At-Bay

33 stats2 reports

All Statistics

The single largest fraud loss in 2025 hit $9.7M.

Financial FraudFraud LossCyber ClaimCyber Insurance

Claim frequency rose 7% year-over-year to the highest rate At-Bay has recorded since 2021.

Cyber InsuranceCyber Claim

Akira, a Ransomware-as-a-Service operation that has run since 2023, drove a 53% increase in ransomware frequency in the second half of 2025.

RansomwareRaaSAkiraCyber ClaimCyber Insurance

The average ransom demand was $957K, and the average ransom paid was $317K. This means the price was often negotiated down by more than half.

RansomwareRansom

Ransomware attacks increased by nearly 20% in 2024.

Ransomware

4 of 5 (83%) financial fraud claims began with email.

Financial fraudClaimCyber insuranceEmailInitial access

Akira accounted for more than 40% of all ransomware claims in At-Bay’s portfolio for the full year.

RansomwareRaaSAkiraCyber Claim

Average claim severity climbed to an all-time high of $221K.

Cyber InsuranceCyber ClaimClaim Severity

The average amount stolen reached $285K, up 16% from the prior year and up significantly from $199K in 2023.

Financial FraudCyber ClaimCyber Insurance

86% of Akira attacks occurred in environments where a SonicWall device was present.

RansomwareRaaSAkiraSonicWallCyber Claim

The largest single business interruption claim hit $5M, the policy limit.

RansomwareBusiness InteruptionCyber ClaimCyber Insurance

Roughly one in 10 ransomware incidents caused downtime exceeding 30 days.

RansomwareBusiness InteruptionDowntimeCyber ClaimCyber Insurance

Companies with under $25M in revenue saw a 26% increase in average claim severity, the steepest jump of any segment and part of a three-year upward trend.

Cyber InsuranceCyber ClaimClaim Severity

Akira ransom demands averaged $1.2M, which is 50% higher than the non-Akira average.

RansomwareRaaSAkiraRansomCyber Claim

Two-thirds of Akira attacks in 2025 occurred on nights or weekends.

RansomwareRaaSAkiraCyber ClaimCyber Insurance

In 2025, one in three ransomware claims triggered business interruption coverage.

RansomwareBusiness InteruptionCyber ClaimCyber Insurance

Ransomware claims that triggered business interruption coverage averaged $510K in severity, compared to $168K for ransomware claims without business interruption.

RansomwareBusiness InteruptionCyber ClaimCyber Insurance

Financial fraud was the most common incident type for the third consecutive year, accounting for 30% of all claims.

Financial FraudCyber ClaimCyber Insurance

Third-party liability claims jumped 70% in 2025.

Third-party LiabilityCyber ClaimCyber Insurance

The blast radius of ransomware continues to grow as businesses impacted by attacks on vendors and partners increased 43%.

RansomwareThird-party attackVendorPartner

The average cost of third-party ransomware incidents jumped by 72% to $241K.

RansomwareThird-party attack

VPNs alone accounted for two-thirds (66%) of all ransomware attacks.

RansomwareVPN

Close to 50 ransomware groups were implicated in attacks in 2024, a 3X increase from 2021.

RansomwareRansomware group

The vast majority of ransomware started with an attack on a remote access tool, contributing to 80% of attacks.

RansomwareRemote access toolRemote access

Mid-sized companies generating $25-100M in revenue saw a 46% increase in ransomware attacks.

RansomwareMid-sized companies

Severity of ransomware attacks was up 13% in 2024.

Ransomware

Only 31% of ransoms were paid by At-Bay customers in 2024. This totaled $146M in unpaid ransoms.

RansomwareRansom

Financial fraud remained the most common incident type, accounting for 32% of all claims.

Financial fraudClaimCyber insurance

Overall claims frequency increased by 16% in 2024.

ClaimCyber insurance

Remote access tools like VPNs and RDP were correlated with 80% of ransomware attacks in 2024, up from 63% the year prior.

RansomwareRemote access toolsVPNsRDP

Supply chain-driven cyber claims were up 43%.

Supply chainCyber claim

The frequency of ransomware attacks in 2024 increased by 19% vs. 2023.

Ransomware

Email was the preferred entry vector for cybercriminals, driving 43% of claims.

EmailCyber attackAttack vectorInitial access