Dive Brief:
- Ransomware extortion caused roughly three-quarters of business losses in the first half of 2026, the cyber insurance firm Resilience said in a recent report.
- At the same time, ransomware accounted for less than 6% of the incidents for which Resilience customers submitted claims, which the company said highlighted how “disproportionately costly” they are.
- Other data in the report highlight the importance of proper employee training and vigilant adherence to protocols such as regular backups.
Dive Insight:
Despite AI-related attacks dominating many organizations’ fears, no such attacks have generated claims yet, Resilience said. Instead, costly attacks have begun in familiar ways. More than 85% of losses that the insurer dealt with began with spearphishing. Remarkably, that figure was only 18% in 2024.
“So far, AI's clearest effect on the portfolio isn’t a new attack type,” Resilience said. “It has made the oldest one, social engineering, more convincing.”
Companies also continue to struggle with patching vulnerabilities, including widely known flaws that hackers have been exploiting for months or even years. The largest technical cause of losses was the exploitation of known vulnerabilities, which accounted for 7% of all losses. In the second half of 2024, those flaws led to 25% of total losses.
No company can completely seal itself off from attacks, Resilience said, but organizations can prepare in ways that make attacks less damaging and more easily withstood.
“What separates outcomes is containment: how fast an event is detected and how much loss gets limited once it's underway,” analysts wrote.
Companies were far more likely to experience losses because of direct intrusions than because of supply-chain compromises in the first half of 2026. Just 2.3% of losses resulted from vendor breaches. In the first half of 2025, that share was 34%.
Major supply-chain incidents still occur — Resilience pointed to the Canvas platform hack — but the firm said that recent ones have been less costly than earlier crises such as the Change Healthcare breach.