Subscribe

The trick: Zero Underneath

The insurer that pays out when cyberattacks succeed cannot find a single AI-specific loss in its 2026 claims data.

AI really is reshaping attacks, just not the way the headlines say. Prompt injection, model exploitation and agentic misuse have paid out exactly nothing. The AI dividend is landing in the oldest line item there is: phishing that works.

Issue 814 August 20264 receipts3 min

AI-driven cyberattacks are escalating and reshaping the threat landscape, with AI-powered attacks exploding across 2026

Before you read on. Your call?

cyber insurer Resilience's H1 2026 report, built on claims data from January 2024 through June 2026, finds zero incurred losses traceable to an AI-specific attack vector. No prompt injection loss. No model exploitation loss. No agentic misuse loss. What the data does show is AI supercharging the oldest attack in the book: phishing, social engineering and transfer fraud climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026. The escalation is real. The vector in the headlines is not the vector in the claims files.

0INCURRED LOSSES IN RESILIENCE'S CLAIMS PORTFOLIO FROM PROMPT INJECTION
85.3%OF H1 2026 INCURRED LOSSES FROM PHISHING
44%IBM'S RISE IN ATTACKS ON PUBLIC-FACING APPS

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Zero Underneath: the headline number has nothing behind it. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“'Which AI attack, specifically, and who paid a claim on it?' Escalating reconnaissance is real, AI-polished phishing is real and expensive. But an insurer combing its own payouts found no prompt injection, no model exploitation, no agentic misuse. The AI threat that exists is an amplifier, not a new weapon.”

Receipts

  1. Supports newsroom.ibm.com: observed a 44% increase in attacks that began with the exploitation of public-facing applications, largely driven by missing authentication controls and AI-enabled vulnerability discovery
  2. Refutes cyberresilience.com: In the first half of 2026, zero incurred losses in the portfolio trace to an AI-specific attack vector, not prompt injection, not model exploitation, not agentic misuse.
  3. Context cyberresilience.com: phishing, social engineering, and transfer fraud have climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026
  4. Context nhimg.org: AI SOC agents sit at the Peak of Inflated Expectations, up from the Innovation Trigger in 2025, while market penetration is 1% to 5%

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.