attacks include:
• Phishing – fraudulent emails disguised as reputable sources to steal credentials or exploit access.
• Smishing – phishing conducted via text messages.
• Vishing – phishing conducted via phone calls.
• AI-Generated Phishing – one of the latest and most effective forms, where AI crafts highly believable messages.
• Spear Phishing – targeted phishing aimed at a specific individual to gain access to sensitive data.
• Whaling – targeted phishing aimed at senior executives to obtain high-value information.
• Pretexting – attackers create a fabricated scenario to manipulate someone into revealing sensitive data.
• Baiting – attackers use malicious lures such as free downloads or malware-infected USB drives.
• Quid Pro Quo – attackers offer a service in exchange for credentials or system access.
• Tailgating – an unauthorized person physically follows someone into a restricted area.
• Scams – trust is exploited to gain information or access.
• Impersonation – attackers pose as legitimate authorities or trusted contacts.
Best Practices for Awareness & Training
Organizations can reduce the risk of data leaks by ensuring employees have the knowledge and tools to safeguard sensitive information. We know the warning signs, but in the heat of the moment even well-trained individuals can be vulnerable. Staying vigilant matters more than ever as AI blurs the line between legitimate and malicious communication.
Federal employees and contractors within CMS Hybrid Cloud — including our CMS clients — are required to comply with the CMS Acceptable Risk Safeguards (ARS), which map to NIST Special Publication (SP) 800-53 controls. These provide the foundational security and privacy controls organizations use to manage cyber risk, so staying aligned with the latest applicable version is essential. Five best practices from the CMS ARS Awareness and Training (AT) control family reinforce that security is everyone’s responsibility:
- Role-Based Training – designed for roles with significant security and privacy responsibilities, completed upon hire, annually, or when responsibilities change. Employees should be well-versed in security practices, incident response, and proper handling of PII/PHI. As CMS contractors, we all complete similar training before gaining and maintaining access to the cloud systems we support.
- Phishing Campaigns – part of broader cybersecurity awareness training, these test and educate employees on social engineering tactics and encourage reporting suspicious messages. Simulated exercises significantly reduce the likelihood of falling for real attacks. The CMS Hybrid Cloud SOC also presents security forums and promotes campaigns to keep teams ahead of emerging threats.
- Social Engineering Awareness – helps employees recognize tactics such as phishing and vishing, along with red flags like urgent or fear-based messages, suspicious sender addresses, requests for passwords or MFA codes, “too good to be true” offers, poor grammar, and unnatural tone shifts common in AI-generated messages.
- Insider Threat Awareness – helps employees identify and report potential insider threats—unusual behavior, attempts to access unauthorized information, patterns of unexplained wealth or debt, and expressions of dissatisfaction.
- Anomalous System Behavior – helps employees detect and respond to unusual activity such as multiple failed logins, logins from unexpected locations, emails from unknown senders, urgent requests for sensitive information, and spikes in unauthorized configuration changes.
Governing AI use is also a key best practice as AI expands across our domain. It ensures employees use only approved models, avoid uploading sensitive information, and follow prompt-engineering best practices. HHS’ new “Secure Use of AI Tools at HHS” course helps standardize AI use, but AI-generated outputs must always be verified and kept under human oversight. Our approach follows the “Guidance for Responsible Use of Artificial Intelligence at CMS” and mirrors Jonathan Shea’s Samtek blog, “Adopt AI Responsibly with Proactive AI Security.”
Samtek personnel also build the infrastructure underpinning CMS data, so we rely heavily on DevSecOps best practices. Key safeguards we adhere to include:
• Strict access controls for authorized access
• Data loss prevention to tag potentially sensitive information
• Data minimization—masking or redacting sensitive variables
• Centralized logging
• Scanning before anything is committed to a repository
• No production data in lower environments
• Automated key rotation
• Enforced allow-lists
• Data leak checks in the CI/CD pipeline
Continuing the Security Awareness Journey
Lack of security awareness and human error remain two of the most common causes of data leaks. The first step toward reducing that risk is well-trained employees who understand how attackers think, recognize red flags, and consistently follow best practices. But compliance doesn’t end with completing required modules.
At Samtek, we encourage employees to practice security awareness daily, stay informed about emerging threats, and share validated insights—reinforcing a culture where security is second nature.
Even with strong training, mistakes can happen. When they do, the priority is understanding the impact and where additional training or knowledge-sharing is needed so issues don’t repeat. This ties back to the themes we emphasize across our work: look closely at the data in front of you, pause before reacting to urgency, and rely on critical thinking rather than pressure. Slowing down, even briefly, can be the difference between spotting an AI-generated phishing attempt and acting on it.
As AI evolves, so must AI governance. As attacks grow more sophisticated against both beneficiaries and the engineers who support federal systems, users must be educated on responsible AI use. That calls for more intentional awareness in the moments that matter most. Samtek remains committed to staying ahead of these trends and helping our federal partners do the same.
References
• 10 Types of Social Engineering Attacks | CrowdStrike
• What is Social Engineering? | IBM (Phishing, Spear Phishing, Whaling)
• NIST SP 800-53 Security and Privacy Controls
• CMS ARS – Awareness and Training (AT)
• TrendAI: Fault Lines in the AI Ecosystem
• IBM: Cost of a Data Breach Report 2025
• cyberdefenders.org – Data Leaks vs. Data Breaches
• security.cms.gov – CMS Acceptable Risk Safeguards (ARS)
• security.cms.gov – Guidance for Responsible Use of AI at CMS
• security.cms.gov – Federal DevSecOps Guidance
• Adopt AI Responsibly with Proactive AI Security – Samtek
• Responsible AI in the Cloud: What Cloud Developers Need to Get Right – Samtek

