Spearphishing drove 85% of cyber insurance losses in H1 2026
AI-enhanced social engineering replaced ransomware as the dominant attack vector, according to Resilience's latest claims data.
Spearphishing surges as primary loss driver
Spearphishing campaigns accounted for more than 85% of cyber insurance losses in the first half of 2026, according to a recent report from cyber insurance firm Resilience. The figure represents a dramatic escalation from just 18% in 2024, signaling a fundamental shift in how successful attacks begin.
While ransomware extortion still caused roughly three-quarters of business losses by dollar value during the period, these incidents represented less than 6% of total claims submitted. The disparity underscores how "disproportionately costly" ransomware remains compared to its frequency, Resilience noted.
The insurer attributed the surge in spearphishing effectiveness to artificial intelligence, which has made social engineering attacks significantly more convincing. "So far, AI's clearest effect on the portfolio isn't a new attack type," Resilience stated. "It has made the oldest one, social engineering, more convincing."
Why it matters
The data reveals that AI's immediate cybersecurity impact isn't creating novel attack methods but rather supercharging existing ones. Organizations investing heavily in defenses against hypothetical AI-native threats may be overlooking the more pressing reality: AI is making traditional phishing dramatically more effective at scale. This shift demands renewed focus on employee training and verification protocols rather than just technical controls.
Technical vulnerabilities persist
Beyond social engineering, organizations continue struggling with basic security hygiene. Known vulnerability exploitation accounted for 7% of all losses in the first half of 2026. While this represents an improvement from 25% of total losses in the second half of 2024, it demonstrates that companies still fail to patch widely publicized flaws that attackers have exploited for months or years.
Supply chain compromises, by contrast, caused just 2.3% of losses during the period—a sharp decline from 34% in the first half of 2025. Resilience pointed to the Canvas platform breach as an example of ongoing supply chain incidents but noted that recent compromises have proven less costly than earlier crises like the Change Healthcare breach.
Containment separates outcomes
Resilience emphasized that no organization can completely prevent attacks, but preparation significantly affects outcomes. "What separates outcomes is containment: how fast an event is detected and how much loss gets limited once it's underway," the company's analysts wrote.
The report's findings reinforce the importance of employee training programs that address AI-enhanced phishing techniques, along with disciplined adherence to security protocols including regular backups and rapid incident response procedures.
Notably, despite widespread concern about AI-driven attacks, Resilience reported that no purely AI-generated attack campaigns have resulted in insurance claims to date. The technology's primary impact remains its ability to enhance traditional attack methods rather than create entirely new threat categories.
The details were first reported by Cybersecurity Dive.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
