In May 2026, Singapore police released footage of a fake Zoom meeting featuring AI-generated images of senior government officials, part of a financial scam that cost one victim at least S$4.9m. It was not an isolated incident.
Across Asia-Pacific, publicly disclosed ransomware attacks rose 59% year on year in 2025, with East and Southeast Asia recording a 71% increase, the highest growth rate globally. The region has moved from being a secondary target for cybercriminals to one of their most active markets.
What connects these figures is not simply that cyberattacks are becoming more frequent. It is that artificial intelligence is starting to erode the assumptions on which cyber and crime insurance were built.
Take social engineering fraud. Every version of policies that cover against this share one premise: that the victim is a human being who can be deceived (what systems operators colloquially refer to as PEBKAC – problem exists between keyboard and chair). It is essentially a problem that no piece of technology can definitively solve. The worrying bit is that AI is dismantling that premise from two directions at once.
On one side, it supercharges fraud attempts that most insurance policies already anticipate: voice and video cloning now let attackers impersonate named executives convincingly enough to defeat the very call-back verification insurers require.
On the other, it creates new types of attacks that escape the trigger entirely. Injection attacks that feed fabricated biometric data directly into authentication software deceive no human at all, leaving insurers to ask whether processing false data counts as unauthorised access in the first place.
The second thread is speed. The rise of agentic AI, systems capable of independent reasoning and autonomous execution, are letting cybercriminals manage an entire attack lifecycle with minimal human input. The result is a widening gap between attackers operating at machine speed and organisations still responding at human speed.
Ransomware has not stood still either, accounting for 64% of incident response cases in the region last year, well above the 45% global average, with threat actors increasingly using data theft and regulatory exposure as extortion leverage rather than encryption alone.
The third thread, and arguably the one that should concern the industry most, is accumulation. A single deepfake toolkit or a shared biometric-vendor vulnerability can trigger correlated losses across many insureds simultaneously, importing the “silent cyber” problem into fraud lines that were priced on the assumption of independent, idiosyncratic losses.
The systemic risk is less of a single worldwide cyber incident (such as the infamous WannaCry from 2017) and more of a series of interconnected events, a vulnerability in a dominant cloud platform or identity provider capable of generating losses across countries, industries and insurers all at once.
But as Douglas Adams wisely said: don’t panic. Insurers need to look at rescoping coverage before the claims arrive rather than after, to widen triggers to capture deception of automated and biometric systems, as well as people, and treating cyber resilience as a continuous discipline rather than a policy reviewed once a year.
The next wave of cyber risk in Asia-Pacific will not wait for wordings to catch up. A
Ahmad Zaki
Editorial Director
Asia Insurance Review