惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response
Ransomware Attacks Drive a Surge in Cyber Insurance Claims
KnowBe4 Team · 2026-05-29 · via Human Risk Management Blog

Cyber insurance claims surged by 40% over the past eighteen months, while ransomware payments have dropped by 44%, according to a new report from Cowbell Cyber. The three most common incident types were data breaches, cybercrime (including phishing and business email compromise), and extortion attacks (including ransomware).

“US cyber insurance premiums declined for the first time to $9.14B, while claims rose 40%, signaling increased loss activity despite reduced premium volume,” the report says. “This signals a more active risk environment, even as pricing adjusts. Ransomware remains a consistent part of that landscape, representing 19% of Cowbell claims between 2022 and 2025. At the same time, average ransom payments have decreased by approximately 44%, reflecting stronger negotiation strategies and more effective claims handling.”

Social engineering remains the most effective initial access vector, with AI tools amplifying the potency of these threats.

“Human error and manipulations prevail as the most common entry point for threat actors,” the report says. “Based on 2025 APWG data identifying approximately 3.8 million phishing attacks globally, phishing and spoofing remain the most prevalent cyber threats, underscoring the need for strong employee awareness, email security, and proactive threat detection as critical first lines of defense. Often delivered at scale and designed to appear credible, threat actors continue to refine these scam tactics using AI, making messages more convincing and harder to detect.”

The researchers add, “Variants of phishing, like smishing (text messages) or vishing (phone calls) expand these risks across channels. These tactics are designed to exploit trust and create a sense of urgency to bypass security protocols. Practical defenses like multi-factor authentication (MFA), employee training, and rapid response remain some of the most effective ways to reduce exposure.”

Risk & Insurance has the story: Ransom Payments Drop 44% Even as Cyber Claims Surge, Cowbell Reports