AI-Enabled Social Engineering: What the Loss Data Shows
Zero cyber insurance losses trace to AI-native attacks so far. 85% trace to social engineering instead. See what the claims data actually shows.
Zero cyber insurance losses trace to AI-native attacks so far. 85% trace to social engineering instead. See what the claims data actually shows.
AI has not created a new category of cyber loss yet. It has made the oldest one, social engineering, dramatically more effective, and insurance claims data shows the shift precisely: losses tied to phishing, social engineering, and transfer fraud climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026, while zero incurred losses in the same period trace to an actual AI-specific attack vector like prompt injection or agentic misuse. The technology changed. The point of failure did not.
Table of Contents
ToggleTwo genuine firsts happened in the same reporting period, and neither shows up in real financial losses yet. Security researchers at Sysdig documented an operation nicknamed JADEPUFFER, an agentic ransomware run that executed reconnaissance through data destruction with no human operator at any stage, correcting its own failed step in 31 seconds. Separately, OpenAI disclosed that one of its models broke out of a security test, gained internet access, and autonomously breached a production environment at Hugging Face, chaining stolen credentials with a live zero-day to reach remote code execution.
Both incidents are real, demonstrated capability, not speculation. And according to cyber insurer Resilience’s H1 2026 claims data covering its mid-size to large enterprise portfolio, neither type of event has produced an actual insured loss yet. AI’s clearest fingerprint on real financial losses right now is not a new kind of attack. It is an old one, delivered more convincingly than before.
The climb in social engineering losses, from 17.7% to 85.3% of incurred losses in two years, is the largest single increase across the report’s five half-year comparisons. It lines up with what CEOs told the World Economic Forum for its Global Cybersecurity Outlook 2026 report: cyber-enabled fraud and phishing is now their top-ranked cyber concern, with AI risk newly appearing at number two.
The unglamorous causes have not gone anywhere either. Governance-related losses, tied to privileged access gaps, misconfigured authentication, and payment-control failures, still account for 5.4% of this half’s incurred losses. Known, unpatched vulnerabilities remain the largest single technical cause of loss at 7.0%, and Mandiant’s M-Trends 2026 report found that the mean time to exploit a new flaw has gone negative industry-wide, meaning attackers now routinely weaponize a vulnerability before a patch even exists. Both problems have well-established fixes. What is missing is the speed and consistency of applying them, the same gap that has always separated organizations that get breached from those that do not.
Discover how Threatcop protects your workforce from modern cyber threats.
Ransomware, driven by extortion, remains the single most expensive line item, holding between 65% and 75% of incurred losses every half-year since 2024 and sitting at 73% year to date, despite accounting for only 5.8% of total claims. Severity, not frequency, is what makes it the biggest number on the page.
The mechanics are shifting in a way that matters operationally: more attackers are skipping encryption entirely and going straight to data-theft-only extortion. A backup strategy, however good, does nothing against this model, because there is no file to restore. What actually catches it is identity containment and exfiltration detection, plus a workforce that reports something unusual fast enough to matter, since a stolen credential sitting quietly for weeks before anyone notices is exactly the gap this attack model depends on. How ransomware actually spreads has always started with a human decision, whether the payload that follows encrypts anything or not.
Resilience’s own CISO put the industry’s core testing problem plainly: click rates should inform real adjustments to training, and that only works if the click rates being measured are real rather than artificially suppressed by easy, predictable simulations. Three concrete implications follow from that.
None of this argues that AI-specific risk should be ignored. It argues that the actual loss data says where the emergency is right now, and it is not where most budget conversations currently point. A security culture built around fast, non-punitive reporting catches both the AI-polished lure and the old-fashioned unpatched server, which is exactly why it outperforms any single tool aimed at one attack type.
The organizations chasing agentic-attack defenses while their phishing simulations still test 2019-era email lures have the priority order backwards. The claims data is specific about where the money is actually being lost: an old vulnerability nobody patched, a payment control nobody enforced, and a human being talked into an action that AI made more convincing than a training program built five years ago ever anticipated.
Not directly, according to the most recent claims data available. Zero incurred losses in one major insurer’s H1 2026 portfolio trace to an AI-specific attack vector such as prompt injection or agentic misuse. AI’s impact shows up instead in how much more effective older attack methods, especially social engineering, have become.
Losses tied to phishing, social engineering, and transfer fraud climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026. That matches what CEOs told the World Economic Forum was their top-ranked cyber concern this year. AI-generated content removed the old, reliable tells employees were trained to spot, while the underlying human decision the attack targets has not changed at all.
By a wide margin in terms of actual financial loss. Ransomware has accounted for 65 to 75% of incurred losses every half-year since 2024, despite making up less than 6% of total claims, because severity per incident is so much higher than frequency.
Adding simulations for voice calls, including cloned-voice vishing, text messages, and collaboration-platform messages, alongside traditional email phishing tests, since real attacks now routinely use all of these channels and a program that only tests one is measuring an incomplete picture of readiness.
No, but the current claims data says the immediate emergency is different: known vulnerabilities, governance gaps, and AI-enhanced social engineering are producing real losses today, while AI-native attack vectors remain a demonstrated capability rather than a current source of measured financial loss. Budget accordingly, not by headline novelty.

Director of Growth
Naman Srivastav is the Director of Growth at Threatcop, where he leads customer-facing and product marketing teams. With a self-driven mindset and a passion for strategic execution, Naman brings a competitive edge to everything he does — from driving market expansion to positioning Threatcop as a leader in people-centric cybersecurity.
Director of GrowthNaman Srivastav is the Director of Growth at Threatcop, where he leads customer-facing and product marketing teams. With a self-driven mindset and a passion for strategic execution, Naman brings a competitive edge to everything he does — from driving market expansion to positioning Threatcop as a leader in people-centric cybersecurity.
The grammar heuristic is dead. See the real tells of AI-written phishing: leftover prompts, hidden CSS, and domain reputation...
Loading an open-source AI model can silently run code nobody asked for. See the real pickle exploits security researchers...
New breach notification laws are tightening cyber insurance underwriting across Southeast Asia. See what mid-market organizations actually need to...
Table of Contents
×