Skip to content

Cyber Insurance Claims Statistics 2026: What Gets Claimed, What It Costs, Who Pays

Cyber insurance claims statistics for 2026 from Coalition, NetDiligence, AM Best and Hiscox: claim frequency, severity, BEC and ransomware losses, loss ratios.

Invadel TeamSeptember 14, 20267 min read

Insurers see the incidents that never make the news: the $27,000 mailbox compromise, the wire that went to the wrong account, the ransomware attack at a 40-person firm. Their claims data is the closest thing to a census of what actually goes wrong at ordinary companies, and it points to different priorities than the breach headlines do. This page collects the current figures from Coalition’s 2026 Cyber Claims Report, the NetDiligence Cyber Claims Study, AM Best’s market results, Hiscox, Sophos and the FBI, each linked to its source. We update the page as the reports are published.

How to cite: link to this page or to the primary source beside each figure. Claims figures describe insured organizations, which skews toward companies that already had some controls in place.

1. How often insured companies claim

  • Cyber claims frequency rose 3% in 2025 while average severity fell 19% to $116,000; the overall claims rate was 1.54% of policyholders. (Coalition 2026 Cyber Claims Report, full-year 2025 claims)
  • Companies with more than $100 million in revenue claimed five times as often as smaller ones, with an average loss of $268,000, down 7%. (Coalition 2026)
  • Small and medium-sized enterprises made up 98% of claims in a study of 10,402 claims from 2020 to 2024; large companies were 2% of claims but more than half of total incident costs. (NetDiligence Cyber Claims Study 2025)
  • 64% of closed claims were resolved with no out-of-pocket loss to the policyholder. (Coalition 2026)

2. What the claims are for

  • Business email compromise was the most common claim at 31% of all claims, with frequency up 15% year over year and an average loss of $27,000, down 28%. (Coalition 2026)
  • Funds transfer fraud was second at 27% of claims, average loss $141,000; 52% of those frauds began with a compromised mailbox. BEC and funds transfer fraud together were 58% of all incidents. (Coalition 2026)
  • Ransomware was the most expensive claim type, average loss $269,000. 70% of ransomware claims were dual extortion (encryption plus data theft), and data-theft claims cost more than twice as much as encryption-only claims. (Coalition 2026)
  • Across five years of NetDiligence data, the top five causes of loss were ransomware, business email compromise, hacker attacks, theft of money, and wire transfer fraud. The study includes 2,675 ransomware claims and 1,864 BEC claims. (NetDiligence 2025)
  • Third-party (liability) claims are trending up 30%. (AM Best, via Insurance Journal, July 2026)

3. What an incident costs an SME

  • $264,000: the average total incident cost for a small or medium-sized enterprise, up about 30% year over year. Crisis services (forensics, legal, notification, credit monitoring) averaged $152,000 of that. The five-year SME average is $246,000. (NetDiligence 2025)
  • For large companies the averages were $3 million for crisis services and $10.3 million per incident. (NetDiligence 2025)
  • Ransomware incidents at SMEs accounted for 81% of claims with a business interruption component, and business interruption losses in some cases exceeded $1 million. (NetDiligence 2025)
  • Five sectors (professional services, manufacturing, healthcare, retail, financial services) accounted for 47% of SME claims and 60% of SME incident costs. (NetDiligence 2025)
  • Insurance paid 69% of total incident cost for SMEs over five years, down from 81%; for large companies 27%. The remainder is retention, uncovered cost, or the gap between the limit and the loss. (NetDiligence 2025)
  • Outside the insured population, the average cost to recover from ransomware was $1.7 million excluding the ransom, and the average data breach cost $4.99 million globally and $11.5 million in the United States. (Sophos State of Ransomware 2026; IBM Cost of a Data Breach Report 2026)

4. Ransom payments through the insurance lens

  • Initial ransom demands surged 47% in 2025, yet a record 86% of Coalition’s policyholders hit by ransomware refused to pay. (Coalition 2026)
  • The general population pays more often: 48% of organizations whose data was encrypted paid, with a median payment of $769,000, and 51% of payers negotiated the demand down. Among small businesses surveyed by Hiscox, 80% of ransomware victims paid. The difference is a response plan and a carrier’s negotiators. (Sophos 2026; Hiscox Cyber Readiness Report 2025)
  • Total ransomware payments traced on-chain fell to about $820 million in 2025 as the share of victims paying reached an all-time low of 28%. (Chainalysis 2026 Crypto Crime Report)
  • Coalition recovered $21.8 million in stolen funds for policyholders, an average of $202,000 per recovery. Recovery depends on reporting the fraud within hours. (Coalition 2026)

5. The market: pricing and loss ratios

  • The US cyber insurance loss ratio rose to 53 in 2025, the second straight yearly increase and the first time above 50 since the ransomware spike of the pandemic years. Surplus lines carriers ran near 56, admitted carriers 50.2. (AM Best, via Insurance Journal, July 2026)
  • Total premium was roughly flat in 2025, and the first quarter of 2026 was the eighth consecutive quarter of price cuts. Buyers are paying less for a product whose losses are rising. (AM Best, via Insurance Journal)
  • Surplus lines carriers write nearly two-thirds of all US cyber premium; Chubb is the largest writer. (AM Best, via Insurance Journal)
  • 33% of small and medium-sized enterprises that were attacked were hit with a substantial fine afterwards, and 44% lost money to payment diversion fraud, the two costs a policy may or may not cover depending on the wording. (Hiscox 2025, 5,750 businesses)

6. Where the losses come from, outside the claims data

  • Business email compromise cost $3.046 billion in reported US losses in 2025; 86% of it moved by wire transfer or ACH. (FBI IC3 2025 Internet Crime Report)
  • The average wire transfer requested in a BEC attack was $50,297 in the fourth quarter of 2025. (APWG Phishing Activity Trends Report, Q4 2025)
  • 31% of breaches started with vulnerability exploitation and 48% involved a third party. Both are questions on every cyber application. (Verizon 2026 Data Breach Investigations Report)
  • 79% of ransomware attacks began with an identity-based approach, and 97% of victims whose credentials were stolen had MFA somewhere but not where it was needed. MFA is the first control on every underwriter’s list for the same reason. (Sophos 2026)

7. What the numbers say to do

  1. Put the controls the claims data points at first. BEC and funds transfer fraud are 58% of incidents: enforce MFA on email, require a call-back on every payment change, and run a phishing test to measure the click rate.
  2. Treat the application as a security review. Underwriters ask about MFA, backups, endpoint detection, patching, and whether the network has been tested. A penetration test report answers the last one with evidence, and the attestation letter that accompanies our reports (see the sample report) is written for exactly that reader.
  3. Know the retention and the gap. Insurance covered 69% of SME incident cost. The rest comes from the operating account; a $264,000 incident against a $25,000 retention is still a $25,000 unplanned expense before the uncovered items.
  4. Plan not to pay. The 86% refusal rate is what a rehearsed plan, tested backups and an incident response retainer look like in the data. An internal penetration test shows how far a ransomware operator gets, and how much of the plan is real.

For New York financial services companies, the same controls map to NYDFS Part 500, which regulators examine regardless of what the policy covers.

Sources

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation