‘While we haven’t yet seen AI-native attacks emerge as their own driver of insured loss, that could of course change at any moment,’ says chief executive

Human error remains the number one route for cyber breaches, according to the latest Cyber Risk Report from cyber risk management firm Resilience.

Published yesterday (30 July 2026), the report – compiled from Resilience’s own loss data – found that in the first half of 2026, 85.3% of incurred cyber losses stemmed from human error, typically via phishing, social engineering or transfer fraud attacks.

And Ransomware remains the single biggest threat to businesses, accounting for 73% of incurred losses, despite appearing in just 5.8% of claims submissions.

Meanwhile, and perhaps surprisingly, Resilience detected no incurred losses whatsoever from artificial intelligence (AI)-native cyber attacks such as prompt injections, model exploitations or targeted agentic AI misuse.

This is despite high profile news stories like the Hugging Face cyber attack and Claude Mythos’ paused rollout hitting the headlines in recent months.

AI-native attacks

Vishaal Hariprasad, co-founder and chief executive at Resilience, said: “AI is rapidly reshaping cyber risk, as recent headlines have shown. But insurance claims help us understand where that risk is actually translating into financial loss.

“Our data shows that AI is already contributing to financial losses by making familiar attack methods like phishing and social engineering more effective than ever. While we haven’t yet seen AI-native attacks emerge as their own driver of insured loss, that could of course change at any moment.

“As such, the organisations best prepared for the future will be the ones that treat AI as part of a broader, risk-first strategy – strengthening the controls that limit the impact of today’s attacks while preparing for tomorrow’s.”