Impersonation campaigns led to more than 85% of the losses that Resilience dealt with in the first half of the year, a dramatic increase from two years ago.
Dive Brief:
- Ransomware extortion caused roughly three-quarters of business losses in the first half of 2026, the cyber insurance firmResilience said in a recent report.
- At the same time, ransomware accounted for less than 6% of the incidents for which Resilience customers submitted claims, which the company said highlighted how “disproportionately costly” they are.
- Other data in the report highlight the importance of proper employee training and vigilant adherence to protocols such as regular backups.
Dive Insight:
DespiteAI-related attacksdominating many organizations’ fears, no such attacks have generated claims yet, Resilience said. Instead, costly attacks have begun in familiar ways. More than 85% of losses that the insurer dealt with began with spearphishing. Remarkably, that figure was only 18% in 2024.
“So far, AI’s clearest effect on the portfolio isn’t a new attack type,” Resilience said. “It has made the oldest one, social engineering, more convincing.”
Companies also continue to struggle with patching vulnerabilities, including widely known flaws that hackers have been exploiting for months or even years. The largest technical cause of losses was the exploitation of known vulnerabilities, which accounted for 7% of all losses. In the second half of 2024, those flaws led to 25% of total losses.
No company can completely seal itself off from attacks, Resilience said, but organizations can prepare in ways that make attacks less damaging and more easily withstood.
“What separates outcomes is containment: how fast an event is detected and how much loss gets limited once it’s underway,” analysts wrote.
Companies were far more likely to experience losses because of direct intrusions than because of supply-chain compromises in the first half of 2026. Just 2.3% of losses resulted from vendor breaches. In the first half of 2025, that share was 34%.
Major supply-chain incidents still occur — Resilience pointed tothe Canvas platform hack— but the firm said that recent ones have been less costly than earlier crises such asthe Change Healthcare breach.
Filed Under:Breaches,Cyberattacks,Threats
