How AI Is rewriting the anatomy of cyber loss

A wave of newly released 2026 claims data from cyber insurers and digital forensics and incident response (DFIR) firms reflects a shared theme: artificial intelligence has not introduced a new category of cyberattack so much as it has made the oldest one – the fraudulent emails or phone calls designed to trick an employee – dramatically more effective. This shift has real consequences for organizations as AI generated messages become harder to distinguish from legitimate communications.  The controls, training, and contractual protections that once provided reasonable assurance against fraud losses may no longer be sufficient as they currently exist.

What the 2026 data shows

Cyber Insurer Resilience’s 2026 Midyear Cyber Risk Report, drawn from claims activity across its portfolio through the first half of the year, found that impersonation-driven spear phishing accounted for more than 85.3% of the losses the insurer handled, up from 17.7% at the midyear point in 2024. Ransomware, by contrast, drove roughly 3/4 of dollar losses for the insurer, but represented less than 6% of claimed incidents. Resilience said this gap reflected how disproportionately costly a successful ransomware event remains even if it becomes a smaller share of overall claims activity, but that “AI’s clearest effect on the portfolio isn’t a new attack type,” rather it has made social engineering more convincing. In the insurer’s view, generative tools have sharpened the oldest tactic in the book, making social engineering harder for employees to catch and outcomes increasingly dependent on how quickly a compromise is detected and contained once it begins.  Other insurers are seeing a similar pattern. Coalition’s 2026 Cyber Claims Report found that business email compromise and fund transfer fraud together accounted for 58% of all claims in 2025, with 71% of funds transfer fraud claims in 2025 tracing directly to social engineering and 52% of those claims originating in a business e-mail compromise. At-Bay’s 2026 InsurSec Report adds a useful nuance rather than a contradiction: across its own claims data, email did not produce a single ransomware claim in 2025, as attackers increasingly gained initial access to encrypt systems through compromised VPN appliances rather than inboxes. Read together, the three reports suggest that email borne social engineering is now the dominant driver of fraud and business email compromise losses specifically, while ransomware actors are pursuing a parallel, more infrastructure-driven path to the same networks.

DFIR firms providing services to victims for these same claims describe the same shift from the technical side. MOXFIVE’s January 2026 monthly threat report identified phishing, social engineering, and related techniques among the most frequently observed initial access points behind ransomware deployment, and separately examined how ClickFix (a technique that manipulates users into executing malicious commands disguised as legitimate system prompts) is increasingly being used to gain the initial foothold. Analyzing additional insights from the DFIR industry, Arete’s Crimeware Report reflects the same trajectory. Specifically, in its Q1 2026 Crimeware Report, Arete’s Chief Data Officer noted that threat actors are increasingly using AI tools “to enhance data analysis, social engineering, and ransom strategies.” These tools allow threat actors to adapt and refine social engineering tactics in an ongoing shift toward identity-driven compromise techniques over traditional credential theft.

Why the shift matters

Generative AI has narrowed the gap that used to give defenders an edge. The poorly worded email, the mismatched tone, the obviously synthetic voice on the phone were teachable clues of attempts at fraud. Attackers can now produce fluent, context-aware messages that mimic a specific executive style, reference real transactions, and arrive at a moment timed to organizational routine, such as month-end closing or during a pending acquisition. Resilience’s own data suggests the technical side of the equation is, if anything, improving in parallel. Losses tied to known, unpatched vulnerabilities fell to 7% in the first half of 2026, down from 25% in the second half of 2024, and losses tied to vendor or supply chain compromise dropped from roughly 1/3 of the total in the first half of 2025 to just over 2% one year later. The human layer however, and increasingly the remote access layer that threat actors favor, have not kept pace with those gains.

Practical steps for organizations

Organizations should treat any request to change payment or wire instructions as a sign that independent, out-of-band verification is required regardless of how legitimate it appears, since a well-crafted AI-generated email or voice message may be indistinguishable from a genuine one on its face. Training built around spotting poor grammar or generic phrasing is no longer sufficient and should be updated to emphasize verification procedures over detection by feel, particularly given how quickly techniques such as ClickFix and AI-assisted impersonation are involving. Finance, legal, and security teams should regularly revisit incident response plans and cyber insured policy language together, since coverage for social engineering losses, notification timelines, and cooperation requirements with their insurer can vary meaningfully by carrier, and gaps are often discovered only after a loss has already occurred.

Because so many of these losses begin with a routine-looking email or a call rather than a detectable intrusion, organizations often do not recognize they are inside an active incident until the harm has been done. Engaging incident response and data privacy counsel proactively and establishing that relationship before an incident occurs allows an organization to move quickly once a suspicious transfer or compromise is identified, including coordinating recall requests with financial institutions, preserving privilege over the resulting investigation, and managing communications with carriers, forensic vendors, and law enforcement in a way that protects the organization’s position under its policy. Every insurer’s data points to another important conclusion: organizations that report and act within days recover meaningfully more than those that wait.

The data from insurer reports and DFIR firms point in the same direction even where their specific findings diverge: the return on investment for threat actors using AI enhanced social engineering and infrastructure exploitation alike is high, and that trend shows no sign of reversing. Organizations that pair updated training and verification protocols, provide attention to remote access infrastructure, and have a clear-eyed review of their incident response and insurance posture before an incident are generally better positioned to limit both the financial and legal fallout when an attack succeeds.

To learn more about proactive pre-incident risk management, contact a member of McDonald Hopkins’ national data privacy and cybersecurity team.

Jump to Page

McDonald Hopkins uses cookies on our website to enhance user experience and analyze website traffic. Third parties may also use cookies in connection with our website for social media, advertising and analytics and other purposes. By continuing to browse our website, you agree to our use of cookies as detailed in our updated Privacy Policy and our Terms of Use.