Growth Signals

Human error drives most cyber losses

By Sofia Ramirez · · 3 min read
Human error drives most cyber losses - cyber losses
Human error drives most cyber losses

Cybersecurity attacks exploiting human error accounted for 85.3% of incurred losses in Resilience’s portfolio of insurance claims during the first half of 2026, up from 17.7% two years earlier.

Artificial intelligence is making attacks such as phishing and payment transfer fraud more convincing than ever, according to an analysis by the cyber risk firm.

Resilience said in its Midyear Cyber Risk Report released July 30 that attackers have used AI to sharpen social engineering across the board, from emails to voice deepfakes.

Judson Dressler, head of Resilience’s Risk Operations Center, said “In two short years, AI has transformed the art of social engineering to make attacks more believable and therefore more effective.”

Most companies conduct training and phishing tests, but those scenarios often aren’t keeping pace with the sophistication of current AI-enabled attacks, Dressler added.

The findings highlight the growing need for CFOs, chief information security officers and risk managers to think about cyber risk more holistically — which includes implementing layered verification for high-risk financial transactions — as AI makes fraud attacks harder to detect.

For finance leaders, one of the clearest warning signs is the rising contribution of payment transfer fraud to insured losses, with its share roughly tripling over the past two years.

They have seen a shift from traditional business email compromise to more targeted ‘big game hunting’ attacks in the transfer fraud category, according to Dressler.

Rather than relying on high volumes of smaller fraud attempts, threat actors are using AI-enabled reconnaissance, voice cloning, and other convincing impersonation techniques to trick victims into transferring much larger sums of money.

Resilience’s report highlighted a case involving an unnamed financial services company whose CFO joined what appeared to be a legitimate Microsoft Teams call with the organization’s CEO and outside legal counsel to discuss a time-sensitive acquisition.

According to the report, attackers used AI-generated voice clones trained on publicly available audio and video of both executives to convince the CFO to authorize a wire transfer.

Resilience said it recovered the funds through a bank clawback process, but noted that an independent callback verification to the CEO using a known phone number could have prevented the fraud.

More broadly, Dressler said CFOs should focus not only on preventing attacks but also on reducing the financial impact when incidents occur.

“The organizations with the best outcomes aren’t necessarily preventing every attack but they are asking the right questions and making sure incidents are contained before they become major material losses,” he said.

Related: Chicago Acting CFO Leaves Amid Budget Fight

Leave a Reply

Your email address will not be published.