Humans, not artificial intelligence threats, are the cause of the large majority of cyber-attacks — for now.
More than 85% of incurred cyber losses in the first half of 2026 were from attacks that exploited human error, specifically where the point of failure included phishing, social engineering, or transfer fraud, according to a report out on Thursday from cyber insurer Resilience.
That’s not to say AI is a passive force in cyber-attacks. The report suggests that AI has become a force multiplier in attacks.
And the threat of AI is growing. So far this year, there has been a few glimpses at the building risk to cyber systems from AI in the form of a fully autonomous ransomware operation that ran without a human, and an AI that breached another company’s systems on its own.
IBM came out with a report on Wednesday that shows AI-driven attacks rose 56% over last year, adding roughly $1 million to the cost of a breach to reach an average $4.99 million.
Related: Insurer Interest in AI Exclusions Growing as Risk Becomes Omnipresent
However, what Resilience is seeing is that human error should still be the top concern for IT departments and cyber insurers.
“What we think about when we think of the future and what’s so scary would be a fully autonomous attack via AI with no humans involved whatsoever, so just kind of the machines taking over attacking, and there’s just zero human involvement,” said Jeremy Gittler, global head of claims, Resilience. “But we have not seen that at all in our book, we’ve had zero such attacks that we’ve been involved in.”
Every loss in the Resilience report is sorted into how the attack originated: social engineering; governance; vendor; vulnerabilities; or other.
The report shows that phishing and social engineering are increasingly primary points of entry for attackers. Losses tied to phishing, social engineering and transfer fraud have been on the rise in the past few years. They were up from 17.7% of incurred losses in the first half of 2024 to 85.3% in the same period this year, marking the single largest increase among loss drivers over the five half-year periods.
Attackers are using AI to improve social engineering attempts in everything from emails to voice deepfakes, the report shows.
“What part it is playing in that is it’s making it better,” Gittler said. “It could be in the form of deep fakes and rerouting the call when you want to check on whether you sent the invoice, for example, to the right spot. Or writing the emails for the threat actor instead of them writing it themselves, so the AI is really professionalizing it.”
Extortion driven by ransomware was the single largest cause of financial loss, accounting for 73% of incurred losses. Ransomware represented only 5.8% of total claims, the report shows. While rarer than other forms of attacks, they are disproportionately costly, but insureds may be getting savvier and helping themselves.
Average claim severity for claims with incurred cost fell from $784,000 in the first half of 2025 to $470,000 the first half this year. The drop was due to fewer high-value extortion demands, according to Gittler.
Related: Mythos Myths: Good Guys Hold More Cybersecurity Cards, Insurer CEO Says
“We have seen a huge shift in terms of the types of extortions,” he said.
Previously, the majority of these extortion attempts involved encrypting systems and requiring companies to pay for a decryption key.
“We’ve been preaching ‘You need to have viable backups so you’re not in this situation,’ and ‘Make sure that the backups have air gaps so there’s not a situation where, if they break into your regular system, they could also get to the backups,'” Gittler said. “That’s essentially shifted and what we see now is the large majority of that is data suppression, so they’re in your system, they steal personally identifiable information or health information or confidential business information, whichever it may be, and they want you to pay a ransom to not to release that data into the dark web.”
In general, these forms of extortion are far less costly. It’s a much bigger risk for an organization that can’t run when their system has been encrypted versus a business is merely faced with paying or not paying to stop information from being released, according to Gittler.
The report shows that vendor-related losses fell to just 2.3% of incurred losses, down from 33.5% in the first half of 2025.
According to Gittler, there were fewer incidents so far that were driven by vendor-related losses with large business ramifications.
“So, that’s not to say that this is something that’s gone away,” he said.
Was this article valuable?
Here are more articles you may enjoy.

Florida’s Fix for Insurance Crisis Puts More Risk on Homeowners
What Home Age Actually Tells Us About Claims — And What It Doesn’t
Spain and France Race to Contain Fires as Next Heat Wave Builds
Jury Awards 78-Year Old Victim $56 Million for Crash Caused by Amazon Delivery Driver