Insurance
Home›Insurance›Health Insurance›Cyber insurers see higher frequency of wrongful data c…
Cyber insurers see higher frequency of wrongful data collection claims
Resilience data shows frequency rose to 45.9 claims per 100 policies in the first half of 2026, up from 40.5 in the prior six-month period.
Wrongful data collection claims are becoming a more frequent issue in cyber insurance, leading more carriers to add specific exclusions and raising questions about whether certain privacy allegations should be insurable, according to Insurance Business. The insurer said the growing focus on policy wording reflects how often businesses collect customer information via their websites, including for marketing and sales purposes.
Resilience reported that claim frequency across its portfolio climbed to 45.9 claims per 100 policies in the first half of 2026, up from 40.5 in the previous six-month period. The insurer attributed much of the increase to wrongful data collection claims, even as only 3.4% of claims generated an incurred loss, the lowest share across five reporting periods in its data.
Insurance Business said Resilience’s global head of claims, Jeremy Gittler, pointed to self-represented plaintiffs, particularly in California, alleging websites tracked visitors and shared information with third parties without consent. Other claims are pursued by law firms through demand letters, arbitration, or litigation, and many cite alleged violations including the California Invasion of Privacy Act and the Federal Wiretap Act.
While settlement sizes can look small individually, Gittler described the pattern as “high volume, low severity,” with many resolutions in the $10,000 to $30,000 range rather than multimillion-dollar ransomware or major breach losses. He also warned that aggregate costs can still rise due to defense expenses and that coverage can vary materially by policy, with some arrangements potentially triggering coverage while others may fall under exclusions.