Human Error, Not AI Agents, Is Driving Cyber Losses So Far In 2026
Despite widespread attention on autonomous AI attacks, cyber insurer Resilience found that no losses in its portfolio during the first half of 2026 could be attributed to AI-specific attack vectors such as prompt injection, model exploitation, or agentic AI misuse.
Instead, the company’s Cyber Mid Year Risk Report found that 85.3% of incurred losses trace back to a person believing a fraudulent voice, message, or request, a figure that has climbed steadily from 17.7% in H1 2024, 41.3% in H2 2024, 46.9% in H1 2025 and 75.2% in H2 2025. The report is based on claims data from Resilience’s portfolio of mid-size to large enterprises, which carry average annual revenue of $2.04 billion, from January 2024 through June 2026.
Agentic AI Threats Documented, But Not Yet In Claims
Resilience pointed to two developments this half that it described as warning signs rather than current drivers of loss.
Sysdig Threat Research documented JADEPUFFER, a ransomware operation the company said ran autonomously from reconnaissance through data destruction with no human operator, self-correcting a failed step in 31 seconds. Separately, OpenAI disclosed that one of its models broke out of a controlled security test, gained internet access, and autonomously breached Hugging Face’s production environment, chaining stolen credentials with a zero-day vulnerability to achieve remote code execution.
Both companies said there was no malicious intent involved, according to the report, but the harm to Hugging Face was real. Resilience said no H1 2026 claim in its portfolio points to a fully automated attack chain or the exploitation of a vulnerability discovered by a frontier model, though it characterized that gap as one that “won’t last.”
Known Fixes Aren’t Being Applied Fast Enough
The report identified known vulnerabilities as the largest technical cause of cyber insurance claims at 7.0% of incurred losses in H1, down from a high of 25% in H2 2024. Governance-related losses, tied to gaps such as privileged access flaws, misconfigured authentication and payment controls, accounted for 5.4%.
Resilience said fixes for both categories already exist; what’s lacking is speed and breadth of adoption. Resilience cited Mandiant’s “M-Trends 2026” report, which found mean time-to-exploit has gone negative to an estimated negative seven days industrywide, meaning exploitation often begins before a patch is even available. It also cited CrowdStrike’s “2026 Global Threat Report,” which found average breakout time — the speed at which a cybercriminal moves from their first step inside a network to other computers in the organization — fell to 29 minutes from 48 minutes in 2024, with the fastest recorded breakout at 27 seconds.
Extortion remained the costliest cause of loss, holding between 65% and 75% of incurred losses since FY 2024 and reaching 73% year-to-date in H1 2026 while representing just 5.8% of total claims.
Vendor-related losses, by contrast, fell sharply, from 81.5% of incurred losses in H1 2024 to just 2.3% in H1 2026, a swing the report attributed to the absence of a widespread event on the scale of Change Healthcare or CDK Global rather than a drop in underlying exposure.
Claims frequency rose to 45.9 per 100 policies in the first half of 2026, driven largely by wrongful data collection claims, which represented 16.7% of claim count, up from 7.3% a year earlier. Average claim severity fell to approximately $470,000, driven by fewer high-value extortion demands and zero business-interruption claims, though Resilience cautioned that figure could reverse if more severe events occur later in the year.
Obtain the full report here. &