Market Analysis

Third-Party Claims Crisis: How Vendor Breaches Are Driving Cyber Insurance Loss Ratios to Record Highs in 2026

Third-party vendor claims now account for over 60% of cyber insurance payouts. Learn how loss ratios hit 72% in 2026, which vendor breaches cost insurers the most, and what policyholders must do to maintain coverage.

8 min read
Third-Party Claims Crisis: How Vendor Breaches Are Driving Cyber Insurance Loss Ratios to Record Highs in 2026

⚡ Quick Answer

Cyber insurance loss ratios reached 72% in H1 2026, the highest on record, driven overwhelmingly by third-party vendor claims. According to the Willis Global Cyber Insurance Claims Report (July 2026), third-party claims now account for 61% of all claims by frequency and 67% by dollar value. S&P Global warns the market is at an "inflection point" where flat premiums can no longer absorb escalating supply chain losses. Insurers are responding with sub-limits, vendor risk exclusions, and mandatory assessments — making it critical for policyholders to strengthen their vendor risk management before the soft market reverses.

📌 Key Takeaways

  • Loss ratios hit 72% in H1 2026 — up from 64% in 2025 and 58% in 2024, approaching the threshold where cyber insurance becomes unprofitable for carriers.
  • Third-party vendor claims represent 61% of claim frequency and 67% of claim value, making supply chain breaches the dominant driver of cyber insurance losses.
  • The Snowflake breach alone affected 165+ organizations through a single vendor compromise, generating an estimated $1.2 billion in aggregated insured losses.
  • Insurers are deploying sub-limits, coinsurance clauses, and vendor exclusions — over 70% of new and renewed policies now include some form of third-party claim restriction.
  • S&P Global projects a market correction in late 2026, with potential rate increases of 15–25% for organizations with weak vendor risk controls.
  • Policyholders who document robust vendor risk programs can secure coverage discounts of 10–20% and avoid the most restrictive endorsements.

The Loss Ratio Inflection Point — Willis and S&P Global Findings

The cyber insurance market entered 2026 with cautious optimism. Premium rates had softened for six consecutive quarters, capacity was abundant, and competition among insurers was fierce. But beneath the surface, a structural shift was underway — one that the Willis Global Cyber Insurance Claims Report (July 2026) has now brought into sharp focus.

According to the Willis report, the cyber insurance industry loss ratio reached 72% in the first half of 2026, the highest figure since the market’s inception. For context, a loss ratio of 65% is generally considered the breakeven point for cyber insurance profitability when accounting for administrative costs, commissions, and reinsurance. At 72%, the market is technically operating at a loss on its underwriting activities.

S&P Global Ratings reinforced this assessment in its June 2026 sector report, declaring that cyber insurance is at an “inflection point.” The rating agency noted that while gross written premiums remained essentially flat year-over-year at approximately $15.8 billion globally, claims severity surged by 34%. The disconnect between premium levels and loss experience is widening at an unsustainable pace.

The most striking finding from both reports is the dominance of third-party claims. Willis data shows that vendor and supply chain-related claims accounted for 61% of all claims by frequency and 67% by dollar value in H1 2026. This represents a dramatic shift from just two years ago, when first-party claims (direct breaches of the insured’s own systems) were the primary driver of losses.

The implications are profound. Traditional cyber insurance underwriting focused heavily on the applicant’s own security posture — firewalls, endpoint detection, employee training, and incident response plans. But when the majority of losses originate from third-party vendors that the policyholder does not directly control, traditional risk assessment models begin to break down.

YearLoss RatioThird-Party Share (Frequency)Third-Party Share (Value)Total Claims Paid (Global)
202263%38%44%$4.2B
202361%42%48%$4.8B
202458%49%53%$5.6B
202564%55%61%$7.1B
2026 (H1)72%61%67%$4.9B (annualized: ~$9.8B)

Data sources: Willis Global Cyber Insurance Claims Report, S&P Global Market Intelligence, APCIA Cyber Claims Study

The table above reveals an unmistakable trend: loss ratios dipped briefly in 2024 — the peak of the soft market — before surging to crisis levels. The third-party share of claims has grown approximately 8 percentage points per year, suggesting that by 2027, vendor-related claims could represent three-quarters of all cyber insurance losses if current trajectories hold.

S&P Global’s analysis attributes this shift to several converging factors: the proliferation of cloud-based supply chains, the concentration of critical business functions in a small number of SaaS providers, and the increasingly interconnected nature of enterprise IT environments. When a single vendor like Snowflake, Okta, or Change Healthcare suffers a breach, the downstream impact radiates to hundreds or even thousands of insured organizations simultaneously — creating what underwriters call “accumulation risk” on a scale never before seen in cyber insurance.

Why Third-Party Claims Are Exploding

The Snowflake Domino Effect

The Snowflake data breach of mid-2024 remains the single most consequential third-party cyber event for the insurance industry. Attackers compromised Snowflake customer accounts through credential stuffing attacks, ultimately exfiltrating data from at least 165 organizations — including Ticketmaster, AT&T, Santander, and Advance Auto Parts. The breach unfolded over months, with new victims surfacing well into 2025.

For cyber insurers, the Snowflake incident was unprecedented. Rather than a single large claim, it generated hundreds of simultaneous claims across virtually every major carrier. Individual claim sizes ranged from $500,000 for small businesses to over $50 million for large enterprises with significant data exposure. The aggregated insured loss from Snowflake-related claims is estimated at $1.2 billion, making it the costliest third-party cyber event in history.

The Snowflake case exposed a critical vulnerability in cyber insurance underwriting: many organizations listed the same cloud providers as critical vendors, creating massive concentration risk. Insurers discovered that they had effectively insured hundreds of companies against the same single point of failure — a scenario that traditional actuarial models, designed for independent risk events, were not built to handle.

Change Healthcare: The $87 Million Precedent

The Change Healthcare ransomware attack in February 2024 demonstrated a different dimension of the third-party claims crisis. Change Healthcare, a subsidiary of UnitedHealth Group’s Optum unit, processes approximately 15 billion healthcare transactions annually — roughly one-third of all U.S. patient records. When the ALPHV/BlackCat ransomware group attacked the company, it disrupted healthcare operations nationwide for weeks.

UnitedHealth Group ultimately confirmed losses exceeding $872 million from the attack. But for the cyber insurance market, the more significant figure was the $87 million in third-party claims filed by healthcare providers, pharmacies, and hospitals that were not Change Healthcare customers themselves — they were simply dependent on the company’s infrastructure to process insurance claims, prescriptions, and patient data.

These contingent business interruption claims tested the boundaries of cyber insurance policies. Many policies covered “dependency failures” — outages caused by service provider disruptions — but had never been tested at this scale. The precedent set by Change Healthcare claims handling established that vendor dependencies are insurable cyber risks, but at costs that insurers are now scrambling to contain.

AsyncAPI npm Supply Chain Attack (July 2026)

The AsyncAPI npm package compromise in July 2026 represents the latest evolution of the third-party claims crisis. AsyncAPI, an open-source specification for message-driven APIs, receives over 2 million weekly downloads and is embedded in critical infrastructure at thousands of organizations. Attackers gained access to the package’s npm registry credentials and published a malicious version that exfiltrated environment variables — including cloud API keys, database credentials, and authentication tokens — from build pipelines and production environments.

The attack was detected within 18 hours, but the damage was extensive. Preliminary estimates suggest that at least 340 organizations were running the compromised package version, with confirmed credential exposure at over 120 companies. Cyber insurers are already processing claims related to cloud account takeovers, unauthorized data access, and incident response costs stemming from the AsyncAPI supply chain attack.

What makes this event particularly alarming for insurers is the velocity of propagation. Unlike a cloud provider breach that affects customers of a specific platform, a compromised npm package can spread to any organization using modern JavaScript tooling — regardless of industry, size, or security budget. The attack surface is essentially the entire software development ecosystem.

Salesforce Ecosystem Breaches

The Salesforce ecosystem has emerged as another major source of third-party claims. In late 2025 and early 2026, two significant incidents involving Salesforce AppExchange partners — the Klue competitive intelligence platform breach and the Canvas Consultants data exposure incident — demonstrated that even trusted enterprise platforms carry substantial vendor risk.

The Klue breach exposed sensitive competitive intelligence data from over 90 enterprise customers, including proprietary pricing strategies, sales playbooks, and customer pipeline information. Because Klue integrated deeply with Salesforce CRM systems, the breach also raised concerns about lateral access to Salesforce environments. Insured losses from the Klue incident are estimated at $45 million across cyber and errors & omissions policies.

The Canvas Consultants incident was smaller in scale but equally instructive. A misconfigured Salesforce community portal exposed over 8 million records belonging to multiple organizations that had engaged Canvas for implementation consulting. The claims that followed tested the boundaries between cyber insurance, professional liability, and technology errors & omissions coverage — creating complex coverage disputes that are still being resolved.

Top 5 Third-Party Breach VectorsOrganizations AffectedEstimated Insured LossClaim Types
Snowflake Data Breach (2024-2025)165+$1.2BData breach, BI, notification, regulatory
Change Healthcare Ransomware (2024)1,000+ (healthcare)$87M+ (third-party)Contingent BI, data restoration, ransom
AsyncAPI npm Compromise (2026)340+$60M (est., developing)Credential theft, cloud takeover, IR
Klue/Salesforce Breach (2025)90+$45MData breach, E&O, third-party liability
Okta Identity Compromise (2023-2024)200+$180MIdentity theft, session hijacking, BI

How Insurers Are Responding

The surge in third-party claims has triggered the most significant restructuring of cyber insurance policy terms since the market’s post-colonial-hardening period of 2021–2022. Carriers are deploying a range of tools to limit their exposure to vendor-related losses, and the pace of change is accelerating.

Sub-Limits for Third-Party Claims

The most common insurer response has been the introduction of sub-limits specifically for third-party vendor claims. These sub-limits typically cap coverage for losses originating from vendor or supply chain breaches at 25–50% of the overall policy limit. For example, a policy with a $10 million aggregate limit may include a $3 million sub-limit for third-party vendor claims — regardless of the total loss.

According to Marsh’s Cyber Insurance Market Update (Q2 2026), approximately 68% of renewed policies in 2026 now include some form of third-party sub-limit, up from just 12% in 2024. The most aggressive sub-limits are being applied to organizations that depend heavily on a small number of cloud providers for critical operations — exactly the risk profile that the Snowflake breach made notorious.

Sub-limits vary by vendor category. Cloud infrastructure providers (AWS, Azure, GCP) typically receive higher sub-limits of $5–10 million, while SaaS applications, npm package dependencies, and smaller vendors may be capped at $1–2 million. Some policies are introducing per-vendor sub-limits, capping the amount recoverable from any single vendor failure regardless of total third-party exposure.

Vendor Risk Warranties and Exclusions

Beyond sub-limits, insurers are increasingly requiring vendor risk warranties — contractual representations that the policyholder has performed due diligence on its vendors and maintains ongoing monitoring. Failure to meet these warranties can result in claim denial or coverage reduction.

The most significant development in 2026 has been the introduction of vendor security exclusion endorsements. These exclusions typically deny coverage for losses arising from vendors that do not meet specific security standards — such as SOC 2 Type II certification, ISO 27001 compliance, or specific encryption requirements. If a vendor breach occurs and the vendor lacked the required certifications, the policyholder’s claim may be denied entirely.

AON reports that 41% of policies underwritten in 2026 include vendor security exclusions, and the number is growing rapidly. This creates a challenging dynamic for policyholders: they must not only manage their own security but also ensure that every vendor in their supply chain meets their insurer’s baseline requirements.

Coinsurance Clauses

Coinsurance clauses have emerged as another mechanism for sharing third-party risk between insurers and policyholders. These clauses typically require the policyholder to retain a percentage of any third-party claim — commonly 10–20% — effectively making the insured a coinsurer of their own vendor risk.

Coinsurance is particularly common in policies covering organizations with complex supply chains or those in highly regulated industries like healthcare and financial services. The logic is straightforward: if the policyholder bears a portion of every vendor-related loss, they have a financial incentive to select vendors carefully and enforce strong security requirements.

Mandatory Vendor Risk Assessments

Perhaps the most consequential change is the mandatory vendor risk assessment requirement now embedded in the majority of cyber insurance applications. Insurers are requiring detailed inventories of third-party vendors, their security certifications, the data they access, and the business functions they support.

The assessment requirements go beyond simple questionnaires. Many insurers now require:

  • Vendor security ratings from platforms like SecurityScorecard, BitSight, or UpGuard
  • Evidence of contractual security requirements in vendor agreements (right to audit, breach notification timelines, encryption standards)
  • Concentration risk analysis showing the organization’s dependency on specific vendors
  • Vendor incident response plans and evidence of vendor breach notification capabilities
  • Continuous monitoring attestations for critical vendors
Insurer ResponseImplementation Rate (2026)Impact on CoverageTrend Direction
Third-party claim sub-limits68% of policiesCaps recovery at 25-50% of policy limit↑ Accelerating
Vendor security exclusions41% of policiesCan void coverage for uncertified vendors↑ Rapidly growing
Coinsurance for vendor claims29% of policiesPolicyholder retains 10-20% of losses↑ Growing
Mandatory vendor risk assessments84% of applicationsRequired for binding coverage↑ Near-universal
Per-vendor concentration caps22% of policiesLimits exposure per single vendor↑ Emerging

Source: Marsh Cyber Insurance Market Update Q2 2026, AON Cyber Risk Profiler, Willis Towers Watson

What This Means for Premiums in Late 2026

The cyber insurance market has been in a soft market phase since mid-2023, with premiums declining an average of 8–15% annually. Generous capacity, new market entrants, and improving first-party security postures drove competition that benefited buyers. But the third-party claims crisis is poised to reverse this trend — potentially abruptly.

S&P Global’s June 2026 report explicitly warns of a “market correction” in the second half of the year. The rating agency notes that the combination of rising loss ratios, diminishing reserve adequacy, and the unpredictable nature of supply chain accumulation risk creates conditions that historically precede hard market transitions. Guy Carpenter’s cyber reinsurance index shows that reinsurers are already tightening terms and reducing capacity for cyber catastrophe covers that include vendor accumulation risk.

For policyholders, this means the window to lock in favorable rates may be closing. Industry analysts project the following Q4 2026 rate changes by sector:

  • Healthcare: +15% to +25% (driven by Change Healthcare aftermath and continued targeting of medical vendors)
  • Financial Services: +10% to +20% (concentration risk in fintech and payment processing vendors)
  • Technology/SaaS: +5% to +15% (higher due to software supply chain exposure)
  • Manufacturing: +8% to +18% (OT/IT convergence and industrial vendor dependencies)
  • Retail/E-commerce: +5% to +12% (moderate exposure relative to other sectors)
  • Professional Services: +3% to +10% (varies significantly by client concentration)

To lock in favorable rates before the market tightens, organizations should renew early — ideally 90–120 days before expiration — and come to market with a comprehensive vendor risk management program already in place. Insurers are pricing in forward-looking risk, and demonstrating proactive vendor risk management can meaningfully differentiate a renewal submission.

Additionally, organizations should consider multi-year policy options where available. While fewer insurers offer multi-year cyber policies in 2026 than in prior years, those that do typically lock in rate caps that can provide significant savings if the market hardens as predicted.

Action Plan: Protecting Your Coverage

Step 1: Map Your Vendor Risk Surface

The foundation of any vendor risk management program is a comprehensive vendor inventory. You cannot insure what you cannot identify, and insurers are increasingly scrutinizing whether policyholders actually understand the full scope of their third-party dependencies.

Start by mapping every vendor that has access to your data, systems, or networks. Categorize vendors by risk tier based on the sensitivity of data they handle, the criticality of the business functions they support, and the level of access they have to your environment. For a structured approach, use our vendor risk and cyber insurance checklist to ensure you’re covering all the bases that underwriters will ask about.

Key actions include:

  • Documenting all SaaS applications in use (including shadow IT discovered through network analysis)
  • Identifying all software dependencies in your codebase (SCA scanning for npm, PyPI, Maven packages)
  • Mapping data flows to and from each vendor
  • Assessing concentration risk — what percentage of your critical operations depend on a single vendor?

Step 2: Strengthen Supply Chain Coverage

Review your current cyber insurance policy to understand exactly what third-party coverage you have — and where the gaps are. Look specifically for third-party sub-limits, vendor exclusion endorsements, coinsurance requirements, and coverage triggers for contingent business interruption.

If your current coverage is insufficient, explore options for supplemental supply chain coverage. Some insurers now offer standalone vendor risk endorsements that buy back some of the coverage restricted by standard policy terms. For a comprehensive overview, review our supply chain cyber attack insurance coverage guide to understand the full range of coverage options available.

Step 3: Contract Requirements That Protect You

Your vendor contracts are your first line of defense — and increasingly, insurers want to see them. Every vendor agreement should include:

  • Breach notification requirements (72 hours maximum, consistent with SEC and GDPR timelines)
  • Right to audit the vendor’s security controls and practices
  • Minimum security standards (SOC 2 Type II, ISO 27001, specific encryption requirements)
  • Indemnification clauses for losses caused by vendor negligence
  • Data return and destruction obligations upon contract termination
  • Subprocessor disclosure requirements for vendors that engage fourth parties

Insurers are beginning to require evidence of these contractual provisions as a condition of coverage. A 2026 survey by Lockton found that 57% of cyber insurers request sample vendor contracts during the underwriting process, up from 18% in 2024.

Step 4: Document Everything for Underwriters

When renewing your cyber insurance policy, the quality and completeness of your vendor risk documentation can directly impact your premium and coverage terms. Prepare a vendor risk management dossier that includes:

  • Your vendor inventory and risk tiering methodology
  • Security ratings and certifications for all critical vendors
  • Results of vendor security assessments and penetration tests
  • Evidence of continuous monitoring (automated alerts, periodic reviews)
  • Incident response plans that specifically address vendor breach scenarios
  • Board-level or executive sponsorship of the vendor risk program

Organizations that present comprehensive vendor risk documentation during underwriting consistently achieve better outcomes. According to Allianz Cyber Risk Outlook 2026, policyholders with documented vendor risk programs receive average premium discounts of 12-18% compared to those without — and are significantly more likely to secure full third-party coverage without restrictive sub-limits.

FAQ

What is the current cyber insurance loss ratio in 2026, and how much of it comes from third-party vendor claims?

The cyber insurance loss ratio reached 72% in H1 2026 according to the Willis Global Cyber Insurance Claims Report. Third-party vendor claims account for 61% of all claims by frequency and 67% by dollar value, making supply chain breaches the dominant driver of loss ratio deterioration. S&P Global has warned that this loss ratio level is unsustainable and signals a market inflection point that will likely trigger premium corrections and coverage restrictions.

How do third-party vendor breaches affect my cyber insurance premiums and coverage?

Third-party vendor claims have led insurers to introduce sub-limits (now in 68% of policies), vendor security exclusions (41% of policies), and coinsurance clauses for supply chain claims. Premiums are projected to increase 10–25% in Q4 2026 depending on industry. Organizations with weak vendor risk documentation face the largest increases and most restrictive coverage terms, including per-vendor concentration caps and mandatory security certification requirements.

What was the largest third-party supply chain claims event in cyber insurance history?

The Snowflake data breach of 2024–2025 remains the costliest third-party event, affecting 165+ organizations and generating an estimated $1.2 billion in aggregated insured losses. The Change Healthcare ransomware attack generated over $87 million in third-party contingent business interruption claims. These events fundamentally changed how insurers evaluate supply chain claims and concentration risk, leading to the sub-limits and exclusions now standard in 2026 policies.

Can my cyber insurance claim be denied if a vendor breach causes my losses?

Yes. If your policy includes a vendor security exclusion endorsement (now present in 41% of policies), your claim may be denied if the vendor involved did not meet the security standards specified in your policy — such as SOC 2 Type II certification or ISO 27001 compliance. Additionally, failure to maintain required vendor risk warranties can result in claim denial or reduced recovery under the policy’s coinsurance provisions.

How can I reduce the impact of third-party loss ratio trends on my cyber insurance renewal?

Document a comprehensive vendor risk management program including vendor inventories, security certifications, continuous monitoring, and contractual security requirements. Organizations with documented vendor risk programs receive 12–18% premium discounts on average. Renew early (90–120 days before expiration), present vendor risk assessments to underwriters, and consider multi-year policies to lock in rates before the market correction predicted for late 2026.

Are npm supply chain attacks and software dependency compromises covered by cyber insurance as third-party claims?

Coverage for npm supply chain attacks and software dependency compromises depends on your policy’s third-party claims provisions. The July 2026 AsyncAPI npm compromise (affecting 340+ organizations with 2M+ weekly downloads) is generating claims under cyber policies, but insurers are increasingly scrutinizing whether policyholders implemented adequate software composition analysis (SCA) controls. Organizations without documented SCA tooling may face claim disputes under vendor risk warranty provisions.


If you’re concerned about how third-party vendor risk could impact your cyber insurance coverage and costs, use our cyber insurance cost estimator to model different scenarios based on your vendor risk profile, industry, and coverage needs. The calculator factors in current loss ratio trends, sub-limit structures, and market conditions to give you a realistic estimate of what adequate protection should cost in today’s hardening market.

Get Premium Range + Coverage Gap Report

Use our free calculator to get your personalized annual premium range and identify coverage gaps in minutes.

Get My Cyber Insurance Report