5 ways hackers are targeting employers’ systems


Artificial intelligence is reshaping the cyber insurance landscape, according to Beazley’s latest Spotlight on Cyber Threats and Tech Advances 2026 report. The findings point to a rapidly changing threat environment where AI-powered attacks, ransomware innovation and expanding third-party vulnerabilities are driving new concerns for insurers and policyholders alike.

The report emphasizes that cybercriminals are increasingly leveraging AI to improve the effectiveness of phishing and impersonation attacks. These tools enable attackers to produce highly personalized messages and realistic fake communications, increasing the likelihood of successful fraud and credential theft.

See also: 9 principles to help HR leaders prepare for ransomware attacks

Ransomware also remains a dominant concern, though tactics are shifting. Threat actors are moving beyond operational disruption and focusing more heavily on data exfiltration and extortion. This evolution increases regulatory, legal and reputational exposures for insured organizations, particularly in sectors handling sensitive customer information.

Beazley also identifies supply chain vulnerabilities as a growing systemic risk. Organizations are increasingly dependent on outside technology providers, creating interconnected exposures that can impact multiple insureds simultaneously. This may prompt carriers to reevaluate accumulation risk and strengthen underwriting requirements related to vendor management and cybersecurity oversight.

Orgs with stronger cyber controls are seeing results from attacks by hackers

At the same time, the report offers signs of progress. Organizations adopting stronger cyber controls, including multifactor authentication, continuous monitoring, and formal incident response planning, are demonstrating greater resilience and faster recovery times following attacks.

The report underscores the need for cyber underwriting models that evolve alongside the threat landscape. As AI continues to influence both attackers and defenders, organizations that combine robust risk assessment with proactive client engagement will be better positioned to manage emerging cyber exposures.

Here are the five tactics Beazley identified cyber criminals use most frequently to gain access to systems.

Social engineering

Q3 2025: 6% of attacks

Q4 2025: 7% of attacks

Supply chain attack

Q3 2025: 8% of attacks

Q4 2025: 4% of attacks

Compromised credentials via RDS

Q3 2025: 6% of attacks

Q4 2025: 4% of attacks

External service exploit

Q3 2025: 23% of attacks

Q4 2025: 32% of attacks

Compromised credentials via VPN

Q3 2025: 48% of attacks

Q4 2025: 54% of attacks



We will be happy to hear your thoughts

Leave a reply

Daily Deals
Logo
Compare items
  • Total (0)
Compare
0
Shopping cart