Coalition Cyber Claims 2024–2026: What Changed?
Coalition's 2024, 2025 and 2026 Cyber Claims Reports show shifting claim frequency, rebounding ransom demands, a move to dual extortion, and persistent email-based fraud. Here is what changed across the three editions.

Coalition’s 2024, 2025 and 2026 Cyber Claims Reports show a cyber claims environment that is volatile year to year but surprisingly consistent in its underlying drivers. Email-based attacks remain the largest source of claim volume, ransomware remains the most financially severe major event type, and exposed remote-access and boundary technologies continue to create outsized risk.
The editions also show meaningful changes. Claims frequency rose in 2023, fell in 2024, and rose again in 2025. Funds transfer fraud became less severe after its 2023 peak. Ransomware demands fell in 2024 before rebounding sharply in 2025, even as fewer victims paid. Third-party loss became a prominent issue in the 2025 report, while the 2026 edition shifted more attention toward data exfiltration, internet-facing infrastructure, privacy allegations, and the mechanics of initial access.
This comparison is most useful for CISOs, security leaders, risk teams, brokers, cyber insurance professionals, incident response teams, and researchers who want to understand what changed across three annual editions rather than reading each report in isolation.
A methodological caution matters throughout: Coalition changed geographic scope and refined its claims criteria over these editions, and it states that historical figures may be revised when newer methodology is applied retroactively. The safest comparison is therefore to focus on the direction of change and each edition’s own year-over-year findings rather than assume every absolute number published in an earlier edition remains directly comparable with later figures.
Short answer
Coalition’s three reports show that the main cyber claim drivers did not disappear between 2023 and 2025; instead, their frequency, severity, and tactics shifted. Email-based attacks remained dominant, ransomware remained costly, and exposed remote-access infrastructure remained a recurring source of risk. Several 2024 expectations were broadly confirmed, including persistent BEC and FTF pressure and continued exploitation of boundary devices, although BEC frequency eventually rose in 2025 and FTF frequency began to decline. The clearest change by 2026 is that ransomware had become more centered on data exfiltration and dual extortion, while ransom demands rebounded even as most victims refused to pay.
What this report series covers
Coalition’s Cyber Claims Report series analyzes claims reported by its policyholders and uses those claims to describe how often different cyber events occur, how costly they are, and which technologies or behaviors appear associated with higher risk.
The 2024 edition is based on claims reported from January through December 2023 and focuses on organizations in the United States. Its main topics include overall claim frequency and severity, business email compromise (BEC), funds transfer fraud (FTF), ransomware, boundary devices, Remote Desktop Protocol (RDP), and third-party compromise.
The 2025 edition analyzes claims from 2024 and expands the geographic scope to Coalition policyholders in the United States, Canada, the United Kingdom, and Australia. It also adds more structured analysis by industry and revenue segment, and introduces miscellaneous first-party loss and third-party allegations as dedicated event categories.
The 2026 edition analyzes claims from 2025 across the United States, Canada, the United Kingdom, Australia, and Germany. It adds more detail on ransomware tactics, targeted technologies, initial access vectors, FTF pathways, privacy-rights allegations, and the distinction between encryption, exfiltration, and dual extortion.
The 2026 methodology also narrows the analyzed population to higher-signal claims with realized financial loss and raises the minimum gross-loss threshold from $10 to $100. Coalition says this threshold was applied retroactively to historical data, which can marginally reduce historical frequency and increase historical severity compared with figures published in prior editions.
What changed across editions?
Overall claims moved from increase, to decline, to renewed growth
The 2024 report described 2023 as a year of rising claims. Overall claims frequency increased 13% year over year and overall severity increased 10% to an average loss of about $100,000.
The 2025 report then showed a reversal in frequency. Global claims frequency decreased 7% in 2024 to 1.48%, while global severity was described as stable at an average loss of $115,000.
The 2026 report showed frequency turning upward again. Global claims frequency increased 3% in 2025 to 1.54%, while claims severity decreased 19% to an average loss of $116,000 under the latest report’s methodology.
Taken together, the series does not support a simple narrative of continuously worsening or continuously improving claims. Frequency moved in both directions, and Coalition’s latest interpretation is that attacks remained persistent while policyholders became more effective at limiting the financial impact of individual incidents.
Because Coalition revised historical figures and expanded geographic coverage, the absolute severity numbers should not be treated as a clean three-year time series. The direction stated within each edition is more reliable for comparison.
Email-based attacks remained the most persistent source of claims
The strongest continuity across the three editions is the importance of email-based attacks.
In the 2024 report, more than half of all claims were BEC or FTF. The 2025 report said BEC and FTF together accounted for 60% of claims in 2024. The 2026 report put their combined share at 58% in 2025.
This means the mix barely changed at the highest level. Even as ransomware tactics and third-party events evolved, compromised communications, impersonation, social engineering, and fraudulent payments remained central to Coalition’s claims experience.
The relationship between BEC and FTF also became clearer over time. In 2024, Coalition emphasized that compromised inboxes frequently become a path to fraudulent payments. The 2025 report quantified this further, stating that 29% of BEC events resulted in FTF. The 2026 report approached the relationship from the opposite direction: 52% of FTF claims originated from a BEC event.
The 2026 report also shows that email compromise is not the only path to payment fraud. It says 71% of FTF claims resulted from social engineering, while 20% involved fraudulent instructions sent directly to banks.
BEC was stable, then became more frequent
The 2024 report said BEC frequency had been relatively stable over time and was likely to remain so. Its severity decreased 15% year over year to more than $26,000.
The 2025 report largely confirmed the frequency prediction for the following year. BEC frequency remained unchanged in 2024 at 0.44%, close to its three-year average, although severity increased 23% to an average loss of $35,000.
The 2026 report shows where that stability ended. BEC frequency rose 15% in 2025 to 0.47%, driven largely by increased activity in the second half of the year. At the same time, severity decreased 28% to an average loss of $27,000.
So the 2024 expectation of stable BEC frequency was supported in the next edition, but not indefinitely. The 2026 data suggests BEC remained structurally persistent and became more common again, even while its average financial impact fell.
FTF severity fell sharply after the 2023 peak
The 2024 report described FTF as a persistent, relatively stable threat. Frequency increased 15% in 2023, while initial severity increased 24% to more than $278,000. Coalition expected FTF frequency to continue hovering around its existing level.
The 2025 report partly confirmed that expectation. FTF frequency decreased only 2% in 2024 to 0.44%, which Coalition described as close to its three-year average. More importantly, initial severity fell 46% to $185,000 after an all-time high in 2023. Coalition linked the decline partly to fewer very large transfer attempts and greater intervention by financial institutions.
The 2026 report shows the trend continuing, but with a more meaningful frequency decline. FTF frequency decreased 18% in 2025 to 0.42%, while severity decreased 14% to an average loss of $141,000.
This means the 2024 expectation of roughly stable frequency held for one year but weakened in 2025. The more durable trend across the later editions is lower average FTF loss severity after the 2023 peak.
Recovery remained an important counterweight. Coalition reported $38 million in FTF recoveries in 2023, $31 million in 2024, and $21.8 million in 2025. These totals are not a direct measure of fraud prevalence because they also depend on claim mix, reporting speed, jurisdiction, and recovery opportunities. The later reports continue to emphasize that rapid reporting materially improves the chance of recovering stolen funds.
Ransomware declined in some measures, but the threat did not recede
The ransomware story is the clearest example of why year-over-year declines should not be mistaken for structural disappearance.
The 2024 report showed ransomware frequency increasing 15% in 2023 and severity increasing 28%, with an average loss of more than $263,000 under that edition’s reported figures. Average ransom demands rose 36% to nearly $1.4 million. However, the second half of 2023 was less severe than the first, leading Coalition to warn against interpreting the decline as the defeat of ransomware.
The 2025 report appeared to extend the improvement. Ransomware frequency decreased 3% in 2024, severity decreased 7% to $292,000, and average ransom demands fell 22% to $1.1 million. The proportion of affected policyholders that chose to pay was 44%, and Coalition reported an average 60% reduction in payments through negotiation.
The 2026 report confirms that the previous decline in demands was temporary. Ransomware frequency was flat in 2025 at 0.32%, and severity decreased 19% to an average loss of $262,000, but average ransom demands surged 47% to more than $1 million under the latest edition’s measurement. Only 14% of victims chose to pay, meaning 86% refused.
The 2024 report’s broader prediction — that attackers would remain persistent and pivot tactics because the financial incentive was too strong to abandon — is therefore supported by the later editions. Ransomware did not disappear. Instead, its economics and leverage changed.
Ransomware evolved from encryption toward dual extortion
The 2026 report provides the clearest evidence of tactical change.
Encryption-only attacks represented 15% of ransomware claims in 2025, with an average loss of $138,000. Exfiltration-only incidents also represented 15%, with an average loss of $205,000. The dominant model was dual extortion: 70% of ransomware claims involved both encryption and data exfiltration, with an average loss of $299,000.
This development helps explain why better backups can reduce the leverage of encryption without eliminating ransomware risk. A business may restore systems without paying for a decryptor, but stolen data can still create legal, regulatory, notification, and reputational costs.
Compared with the 2024 report, ransomware in the 2026 edition looks less like a single encryption problem and more like a combined operational and data-risk event.
Boundary-device risk in 2024 became a broader initial-access story by 2026
The 2024 report devoted substantial attention to boundary devices and exposed remote access. Businesses with internet-exposed Cisco ASA devices were nearly five times more likely to experience a claim, businesses with internet-exposed Fortinet devices were twice as likely, and organizations with exposed RDP were 2.5 times more likely to experience a claim.
The 2026 report strongly reinforces that concern. VPNs were the primary targeted technology in ransomware incidents where forensic investigators confirmed a technology, accounting for 59% of those incidents. Remote desktop applications represented another 14% of exploited technologies.
The most frequently targeted perimeter vendors listed in the 2026 report were SonicWall, Fortinet, Cisco, Citrix, and Palo Alto Networks. Software exploits were the most common confirmed ransomware attack vector at 38%, followed by compromised credentials at 27%.
The continuity is notable. The exact products and proportions changed, but the 2024 warning about internet-facing boundary and remote-access technology was not a one-year anomaly. By 2026, Coalition was presenting perimeter appliances, VPNs, remote desktop services, patching, and MFA as central parts of the ransomware initial-access problem.
Third-party risk surged into focus, then became more differentiated
The 2024 report highlighted MOVEit as a major third-party compromise issue and noted that incidents continued well after the initial vulnerability disclosure.
The 2025 report broadened this into a larger third-party dependency problem. Third-party breaches accounted for 52% of miscellaneous first-party loss events in 2024. Coalition highlighted the Change Healthcare and CDK Global incidents as risk-aggregation events that created losses for policyholders whose own systems were not necessarily the original point of compromise.
The 2026 report still treats third-party dependency as important, but the share changed substantially: third-party breaches represented 15% of miscellaneous first-party loss events in 2025, with an average loss of about $30,000. It also added third-party account compromise as a separate form of loss.
This suggests third-party risk remained relevant but was less dominant in 2025 than in 2024. The comparison should be read cautiously because the later edition provides a more granular taxonomy and uses refined claims criteria.
Privacy and external liability became more visible in 2026
The 2025 report introduced third-party allegations as a dedicated category and described them as claims involving privacy, security, intellectual property, and other external liabilities.
The 2026 report develops this area substantially. Security failure or data breach allegations accounted for 32% of third-party allegations, privacy rights violations 20%, and intellectual property infringement 15%. The report also highlights web-tracking-related claims, including allegations citing the California Invasion of Privacy Act, Meta Pixel, and the Telephone Consumer Protection Act.
This is one of the clearest expansions in scope across the series. The 2024 edition is primarily centered on attack-driven insurance losses. By 2026, Coalition is giving more attention to the legal and regulatory costs that can follow digital data practices even when the event is not a conventional cyberattack.
Trends and predictions: what was confirmed?
Confirmed: BEC and FTF remained mainstays of the claims mix
The 2024 report said the easy-to-execute nature of FTF and BEC made them mainstays of the cybercrime economy. The next two editions support that view.
BEC and FTF represented 60% of claims in 2024 and 58% in 2025. Their individual frequencies changed, but together they remained the dominant claim category.
Assessment: Confirmed.
Partly confirmed: BEC frequency would remain stable
The 2024 report anticipated continued stability in BEC frequency.
The 2025 report confirmed that in the immediate next year, with BEC frequency unchanged at 0.44%. The 2026 report then recorded a 15% increase to 0.47%.
Assessment: Confirmed for 2024, but not as a longer-term trend.
Partly confirmed: FTF frequency would hover near its existing level
The 2024 report expected FTF frequency to remain around its current level.
The 2025 edition was consistent with that view, reporting only a 2% decline to 0.44%. The 2026 edition then reported an 18% decline to 0.42%.
Assessment: Broadly confirmed in the next edition, but weakened by the 2025 claims data.
Confirmed: ransomware would remain persistent and attackers would pivot
The 2024 report explicitly warned that a second-half decline in ransomware did not mean the problem had been defeated and said threat actors would continue to adapt.
The next editions support this. Ransomware remained around one-fifth of claims, frequency stabilized rather than collapsing, dual extortion became dominant, and ransom demands rebounded sharply in 2025.
Assessment: Confirmed.
Confirmed: exposed boundary and remote-access technologies would remain high-risk
The 2024 report connected exposed Cisco ASA, Fortinet, and RDP technologies with higher relative claim frequency.
The 2026 edition again places perimeter appliances, VPNs, remote desktop applications, software exploits, and compromised credentials at the center of ransomware initial access.
Assessment: Strongly confirmed.
Not sustained: the 2024 decline in ransom demands
The 2025 report showed a 22% fall in ransom demands during 2024.
The 2026 report then showed a 47% increase in 2025.
Assessment: Not sustained. The decline was a one-year movement rather than evidence of a durable reduction in attacker demands.
Themes that became more prominent
Cyber Risk & Resilience
This theme became more explicit across the editions. The 2024 report focused on risk reduction through security controls and active engagement, while the 2026 report frames the core problem as operational resilience and the ability to limit losses even when incident frequency rises.
Ransomware & Extortion
Ransomware was prominent in every edition, but the analysis became more sophisticated. By 2026, the report distinguishes encryption, exfiltration, and dual extortion and connects them to different loss profiles.
Vulnerability & Exposure Management
The 2024 focus on boundary devices develops into a much broader exposure-management story by 2026, including VPNs, remote desktop applications, internet-facing login panels, zero-day alerts, patching, and software exploits.
Identity, Phishing & Access Security
BEC, phishing, compromised credentials, and social engineering remain central throughout the series. The 2026 report adds more detail on bank impersonation, credential-based access, and the role of identity in ransomware initial access.
Software & Supply Chain Security
MOVEit in the 2024 report and Change Healthcare and CDK Global in the 2025 report make third-party technology dependencies increasingly visible. The 2026 report continues the theme through third-party breaches and compromised SaaS or cloud accounts.
Data Security & Privacy
This theme becomes much more prominent in the 2026 edition. Data exfiltration drives ransomware loss, while privacy-rights allegations and web-tracking practices create a separate source of legal exposure.
Cyber Insurance & Economics
All three editions analyze the financial consequences of cyber incidents, including claim frequency, severity, ransomware payments, funds recovery, business interruption, and the effect of risk management on insured losses.
Themes that remained consistent
Email-based fraud remained structurally important
BEC and FTF stayed near the top of the claims mix in every edition. Their internal balance changed, but the combined importance of email compromise, impersonation, and payment deception remained remarkably stable.
Ransomware remained the most severe recurring attack category
Even when ransomware frequency was lower than BEC or FTF, it continued to generate higher average losses and significant business interruption, forensic, restoration, legal, and extortion costs.
Fast response remained financially important
Across the series, Coalition repeatedly links rapid response to better outcomes. This is most visible in FTF clawbacks and ransomware negotiation, where reporting and intervention speed can affect recoveries and final payments.
Security controls remained central to claim prevention
The reports consistently emphasize MFA, patching, monitoring, incident response, backups, managed detection and response, and reducing unnecessary internet exposure. The later editions add greater detail, but the core control priorities remain recognizable.
What this means for security teams
The three reports suggest that security teams should avoid interpreting a one-year decline in one metric as evidence that a threat has been solved. Ransomware demands fell and then rebounded. BEC frequency stayed flat and then increased. Overall claims frequency fell and then rose again.
For email and payment fraud, the practical lesson is that mailbox security alone is not enough. BEC can lead to FTF, but the 2026 report also shows fraud through spoofing, direct social engineering, bank impersonation, and compromised payment credentials. Payment verification processes therefore need to complement identity and email controls.
For ransomware, backups remain important but are no longer a complete answer. The dominance of dual extortion in the 2026 edition means organizations need to prepare for data theft, notification obligations, privacy exposure, and legal consequences as well as system restoration.
Exposure management deserves sustained attention. The recurrence of VPNs, boundary appliances, RDP, software exploits, and compromised credentials across multiple editions suggests that internet-facing infrastructure and remote access should be treated as continuously monitored attack paths rather than one-time hardening projects.
Third-party dependencies also need to be considered as operational risk, not only vendor-compliance risk. The 2025 report shows how attacks on major service providers can create business interruption and financial loss for organizations that were not directly compromised.
Finally, security leaders should interpret claims data with its methodology in mind. Coalition’s reports provide useful signals about its policyholder population, but the publisher explicitly states that its findings are not representative of all cyber incidents or all organizations.
Which edition should you read?
Coalition — 2024 Cyber Claims Report is the most useful of the three for understanding the 2023 surge in claims, the early warning around exposed boundary devices, the role of RDP, the MOVEit third-party event, and the relationship between ransomware volatility and ransom payment decisions.
Coalition — 2025 Cyber Claims Report is the best edition for understanding the relative stability of 2024, industry and revenue differences, the sharp drop in FTF initial severity, Change Healthcare and CDK Global as aggregation events, and the expansion into miscellaneous first-party loss and third-party allegations.
Coalition — 2026 Cyber Claims Report is the most useful current edition for understanding 2025 claims. It provides the deepest detail on ransomware tactics, exfiltration, initial access, targeted perimeter technologies, FTF pathways, privacy allegations, and the relationship between higher attack frequency and lower average loss severity.
For readers who want the latest view, the 2026 edition should take priority because Coalition applies its current methodology retroactively and recommends referencing its most recent report where possible. The 2024 and 2025 editions remain valuable for understanding what Coalition observed and expected at those points in time, especially when evaluating whether earlier trends persisted.
Reports mentioned in this article

Coalition — 2026 Cyber Claims Report
The 2026 Cyber Claims Report highlights the evolving cybersecurity landscape, emphasizing the Cyber Protection Paradox where increased cybersecurity spending does not necessarily equate to greater business safety. It explores trends in cyber threats, including business email compromise (BEC), funds transfer fraud (FTF), and ransomware, and discusses the effectiveness of defensive strategies and insurance solutions in mitigating financial losses.

Coalition — 2025 Cyber Claims Report
The 2025 Cyber Claims Report by Coalition provides an in-depth analysis of the cybersecurity landscape, focusing on trends in cyber claims frequency and severity, the impact of email-based attacks, and industry-specific risks. It highlights the effectiveness of Active Insurance in reducing claims and offers insights into the evolving threat landscape and risk mitigation strategies.

Coalition — 2024 Cyber Claims Report
The 2024 Cyber Claims Report highlights the evolving landscape of cybercrime, with increased frequency and severity of claims across various sectors. It emphasizes the role of boundary devices, ransomware, and funds transfer fraud (FTF) as significant threats. The report also showcases Coalition's efforts in mitigating risks through proactive measures, incident response, and clawback mechanisms.
