Most claims are not ransomware, they are misdirected payments
Event dated 19 May 2026 · Published 2 September 2026 · 3 sources
Claims data is unusually trustworthy by the standards of this field. Almost every widely quoted security figure comes from a survey, a vendor's telemetry or a self-assessment, and this site has spent several pages on figures whose original question cannot be recovered.
A claim is different. Somebody lost money, filed for it, and an organisation with a direct financial interest in disputing the account examined it. The resulting numbers are narrow — they only describe insured losses reported by insured organisations — but within that boundary they were checked by a sceptic.
Two ways of counting, two different answers
Ransomware leads on severity and payment fraud leads on frequency, so the honest summary depends on which question is being asked. Where does the largest single loss come from? Ransomware. What is most likely to happen to your organisation this year? A member of staff sending a payment to an account controlled by somebody else.
Security budgets are set almost entirely against the first question. The spending pattern follows the headline rather than the frequency, and the frequency is where most organisations will actually meet the problem.
Why it is barely a security incident
In the ordinary case there is nothing for a security tool to detect. An email arrives — frequently from a genuine, compromised account at a genuine supplier — mentioning changed bank details. The finance team updates the record and pays the next invoice. Every system involved behaved correctly.
Which is why it sits awkwardly in most organisations. The loss is financial, the control is a payment process, and the incident lands with a security team whose tooling has nothing to say about it.
The control that works, and its cost
Out-of-band verification of any change to payment details, using a number held on file rather than one supplied in the message. It is unglamorous, it slows down a genuine supplier's legitimate change, and it defeats the majority category by volume in a way no detection product does.
The reason it is not universal is the friction, and the reason to accept the friction is on the claims sheet. Three in five claims arriving from one mechanism is a strong argument for a process step that stops that mechanism, even when the step is annoying every single time it runs.