Resilience, a cyber risk solutions company renowned for helping organizations navigate and mitigate cyber threats, has published a critical analysis revealing that artificial intelligence (AI) is predominantly utilized to bolster established cyber attack methods. This finding is part of Resilience’s 2026 Midyear Cyber Risk Report, which synthesizes insurance claims data and intelligence from the company’s Risk Operations Center (ROC).

Throughout the first half of 2026, Resilience reported no financial losses specifically attributed to AI-centric attack methods, such as prompt injection, model exploitation, or agentic AI misuse. Instead, traditional cyber threats continued to dominate the financial losses, with incidents stemming from human error accounting for a staggering 85.3% of incurred losses. The data indicated that phishing, social engineering, and transfer fraud were the most common entry points for attackers.

Interestingly, this represents a significant departure from the situation in early 2024 when human error-related incidents only accounted for 17.7% of losses. This shift suggests that while AI is indeed enhancing the efficiency of known attack strategies, it has yet to give rise to a distinctly new category of attacks that could lead to insured losses.

Attacks through phishing and social engineering are increasingly prevalent, making them favored methods for attackers to infiltrate systems. While ransomware-related extortion remains a significant contributor to financial damage—responsible for 73% of incurred losses—Resilience highlighted that ransomware incidents are notably less frequent, marking only 5.8% of all claims, but they carry a considerable financial burden when they do occur.

Statistically, the increase in the use of immutable backups from 79.9% to 85.2% year-on-year is promising; it may improve recovery capabilities and possibly reduce the number of claims associated with ransomware. Moreover, Resilience revealed that vendor-related incidents accounted for only 2.3% of losses, a steep drop from 33.5% during the first half of 2025. This downward trend signifies that although third-party disruptions remain operational risks, they are not leading to the same level of insured financial repercussions as in prior years.

As AI technologies continue to enhance the effectiveness and sophistication of established attack methods, Resilience recommends that organizations prioritize strategies to minimize the potential financial fallout from security breaches. Key recommendations include adapting phishing exercises to simulate AI-enabled deceptions, implementing additional verification for sensitive transactions, and continuously monitoring for compromised credentials.

“AI is rapidly reshaping cyber risk, as recent headlines have shown. But insurance claims help us understand where that risk is actually translating into financial loss,” emphasized Vishaal “V8” Hariprasad, Co-Founder and CEO of Resilience. He noted that while AI has not yet spawned a new category of attacks leading to insured losses, organizations need to adopt a risk-first approach to manage the evolving landscape.

Judson Dressler, Head of Resilience’s Risk Operations Center, echoed this sentiment by stating that organizations must prepare not only for traditional threats but also for potential future challenges presented by AI-generated attacks. The focus should be on swiftly containing incidents and building layered controls to mitigate the worse outcomes of cyber incidents, whether initiated by human actors or AI systems.