SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
AI boosts phishing losses in Resilience cyber claims

AI boosts phishing losses in Resilience cyber claims

Fri, 31st Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Human error drove most cyber insurance losses in the first half of 2026, according to Resilience. More than 85% of incurred losses in its portfolio stemmed from attacks involving phishing, social engineering or transfer fraud.

Its claims analysis found no incurred losses from what it described as AI-specific attack vectors, such as prompt injection, model exploitation or agentic AI misuse, during the period.

Instead, the data pointed to familiar attack methods made more effective by artificial intelligence tools. The share of incurred losses tied to attacks exploiting human error rose sharply to 85.3% in the first half of 2026 from 17.7% in the same period of 2024.

The findings add to a wider debate in the cybersecurity industry over whether AI is creating entirely new sources of insured loss or mainly strengthening existing techniques such as phishing and impersonation.

Resilience based the analysis on cyber insurance claims across its own portfolio over the past six months, alongside intelligence from its Risk Operations Centre. The figures reflect incidents that translated into direct financial losses, rather than attacks that were merely observed.

One of the clearest patterns involved ransomware. Extortion driven by ransomware accounted for 73% of incurred losses, making it the largest single cause of financial damage across the portfolio.

That came despite ransomware representing a small share of overall claims volume. It made up 5.8% of total claims, suggesting such incidents remained comparatively infrequent but far more costly when they occurred.

Resilience linked the lower frequency in part to greater use of immutable backups. Adoption among insured organisations rose to 85.2% from 79.9% a year earlier, which may be helping companies recover more effectively from ransomware incidents.

Claims picture

The company also reported a steep fall in vendor-related losses. These accounted for 2.3% of incurred losses in the first half of 2026, down from 33.5% in the first half of 2025.

That shift suggests third-party failures remained an operational risk but did not always lead to the same level of insured financial impact seen in some earlier high-profile supply chain and service provider incidents.

Vishaal "V8" Hariprasad, Co-Founder and Chief Executive Officer of Resilience, said the figures show where cyber risk is resulting in actual financial loss.

"AI is rapidly reshaping cyber risk, as recent headlines have shown. But insurance claims help us understand where that risk is actually translating into financial loss," Hariprasad said.

"Our data shows that AI is already contributing to financial losses by making familiar attack methods, like phishing and social engineering, more effective than ever. While we haven't yet seen AI-native attacks emerge as their own driver of insured loss, that could of course change at any moment. As such, the organizations best prepared for the future will be the ones that treat AI as part of a broader, risk-first strategy-strengthening the controls that limit the impact of today's attacks while preparing for tomorrow's," he said.

For insurers and their clients, the figures suggest the immediate issue is less about speculative autonomous attacks and more about the financial consequences of staff mistakes, deceptive communications and weak controls around payments and access.

Resilience said this has implications for how companies manage cyber risk. Rather than relying mainly on staff awareness training, organisations should strengthen practical controls that limit the damage when an employee is deceived.

These include more realistic phishing simulations, layered verification for high-risk transactions, closer monitoring of compromised credentials and stronger third-party risk management. Such steps become more important as AI increases the speed and scale of attacks that target existing weaknesses.

Human factor

Judson Dressler, Head of Resilience's Risk Operations Centre, said the focus should be on limiting losses once an incident begins.

"You can't train your way out of every AI-generated phishing email or rely on human judgement when attacks themselves become entirely AI-generated," Dressler said.

"Whether an attack starts with an AI agent or a regular person, what matters most is how quickly an incident is contained once it's underway. The organizations that avoid the worst financial outcomes detect threats quickly, build layered controls, verify high-risk transactions, and limit the fallout of attacks before they can become material losses," he said.

The claims data offers a view of cyber risk through the lens of insured losses rather than technical incident counts. On that measure, the biggest costs still come from long-established attack routes, even as AI changes how efficiently criminals can use them.