Human Error Remains at the Core of AI-Enabled Social Engineering

KnowBe4 Team | Aug 24, 2026

AI is making social engineering attacks significantly more effective, according to a new report from cyber insurance firm Resilience. These attacks were behind more than 85% of losses in the first half of 2026, compared to less than 20% during H1 2024.

“Losses tied to phishing, social engineering, and transfer fraud have climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026, the single largest increase in the report’s five half-year comparison,” Resilience says. “That climb matches what CEOs told the World Economic Forum for its ‘Global Cybersecurity Outlook 2026’ report, published this January. Cyber-enabled fraud and phishing are now their top-ranked cyber concerns, with AI risk newly at number two.”

The researchers also note that ransomware attacks — which often begin with social engineering — remain the most costly type of cyberattack, accounting for nearly three-quarters of reported losses so far this year.

“Ransomware, driven by extortion, is still the single most expensive line in the book, holding between 65% and 75% of incurred losses since 2024 and sitting at 73% year to date, even though it’s a small share of total claims (5.8%),” the researchers write. “The report also tracks the shift Resilience detailed in The Ransom Dilemma: more attackers are skipping encryption and going straight to data-theft-only extortion, a model that backups can’t stop but that identity containment and exfiltration detection can catch.”

Chris Wheeler, Resilience’s Chief Information Security Officer, stresses that social engineering awareness programs need to address this new threat landscape. “CISOs need to be turning up the difficulty on social engineering simulations and expanding beyond email if they’re going to reflect real-world incidents,” Wheeler said.

Resilience has the story: AI is reshaping cyber risk, but H1 2026 losses still trace to human error

FAQs

What percentage of cyber insurance losses come from social engineering?

According to Resilience's H1 2026 Cyber Risk Report, phishing, social engineering, and transfer fraud accounted for 85.3% of incurred losses in the first half of 2026. That's up from 17.7% in H1 2024 — the single largest increase across the report's five half-year comparisons.

How should organizations update their social engineering simulations?

Increase difficulty to match what attackers now produce with AI, and expand beyond email into voice, SMS, and collaboration tools where real incidents originate. Simulations that only test easy-to-spot email lures will overstate how prepared employees actually are.

Why is ransomware still the most expensive type of cyberattack?

Ransomware has held between 65% and 75% of incurred losses since 2024 and sits at 73% year to date, despite making up only 5.8% of total claims. The claims are few but severe, driven by extortion demands, business interruption, and recovery costs.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.