Briefing at a Glance

  • Analysis by Resilience shows that in the first half of 2026, cyberattacks exploiting human error accounted for 85.3% of incurred losses in its insurance claims portfolio, compared with 17.7% two years earlier.
  • The company's Mid-Year 2026 Cyber Risk Report, released on July 30, notes that artificial intelligence is making attacks such as phishing and payment fraud more convincing than ever.
  • Judson Dressler, head of Resilience's Cyber Risk Operations Center, said in an email response: "In just two years, AI has transformed the landscape of social engineering, making attacks more credible and effective. Most companies conduct training and phishing tests, but these scenarios often lag behind the sophistication of current AI-enabled attacks."

In-Depth Insights

Resilience says these findings highlight the need for CFOs, CISOs, and risk managers to think more holistically about cyber risk—including implementing layered verification for high-risk financial transactions—because AI makes fraudulent attacks harder to detect.

Based on cyber insurance claims data from Resilience's portfolio between January 2024 and June 2026, the report states: "Attackers have used AI to comprehensively enhance social engineering tactics, from email to voice deepfakes."

For financial leaders, one of the clearest warning signs is the rising share of payment fraud in insurance losses. Over the past two years, payment fraud as a percentage of incurred losses in Resilience's portfolio has nearly tripled, jumping from 2.9% to 9.2%, even as the number of such claims has declined.

Dressler said: "On a case-by-case basis, we are seeing traditional business email compromise shift toward more targeted 'big-game hunting' attacks. Instead of relying on a high volume of small-scale fraud attempts, attackers use AI-driven reconnaissance, voice cloning, and other convincing impersonation methods to trick victims into transferring larger sums. The result is fewer successful attacks, but when they succeed, the financial losses are significantly greater."

Resilience's report also cites a case involving an unnamed financial services company whose CFO participated in what appeared to be a legitimate Microsoft Teams call with the organization's CEO and external legal counsel to discuss a time-sensitive acquisition. According to the report, attackers used AI voice cloning trained on publicly available audio and video to mimic both executives, persuading the CFO to authorize a wire transfer. Resilience recovered the funds through bank tracing processes, but noted that an independent callback verification to the CEO using a known phone number could have prevented the fraud.

More broadly, Dressler said CFOs should focus not only on preventing attacks but also on reducing financial impact when incidents occur. He said: "Top-performing organizations are not those that stop every attack, but those that ask the right questions and ensure incidents are contained before they escalate into major material losses."