The most feared cyber threats are not the ones draining corporate bank accounts. That is the central finding of cyber insurance firm Resilience’s 2026 Midyear Cyber Risk Report, which found that despite mounting anxiety over AI-powered attacks, not a single claim in its portfolio during the first half of 2026 traced back to an AI-specific attack vector.
What is generating losses is far more familiar. Social engineering, including phishing and transfer fraud, accounted for 85.3% of incurred losses in the first half of 2026, up from 17.7% two years earlier. AI’s real contribution, the insurer said, has been making the oldest scam in the book more convincing, with voice cloning and deepfakes fooling employees who once trusted their own ears.
One case study should make any operation handling payment instructions take notice. A CFO at a small financial services firm joined an audio-only Teams meeting where AI-generated voices of the CEO and a transactional attorney discussed an acquisition, then instructed the CFO to wire funds. Neither executive was on the call. A callback protocol recovered the full amount, but only after the wire went out.
The severity math is equally striking. Extortion events represented just 5.8% of claims but 73% of losses year to date. Meanwhile, the extortion playbook has shifted: data theft without encryption now dominates, meaning backups alone cannot neutralize the threat. Attackers are increasingly paid for silence, not decryption keys.
Vendor risk told a quieter story this half, falling to 2.3% of losses from 81.5% in early 2024, though Resilience cautioned that reflects the absence of a Change Healthcare-scale event, not reduced exposure.
For companies in credit and collections, the implications are direct. Operations built on outbound and inbound communications, wire transfers, and consumer data sit squarely in the attack surface that is actually producing losses. The report’s prescription is unglamorous but pointed: callback verification on a known number, dual sign-off on high-value transfers, harder phishing simulations, and containment capabilities that limit damage after someone inevitably clicks.




