Dive Brief:
- Cybersecurity attacks exploiting human error accounted for 85.3% of incurred losses in Resilience’s portfolio of insurance claims during the first half of 2026, up from 17.7% two years earlier, according to an analysis by the cyber risk firm.
- The shift comes as artificial intelligence is making attacks such as phishing and payment transfer fraud more convincing than ever, Resilience said in its Midyear Cyber Risk Report released July 30.
- “In two short years, AI has transformed the art of social engineering to make attacks more believable and therefore more effective,” Judson Dressler, head of Resilience’s Risk Operations Center, said in an emailed response to questions. “Most companies conduct training and phishing tests, but those scenarios often aren’t keeping pace with the sophistication of current AI-enabled attacks.”
Dive Insight:
The findings highlight the growing need for CFOs, chief information security officers and risk managers to think about cyber risk more holistically — which includes implementing layered verification for high-risk financial transactions — as AI makes fraud attacks harder to detect, Resilience said.
“Attackers have used AI to sharpen social engineering across the board, from emails to voice deepfakes,” according to the report, which is based on cyber insurance claims data in the Resilience portfolio from January 2024 through June 2026.
For finance leaders, one of the clearest warning signs is the rising contribution of payment transfer fraud to insured losses.
Payment transfer fraud’s share of insured losses in Resilience’s portfolio roughly tripled over the past two years, jumping to 9.2% from 2.9%, even as the number of transfer fraud claims declined.
“Anecdotally, we've seen a shift from traditional business email compromise to more targeted ‘big game hunting’ attacks in the transfer fraud category,” Dressler said.
“Rather than relying on high volumes of smaller fraud attempts, threat actors are using AI-enabled reconnaissance, voice cloning, and other convincing impersonation techniques to trick victims into transferring much larger sums of money. The result is fewer successful attacks but significantly higher financial losses when they occur,” he added.
Resilience’s report highlighted a case involving an unnamed financial services company whose CFO joined what appeared to be a legitimate Microsoft Teams call with the organization’s CEO and outside legal counsel to discuss a time-sensitive acquisition. According to the report, attackers used AI-generated voice clones trained on publicly available audio and video of both executives to convince the CFO to authorize a wire transfer.
Resilience said it recovered the funds through a bank clawback process, but noted that an independent callback verification to the CEO using a known phone number could have prevented the fraud.
More broadly, Dressler said CFOs should focus not only on preventing attacks but also on reducing the financial impact when incidents occur.
“The organizations with the best outcomes aren’t necessarily preventing every attack but they are asking the right questions and making sure incidents are contained before they become major material losses,” he said.