Reinsurance News

Resilience analysis shows AI is strengthening existing cyber attack methods

3rd August 2026 - Author: Taylor Mixides -

Share

Resilience, a cyber risk solutions company helping organisations identify, manage and reduce cyber threats, has released new analysis indicating that artificial intelligence is currently being used primarily to enhance established attack techniques rather than enable widespread new categories of autonomous cyber attacks.

resilience-logoThe findings, published in Resilience’s 2026 Midyear Cyber Risk Report, are based on insurance claims data from the company’s portfolio and intelligence gathered by its Risk Operations Center (ROC).

Resilience reported that it recorded no incurred losses linked to AI-specific attack methods, including prompt injection, model exploitation, or agentic AI misuse, during the first six months of 2026.

Instead, Resilience found that traditional cyber risks continued to account for the majority of financial losses. During the same period, 85.3% of incurred losses across Resilience’s portfolio were connected to incidents involving human error, with phishing, social engineering, or transfer fraud identified as the initial point of compromise.

Resilience said this represents a notable change from the first half of 2024, when these types of attacks accounted for 17.7% of incurred losses. The company’s analysis suggests that AI is currently increasing the effectiveness and scale of existing attack methods rather than creating a separate category of AI-driven insured losses.

Resilience’s report found that phishing and social engineering were increasingly common routes used by attackers to gain access. The company also reported that ransomware-related extortion remained the largest contributor to financial losses, accounting for 73% of incurred losses. Resilience said the figures indicate that attackers are using multiple approaches to achieve the same objective: causing significant disruption or obtaining financial payments.

Despite representing the majority of incurred losses, ransomware accounted for only 5.8% of all claims recorded by Resilience. The company said this demonstrates that ransomware incidents are less frequent but can have a substantial financial impact when successful.

Resilience also highlighted that the use of immutable backups increased from 79.9% to 85.2% year-on-year, which may be contributing to improved recovery capabilities and fewer ransomware-related claims.

Resilience’s review of other causes of loss found that vendor-related incidents accounted for 2.3% of incurred losses, down from 33.5% during the first half of 2025. While the company noted that third-party disruptions remain a significant operational concern, its claims data suggests these events are not consistently resulting in the same scale of insured financial impact associated with major third-party breaches in previous years.

As AI continues to improve the efficiency and sophistication of established attack techniques, Resilience said organisations should focus on reducing the potential financial consequences of security failures. The company recommends adapting phishing exercises to reflect AI-enabled deception, introducing additional verification measures for sensitive transactions, monitoring compromised credentials on an ongoing basis, and maintaining robust third-party risk management processes.

“AI is rapidly reshaping cyber risk, as recent headlines have shown. But insurance claims help us understand where that risk is actually translating into financial loss,” commented Vishaal “V8” Hariprasad, Co-Founder and CEO of Resilience.

“Our data shows that AI is already contributing to financial losses by making familiar attack methods, like phishing and social engineering, more effective than ever. While we haven’t yet seen AI-native attacks emerge as their own driver of insured loss, that could of course change at any moment. As such, the organisations best prepared for the future will be the ones that treat AI as part of a broader, risk-first strategy—strengthening the controls that limit the impact of today’s attacks while preparing for tomorrow’s.”

“You can’t train your way out of every AI-generated phishing email or rely on human judgement when attacks themselves become entirely AI-generated,” added Judson Dressler, Head of Resilience’s Risk Operations Center.

“Whether an attack starts with an AI agent or a regular person, what matters most is how quickly an incident is contained once it’s underway. The organisations that avoid the worst financial outcomes detect threats quickly, build layered controls, verify high-risk transactions, and limit the fallout of attacks before they can become material losses.”