09/30/2026 | Press release | Archived content
Cybercriminals are using artificial intelligence to sharpen the same tricks they've always relied on, making fake payment requests more convincing and helping them move faster once they're inside. The claims that follow still start in familiar places: a changed invoice or a password that was easy to guess. And some claims involve no cybercriminal at all. Last year brought a notable rise in claims over the tracking tools on businesses' own websites.1
Most small and midsize businesses have already implemented the protection they need: 86.8% have multifactor authentication in place, the extra verification step after a password, and 88.4% keep backups of their data. However, only 51.1% require that extra step on all their key business accounts, and only 61.4% have tested a backup to confirm it restores.2
Those gaps are where losses happen. A control that covers most of a business leaves the rest standing open, and the openings cybercriminals use are ordinary ones. Ordinary is good news, because ordinary openings are the easiest to address. Three of those doors show up repeatedly in claims data.
The most common cyber loss for a business this size doesn't involve breaking into anything. Someone simply gets into an email account and reads.
Business email compromise and funds transfer fraud together accounted for 58% of all cyber claims last year.3 More than half of the funds transfer cases, 52%, began in a compromised inbox.4 And 71% came down to social engineering, where a person is persuaded to move money on instructions that look legitimate, usually under time pressure.5
Coalition's claims data describes one case in detail: A property management company received updated payment instructions inside a live email thread with a client. Four payments went out, totaling $539,000. The attacker had altered a single character in the client's email address, and had been sitting inside the mailbox for two months, implementing inbox rules that redirected replies so nobody noticed the thread had a third participant.6
Fortunately, its cyber insurance went to work. By working with the company's payment processor, the claims team recovered $290,000 of the stolen funds. The company met the first $25,000 itself, and its funds transfer fraud coverage paid the remaining $224,000.7 A $539,000 loss cost that business $25,000.
Closing the door: verify every change in payment details by phone, and never through contact information supplied in the email itself.
An attacker holding a working password has no need for malware and sets off no alarms. From the inside, the login looks like an employee arriving at work. In CrowdStrike's 2026 global threat data, 82% of detections involved no malware at all, because the intruders arrived through valid credentials and the same tools staff use every day.8
Passwords are guessed more often than business owners assume. Automated software tests thousands of combinations every second, and length is what defeats it. An eight-character password falls in seconds no matter how many symbols it holds, while a complex 16-character password would take billions of years.9
Passwords and identity verification are doors many businesses have already started closing. More than a third of small and midsize businesses, 35.7%, require that extra verification step on only some of their accounts.10 Unfortunately, an account left outside that requirement is the easiest for an attacker to find.
Closing the door: turn the extra verification step on everywhere it's offered, starting with email and remote access. Then move passwords into a password manager, which makes a 16-character password cost nothing to remember.
The third door involves no cybercriminal at all.
Most business websites run tools the owner stopped considering after setup: an advertising pixel, an analytics script, a chat widget. Each one can collect information about the people who visit. When the site's privacy policy doesn't describe what those tools do, that gap has become the basis for a legal claim.
In Coalition's analysis of privacy claims, 77% of wrongful collection claims arose from activity on a business's own website. The claimants are remarkably concentrated. Out of more than 400,000 law firms in the United States, four of them represented the claimants in 72% of all web privacy claims, usually through templated demand letters aimed at a quick settlement before any lawsuit is filed.11
Website scans in the same study show how wide the gap is. Only 19% of websites deploy a consent banner. Only 29% of privacy policies named the specific tracking technology running on the site, and half carried a generic line about tracking instead. Among the lowest-traffic sites, only 37% had updated their privacy policy in the past year.12
However, there is reassurance in the same scans. Tracking tools cluster where the traffic is, and most of the lowest-traffic sites ran no tracking technology at all.13 If your site is simple, it may already be clean.
Closing the door: find out what's running on your website and make sure your privacy policy names it clearly. Then, talk to your agent. Cyber policies differ in how they treat privacy claims, and it's a specific question worth asking.
Owners hear constantly that cybercriminals are using AI. Far fewer have been told what it looks like on their own screen.
For example, fake CAPTCHA campaigns are surging. CrowdStrike recorded a 563% rise in incidents using fake versions of that prompt during 2025.14 The page looks routine, but the instruction that follows installs and executes malware. In the same data, attacks by adversaries using AI rose 89% year over year.15
According to IBM, more than one in four organizations that suffered a malicious attack reported it was driven by AI, a 56% increase over the previous year.16 Lagging AI governance also creates vulnerabilities. Among small and midsize businesses, 87.3% now use AI, while only 45.6% have written guidelines for how employees may use it.17 A short written policy naming the approved tools and the data that never goes into them is a practical first step toward closing that gap.
Cyber coverage varies more than most business policies, so the details are worth asking about directly. Five questions to bring to your Highstreet agent:
Coverage terms and availability vary. Talk to your local Highstreet agent for details.
One finding in this year's small business survey stands out: Businesses that have already been through a cyberattack are measurably better prepared than businesses that have not. Nearly three-quarters of breached companies have a documented incident response plan they follow, against 51.5% of companies that have never had an incident. That means companies with no incident behind them are five times more likely to have no plan at all.18
Everything those businesses learned the hard way is recognizable in advance. The doors we've discussed show up again and again in claims data and closing them can start with a phone call to your Highstreet agent. Our team is available to walk through your unique exposures. We'll help you find the openings in your business and the coverage that fits.
1 Coalition (2026). 2026 Cyber Claims Report.
2 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.
3 Coalition (2026). 2026 Cyber Claims Report.
4 Coalition (2026). 2026 Cyber Claims Report.
5 Coalition (2026). 2026 Cyber Claims Report.
6 Coalition (2026). 2026 Cyber Claims Report.
7 Coalition (2026). 2026 Cyber Claims Report.
8 CrowdStrike (2026). 2026 Global Threat Report.
9 National Cybersecurity Alliance (2026). Cybersecurity Awareness Month 2026 tip sheet.
10 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.
11 Coalition (2025). The State of Web Privacy.
12 Coalition (2025). The State of Web Privacy.
13 Coalition (2025). The State of Web Privacy.
14 CrowdStrike (2026). 2026 Global Threat Report.
15 CrowdStrike (2026). 2026 Global Threat Report.
16 IBM (2026). Cost of a Data Breach Report 2026.
17 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.
18 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.