Skip to main content

Report

Global Cyber Claims Report

The defining trend for global cyber claims in 2025 was complexity

While some regions recorded slightly fewer notifications year-over-year, and a large number of correlated events in mid-2024 affected the comparison, adjusted totals for 2024 and 2025 are broadly comparable. More notable is how incidents now combine multiple loss drivers — privacy exposure, extortion, prolonged business interruption, third-party failure, and litigation — within single events. These multi-vector incidents produce larger, more legally complex, and longer-running claims. 

The practical implication is that cyber resilience must be enterprise-wide, integrating security, privacy, vendor governance, legal, crisis management, and insurance design, and must be built to manage high-severity, aggregation-driven events rather than only to reduce incident counts.

Context and high-level trends

A modest year-over-year dip in some regions masked persistent high activity: much of the apparent decline results from normalising for a cluster of correlated events in 2024. 

The graph above covers the last five years of claims volume. For privacy reasons, we have indexed the volume to a baseline of 2021 levels = 100, allowing for normalised year-over-year comparisons.

In the following graph, we have identified correlated events in 2024. When these are removed, it shows that 2024 attritional levels were roughly on a par with 2025.

Cyber claims are evolving

Contemporary claims increasingly combine privacy liabilities, business interruption, third‑party impacts, regulatory action, and extortion, multiplying cost drivers, litigation risk, and recovery timelines.

Even in regions where notification volumes declined, incidents tended towards the more severe and legally complex. Losses increasingly reflect operational disruption, data misuse, regulatory scrutiny, extortion dynamics, and dependencies on external vendors. 

Organisations may want to evaluate both frequency and aggregation risk across ecosystems and geographies, recognising that a single technical compromise can cascade into multiple forms of exposure.

Our taxonomy

Several years ago, we worked to build and deploy an internal taxonomy to help clarify the emerging complexity we saw in claims. Collecting information within this structure allows us to more precisely describe both the causes and effects of events impacting our clients. 

In this report, we break down claims along three main axes:

This section focuses on gathering data about the origins of the event. This generally breaks down into the following sources:

  • External actor - any person, organisation, or system outside the organisation’s control boundary that can interact with or impact its technology, data, or services
  • Insider - a person with legitimate authorised access to the organisation’s systems or data who may intentionally or unintentionally cause harm
  • Third party - a non-employee external entity that provides services or has a business relationship with the organisation and may access, process, host, or otherwise affect its systems or data

This section intends to capture the details of the event that apply to the cyber infrastructure — the “how” of the event. Notably, this is separate from the effects of the event, which is covered under business events. These do not need to be mutually exclusive; often multiple cyber events occur in a given claim.

  • Network breach - the majority of cases and what one typically thinks of as a cyberattack
  • Error/misconfiguration - non-malicious “mistakes” made in digital infrastructure
  • Non-breach impersonation (fraud and pure social engineering, generally used in funds transfer fraud) - impersonation activities that do not require or include a breach of network assets
  • System degradation - DDoS attacks, resource hijacking, and other behaviours that include the degradation of services
  • Interception/passive collection - generally, when first- or third-party companies collect information that may put them at risk

This section is where we aim to capture the effects on the business of an event. This allows us to model and label cyber events regardless of their effects. Examples of business event data include, among others:

  • Extortion - the “ransom” part of ransomware and other activities that seek to exploit leverage
  • Privacy breach - the impacts associated with exposure or mishandling of private information (note that breaching privacy does not require a network breach)
  • Litigation - the effects associated with actual or threatened legal action (including defence costs, settlements, and judgments) arising from the event
  • Regulatory fines - monetary penalties, sanctions, or mandated remediation imposed by regulators for non-compliance
  • Asset degradation - the financial impact of damaged assets
  • Reputational harm - the damage to trust and brand perception resulting from the event
  • Liability - the legal responsibility to compensate others for losses (customers, third parties, contractual counterparties) associated with the event

These terms are used throughout the report and combined in various forms. At times, we may group them for simplicity and display purposes (for example, privacy impacts includes things such as litigation, regulatory action, and privacy breach business events).

2025 key trends

selected option

Extortion claims severity is rising even as claims numbers fall  

Despite decreasing extortion claims volumes since 2023, average claim severity has risen over the last two years as threat actors pivot from encryption‑only extortion to monetising access through exfiltration, leak threats, and disruptive tactics. 

Incident response and coverage design must therefore address data theft and public disclosure scenarios in addition to system restoration and decryption. Organisations also should be prepared for complex stakeholder communications and regulatory exposures tied to disclosure.

Non-malicious incidents can have outsize impacts

Incidents arising not from attacks, but from errors and passive/wrongful collection of data continue to rise in prominence, and hold an increasing share of claims activity. Notably, 2024 and 2025 continued to see a general increase in non-malicious events claims.

Insider and third-party risks are more prominent

While external actors remain the biggest source of activity, insider and third-party threats continue to grow in prominence, similarly leading to a complex set of outcomes. Below we break down the business events stemming from these sources of activity.

Severity distributions are skewing higher

Median severity values have largely remained stable year over year, but we are observing an expansion of the higher end of claims — the 75th percentile shown in the below graphic. This shows where the distribution of outcomes is becoming more skewed towards the tail or rather, where the “worst case scenarios” are getting worse. 

Business interruption, unsurprisingly, leads the pack, but litigation and liability additionally appear in our top 5 severity risks, as the privacy landscape continues to evolve. Some of the biggest claims in 2025 were — perhaps surprisingly — driven by privacy litigation, not extortion. Even in many cases where extortion-related costs were high, it is generally not ransom payments, but rather other breach-related costs that contribute to the severity.

For business interruption, the 75th percentile loss is 63.53x the median loss, meaning a higher-severity (top 25%) BI claim is typically more than sixty times larger than the median claim.

Industry breakdown

Claims were widely spread across industries in 2025, but several key industries remain near the top as in previous years. Below is the breakdown of the top ten industries by 2025 claims volume, and a breakdown of the specific risk areas present in the top four.

Breakdowns

Communications, media, and technology companies often rely on complex supply chains, with many third parties involved that could be compromised. By nature of these industries, they also handle high levels of intellectual property, making them a key target for bad actors.   

While several of these risk areas are not new, attention should be paid to interception and passive collection leading to privacy breaches. This industry sector has particular exposure to risks pertaining to digital record collection and processing.

This graphic shows which cyber event patterns are most strongly associated with each business event type in this sector. The heatmap suggests that:

  • A network breach is a relatively likely driver of privacy breach events, for example when attackers access internal systems and extract sensitive or personal data.
  • A network breach is also a relatively likely pathway to cyber extortion.
  • System degradation is a relatively likely driver of business interruption impact.

Privacy is everything in healthcare, and the heatmap below demonstrates it. Nearly all cyber events, save for impersonation (fraud) cause privacy breach impacts in this sector. Additionally, impersonation leading to fraudulent funds transfer was prevalent.

Highly sensitive data, connections, and data processing by third-party providers are increasing attack surfaces and placing critical infrastructure under attack (including disruption-oriented ones such as DDoS attacks).

Manufacturing is — unfortunately — emerging as an increasingly targeted industry for a number of threat actors. Ransomware actors may see the manufacturing sector as an area where they can gain leverage to motivate payments. Geopolitical tensions have increasingly put manufacturing and other OT-heavy industries in the spotlight of cyber risk. Additionally, the increasingly complex and digitised supply chain adds further complexity to the risks in this sector.

Artificial intelligence (AI) layers into classes of cyber risk

In 2025, we collected a handful of claims that mentioned AI, either as an affected service, a third-party source, or other mention in the nature of the claim. However, AI is not becoming a new class of risk, but rather fits into existing classes we already track. 

Currently, those risk classes appear to be:

  • Errors and misconfigurations – This is perhaps the most exigent area where AI risk currently looms. As organisations race to deploy and reap the rewards of AI, mistakes and blind spots occur. Additionally, third-party services and suppliers may roll AI-enabled services into their platforms, introducing new risk without explicit knowledge of downstream effects.
  • Non-breach impersonation – The first frontier of attacker AI usage has been an increase in both the volume and quality of social engineering. This leads to more convincing lures and a growing financial fraud industry. So much so that Marsh — along with key partners across the financial, cybersecurity, and retail sectors — has been working as part of the Fight Financial Fraud MITRE initiative to improve reporting and defences against this increasing threat.
  • Network breaches – Developments in early 2026 have indicated this may be the year where AI-driven network breaches truly arrive. Whether or not that occurs at scale, it is already true that AI has lowered the bar for attack expertise, and provided tools for attackers to scale. Given an expected increase in volume of attempts, it is all the more important for organisations to build resilience into their cybersecurity programmes. Security through obscurity is not a winning strategy in an AI-scaled adversary environment.

Conclusions and looking ahead

2025 showed a clear shift: incidents became more complex and costly. Many claims combined privacy exposure, extortion, prolonged business interruption, and litigation within single events, driving larger, lengthier, and more complex losses. Non-malicious incidents (errors, misconfigurations, and passive data collection) and non-breach privacy actions grew in prominence, while extortion evolved from encryption to data theft and leak strategies that inflate downstream costs. The tail of severity expanded: median losses held steady, but the 75th percentile and above accounted for a larger share of total cost.

In 2026, expect more of the same, amplified. Aggregation-driven events will remain the principal danger as interdependent supply chains and third-party services spread impact across sectors and geographies. Privacy litigation and regulatory scrutiny are likely to increase, particularly around non-breach data practices. Extortion will continue to monetise exfiltration and reputation risk rather than simply encryption-based payments. AI will raise the baseline risk by lowering attackers’ entry costs and introducing new error modes in deployments and vendor services, while also improving the scale and plausibility of social engineering campaigns. 

As cyber losses become more complex and severe, organisations should reassess whether insurance limits remain adequate for today’s risk environment, especially given the potential for multi-faceted and high-severity claims. Incident and claims preparedness should also be a priority, including maintaining access to out-of-band communications, such as Marsh Central, and clear response protocols. Regular tabletop exercises, whether in person or facilitated through digital tools, such as Marsh Central, can help teams respond more effectively under pressure. Organisations should also review and actively manage third-party dependencies, while staying current on evolving privacy requirements and enforcement trends.

Interested in finding out more?

Fill in the form to speak with a Marsh representative.