Skip to main content
Cybersecurity

Human error drove cyber losses in H1 2026

Social engineering contributed to 85.3% of incurred losses during that period, according to Resilience.

less than 3 min read

TOPICS: Cybersecurity / Incident Response & Resilience / Cyber Insurance

Good ol’ fashioned human error drove cyber insurance losses in the first half of the year.

According to a recent report from cyber risk management firm Resilience, social engineering was the culprit behind 85.3% of incurred losses in H1 2026, up from 17.7% in H1 2024.

Judson Dressler, director of Resilience’s risk operation center, told IT Brew that the rise in incurred losses driven by social engineering can be attributed to AI, which is making it easier for attackers to execute more convincing attacks.

“What we’re seeing is [AI] primarily acting as a force multiplier for the familiar human-enabled attacks,” he said.

What about AI? While incidents like OpenAI’s rogue agent and JadePuffer have dominated the news cycle in the past few months, Resilience said no losses in its claims data could be attributed to a fully autonomous attack chain or AI-specific attack vectors.

“We had no losses traced to prompt injection, model exploitation, agentic AI misuse,” Dressler said. “We just didn’t see it.”

While AI-native attacks may one day become a “significant source of loss,” Dressler said claims data shows the industry hasn’t reached that point yet: “I’m not saying that we don’t need to still pay attention to those [events], but we can’t lose sight of today’s risks while preparing for tomorrow’s.”

Back to the basics. Dressler said claims data reflects a growing need for organizations to prioritize security fundamentals. He recommended IT teams administer more realistic and up-to-date security awareness training to educate users about current attacks.

“The more your personnel, your employees know the different means [and] different methods that the attackers use, they can develop more of that healthy skepticism that they need going forward in cyber,” he said.

Dressler also said organizations should inform employees about the company’s standard processes so they can identify suspicious activities.

“Your employees should know that your help desk is never going to ask them for their PIN number for MFA,” Dressler said. “They are never going to ask them to download a remote-access tool or remote-management tool from the web.”

Top insights for IT pros

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.

About the author

Brianna Monsanto

Brianna Monsanto is a reporter for IT Brew who covers news about cybersecurity, cloud computing, and strategic IT decisions made at different companies.

Top insights for IT pros

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.