Claims Data Shows Where AI Risk Is Hitting Now #AI


Artificial Intelligence & Machine Learning
,
Cyber Insurance
,
Fraud Management & Cybercrime

Resilience Data Shows Social Engineering Dominates Over AI-Native Losses


Jud Dressler, director, Resilience Risk Operations Center

Artificial intelligence is reshaping cyber risk, but insurance claims suggest its biggest near-term impact isn’t a new class of attack. It’s helping cybercriminials use familiar tactics such as social engineering, but creating more convincing and more financially damaging campaigns faster, said Jud Dressler, director of Resilience’s Risk Operations Center.

See Also: How Skilled Attackers Weaponize AI Faster

Claims data can offer CIOs and CISOs insights that conventional threat intelligence can’t, Dressler said, identifying which types of attacks lead to paid claims, business interruptions, fraud losses or ransom payments. Threat reports show what adversaries attempt, while claims reveal where controls hold up in actual incidents and where operational gaps lead to loss. Organizations can use that evidence to prioritize spending according to demonstrated financial impact, rather than perceived risk or speculative scenarios.

“We can’t lose sight of today’s risks while we’re preparing for tomorrow’s,” Dressler said.

Resilience recorded no incurred losses from AI-native attacks, including prompt injection, model exploitation and agentic misuse, during the first half of 2026, the company revealed in its 2026 Midyear Cyber Risk Report. Instead, AI primarily acted as a force multiplier for human-enabled attacks. Social engineering accounted for 85% of incurred losses in the portfolio, up from 17% a couple of years earlier, while payment fraud losses tripled from the prior year. The underlying targets remain people, credentials and internet-facing devices.

In this video interview with ISMG, Dressler discussed:

  • How claims data distinguishes demonstrated financial loss from emerging cyberthreats;
  • Which layered controls, response capabilities and governance practices reduce exposure;
  • Why data theft, control gaps and recurring extortion demand a resilience-first strategy.

Dressler leads Resilience’s Risk Operations Center. He retired as an Air Force colonel after 20 years in cyber operations, during which he established the Air Force’s Advanced Cyber Schoolhouse, commanded incident response teams and served as permanent professor and head of the Department of Computer and Cyber Sciences at the U.S. Air Force Academy. He holds a Ph.D. in computer science from Rice University.



Click Here For The Original Source.

——————————————————–

..........

.

.