Cyber insurance claims up 40%

Cowbell just released their 2026 Cyber Roundup Claims Report, and there’s some genuinely good news buried in there: average ransom payments are down 44% over the past few years.

The bad news: cyber insurance claims are up 40%. Cyber insurance premiums just dropped for the first time—to $9.14 billion—while the actual number of attacks keeps climbing.

So we’re getting better at not paying ransoms, but we’re definitely not dealing with fewer attacks. In fact, we’re dealing with more. A lot more.

The Numbers

Cowbell analyzed 18 months of claims data, and three types of incidents account for almost everything:

  • Data breaches – 33.5% of claims
    Someone gets unauthorized access to sensitive information. Could be customer data, employee records, financial info—anything you really don’t want walking out the door.
  • Cybercrime – 31.8% of claims
    This is your phishing, business email compromise, funds transfer fraud. The stuff that exploits human trust rather than technical vulnerabilities.
  • Extortion – 18.3% of claims
    Mostly ransomware, but increasingly “we’ll leak your data unless you pay us” schemes.

Notice what these have in common?

They all start with someone on your team being targeted. Between 74% and 95% of breaches involve what the report politely calls “the human element.” Translation: someone clicked something, responded to someone, or trusted the wrong message.

Who are the perpetrators

The data shows that seven ransomware groups are behind more than two-thirds of the cases where they could identify the attacker.

Two criminal groups account for more than half by themselves. They operate as ransomware-as-a-service (yes, that’s a business model ) and target bigger enterprises. They steal your data first, encrypt it second, then threaten to publish it if you don’t pay.

Akira – 38.8% of identified attacks

They go after small and mid-sized businesses through VPN and remote access vulnerabilities. If you’re running outdated remote access tools, you’re exactly who they’re looking for.

Qilin – 14.2% of identified attacks

There are seven groups in total, and most operate from Eastern Europe. They’re specifically hunting for unpatched VPNs and remote access vulnerabilities—the stuff we know we should fix but haven’t gotten around to yet.

The 2026 Ransomware playbook – how it works

Ransomware used to be “pay us or you’ll never get your files back”? That’s evolved.

Now it’s double-extortion: “We encrypted your files AND we copied them. Pay us to decrypt them. Also pay us not to publish them.”

Some groups are skipping encryption entirely and just going straight to “pay us or we leak everything.”

Why are ransom payments dropping if the attacks are getting worse? Two reasons:

  • Better backups – Companies are finally taking backup strategies seriously. If you can restore from backup, you don’t need to pay for decryption.
  • Stronger negotiation – Organizations are getting better at pushing back on ransom demands.

But while decryption payments are going down, data suppression payments are going up. You might not need to pay to unlock your files, but you might still pay to prevent them from being published. That data could include client information, trade secrets, legal documents—anything that would cause serious damage if it went public.

Which companies are getting targeted

Certain industries are seeing consistently higher exposure:

  • Professional services (financial and law firms)
  • Construction
  • Manufacturing
  • Healthcare
  • Wholesale trade

Some are because they handle sensitive information. The others rely heavily on systems staying operational. Law and investment firms remain THE favorite target because they hold extremely sensitive client data and often run outdated security controls.

If you’re in one of these sectors, you’re not just a possible target—you’re a preferred target.

The Defenses that work

Cowbell looked at what’s actually preventing claims, not just what sounds good in a security checklist.

  1. Multi-factor authentication: Still one of the most effective controls. It’s not perfect, but it stops a huge percentage of attacks that rely on stolen credentials.
  2. Employee training: Not the annual compliance training everyone clicks through. Real, practical awareness of what current attacks look like and how to verify unexpected requests.
  3. Penetration testing: Cowbell’s data shows that over 95% of policyholders who used their complimentary micro penetration testing services haven’t experienced a claim. That’s not a coincidence—you can’t fix vulnerabilities you don’t know about.
  4. Robust backup strategies: Not just having backups, but testing them regularly and keeping them isolated from your network so ransomware can’t encrypt them too.

The Bottom Line

Attacks are up. Claims are up. Sophistication is up. The good news is ransom payments are down, which means we’re getting better at response and recovery.But the better news would be not dealing with the incident in the first place.

The cyber insurance market is showing signs of stress. Insurers are betting that losses will stabilize as defenses improve. But the claims data suggests attacks are getting more sophisticated and more frequent, not less. But you can’t rely on insurance as the primary defense. It’s there to help manage the financial impact when something goes wrong, but the goal is to not have something go wrong in the first place.

The threat landscape in 2026 isn’t about mysterious hackers finding zero-day vulnerabilities in your custom code. It’s about organized groups systematically exploiting unpatched systems and manipulating people into taking actions that compromise security.

Those are both things we can defend against—not perfectly, but well enough to make us a less attractive target than the company down the street that hasn’t updated their remote access tools in three years.

As always, if something feels off or you’re not sure about a request, reach out to Corporate IT directly. We’d rather answer a hundred questions than clean up after one successful attack.

Stay sharp out there!

Klaus