AI makes costly spearphishing attacks easier, cyber insurer says
The latest report from cyber insurer Resilience indicates that in the first half of 2026, losses from ransomware extortion accounted for about three-quarters of corporate losses, yet related incidents made up less than 6% of claims, highlighting their high-cost nature. Meanwhile, AI has not directly triggered new types of attacks but has made traditional social engineering methods like spear phishing more deceptive—over 85% of losses originated from such attacks, far higher than the 18% in 2024. The report also shows that exploitation of known vulnerabilities remains the primary technical cause of losses, while losses from supply chain attacks have dropped significantly.

Dive Brief:
- Ransomware extortion caused roughly three-quarters of business losses in the first half of 2026, the cyber insurance firm Resilience said in a recent report.
- At the same time, ransomware accounted for less than 6% of the incidents for which Resilience customers submitted claims, which the company said highlighted how “disproportionately costly” they are.
- Other data in the report highlight the importance of proper employee training and vigilant adherence to protocols such as regular backups.
Dive Insight:
Despite AI-related attacks dominating many organizations’ fears, no such attacks have generated claims yet, Resilience said. Instead, costly attacks have begun in familiar ways. More than 85% of losses that the insurer dealt with began with spearphishing. Remarkably, that figure was only 18% in 2024.
“So far, AI's clearest effect on the portfolio isn’t a new attack type,” Resilience said. “It has made the oldest one, social engineering, more convincing.”
Companies also continue to struggle with patching vulnerabilities, including widely known flaws that hackers have been exploiting for months or even years. The largest technical cause of losses was the exploitation of known vulnerabilities, which accounted for 7% of all losses. In the second half of 2024, those flaws led to 25% of total losses.
No company can completely seal itself off from attacks, Resilience said, but organizations can prepare in ways that make attacks less damaging and more easily withstood.
“What separates outcomes is containment: how fast an event is detected and how much loss gets limited once it's underway,” analysts wrote.
Companies were far more likely to experience losses because of direct intrusions than because of supply-chain compromises in the first half of 2026. Just 2.3% of losses resulted from vendor breaches. In the first half of 2025, that share was 34%.
Major supply-chain incidents still occur — Resilience pointed to the Canvas platform hack — but the firm said that recent ones have been less costly than earlier crises such as the Change Healthcare breach.