{"slug": "resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-2026-claims", "title": "Resilience Finds AI Amplifies Familiar Cyberattacks in H1 2026 Claims", "summary": "Resilience's 2026 Midyear Cyber Risk Report found that 85.3% of incurred losses in its insurance portfolio during H1 2026 traced to social engineering, up from 17.7% in H1 2024, while recording no incurred losses from AI-specific attack vectors. The report indicates AI's primary financial impact is amplifying familiar deception attacks rather than creating a new class of insured loss.", "body_md": "# Resilience Finds AI Amplifies Familiar Cyberattacks in H1 2026 Claims\n\nResilience's 2026 Midyear Cyber Risk Report says 85.3% of incurred losses in its insurance portfolio during the first half of 2026 traced to social engineering, up from 17.7% two years earlier. The company recorded no incurred losses from AI-specific attack vectors, suggesting that AI's clearest financial effect in its portfolio is to strengthen familiar deception rather than create a separate class of insured loss.\n\nResilience's 2026 Midyear Cyber Risk Report says AI is showing up in its insurance claims by making familiar attacks more convincing and scalable, not by creating a separate wave of AI-native insured losses. The company analyzed claims from its own portfolio alongside intelligence from its Risk Operations Center; its findings describe that book of business, not all cyber incidents worldwide.\n\n### Human deception dominates the loss mix\n\nIn the first half of 2026, Resilience attributed **85.3% of incurred losses** to social engineering as the point of failure, up from 17.7% in the first half of 2024. The report describes victims believing a false voice, message or request, and says attackers are using AI to sharpen those established techniques.\n\nThe same report says social engineering represented 21.7% of claim frequency in H1 2026. That gap matters: the 85.3% figure is a share of incurred loss value, not a claim count or an estimate of the global breach market.\n\nResilience recorded no incurred losses in the period from attack vectors it classified as AI-specific, including prompt injection, model exploitation or agentic-AI misuse. That does not mean those attacks do not exist. It means the company's H1 claims data had not yet identified them as a distinct driver of insured loss.\n\n### Ransomware remains rare but costly\n\nExtortion, driven by ransomware, accounted for 73.05% of incurred losses while representing 5.8% of claims. Resilience also reports that immutable-backup adoption among clients that self-reported controls rose from 79.9% to 85.2% year over year. The company says that improvement is likely one reason claims remain relatively infrequent, but the report does not establish a causal effect.\n\nVendor-related incidents accounted for 2.3% of incurred losses in H1 2026, down from 33.5% a year earlier. Resilience cautions that the lower share reflects the absence of a broad, high-severity vendor event in the period, not the disappearance of third-party exposure.\n\n### What security teams can act on\n\nThe report recommends phishing exercises that reflect AI-enabled deception, callback and dual-approval checks for sensitive transactions, continuous monitoring for compromised credentials, and contingency planning for critical vendors. For practitioners, the useful signal is operational: test whether controls contain a successful deception attempt and limit financial loss, rather than treating AI as a wholly separate attack category.\n\n## Key Points\n\n- 1Resilience attributes 85.3% of H1 2026 incurred losses in its portfolio to social engineering as the point of failure, compared with 17.7% in H1 2024.\n- 2The company recorded no incurred losses from AI-specific attack vectors in the period; that portfolio finding is not evidence that such attacks are absent globally.\n- 3Extortion represented 73.05% of incurred losses but only 5.8% of claims, while immutable-backup adoption rose to 85.2% among clients that self-reported controls.\n\n## Scoring Rationale\n\nThe report provides current claims-based evidence about how AI changes attacker economics and insured loss severity, with direct relevance to security and risk teams; its scope is limited to Resilience's portfolio and self-reported controls, so the finding is material but not industry-wide proof.\n\n## Sources\n\nPrimary source and supporting public references used for this report.\n\nPractice with real Health & Insurance data\n\n90 SQL & Python problems · 15 industry datasets\n\n250 free problems · No credit card\n\n[See all Health & Insurance problems](/problems/datasets/health)", "url": "https://wpnews.pro/news/resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-2026-claims", "canonical_source": "https://letsdatascience.com/news/resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-20-75ef5c59", "published_at": "2026-08-03 05:30:39+00:00", "updated_at": "2026-08-03 06:58:29.067821+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy"], "entities": ["Resilience"], "alternates": {"html": "https://wpnews.pro/news/resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-2026-claims", "markdown": "https://wpnews.pro/news/resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-2026-claims.md", "text": "https://wpnews.pro/news/resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-2026-claims.txt", "jsonld": "https://wpnews.pro/news/resilience-finds-ai-amplifies-familiar-cyberattacks-in-h1-2026-claims.jsonld"}}