AI‑Enhanced Social Engineering Drives 85% of Cyber‑Insurance Losses, Claims Data Shows
What Happened — Resilience’s 2026 Mid‑Year Cyber Risk Report found that AI has not yet produced a distinct “AI‑native” breach, but it is amplifying traditional social‑engineering attacks. Social engineering accounted for 85 % of incurred losses, while payment‑fraud losses tripled year‑over‑year.
Why It Matters for Compliance & Audit Readiness
- The surge in AI‑assisted phishing directly tests SOC 2 CC6.1 (Logical Access) and CC7.1 (Security Awareness) controls; evidence of training and testing is now a core audit artifact.
- Continuous monitoring of human‑centric controls (phishing simulations, credential‑use analytics) provides the defensible trail insurers and auditors demand.
- Mapping the financial impact shown in claims data to control gaps helps prioritize remediation and demonstrates due‑diligence under SOC 2 Trust Services Criteria.
Who Is Affected – Financial‑services insurers, large enterprises across all verticals, and any organization that relies on human‑based authentication or payment processes.
Recommended Actions –
- Align your security‑awareness program with SOC 2 CC7.1: schedule regular, AI‑aware phishing simulations and retain training logs as audit evidence.
- Implement continuous credential‑use monitoring to detect anomalous access patterns amplified by AI‑generated lures.
- Use claims‑style loss data to prioritize control investments where financial impact is proven.
Source: DataBreachToday – Claims Data Shows Where AI Risk Is Hitting Now
Technical Notes – The report does not cite a specific vulnerability; the vector is human‑focused social engineering, accelerated by AI‑generated content (deepfakes, persuasive language models). No CVEs are involved. Source: same as above