Marsh clients in the United States and Canada submitted more than 1,800 cyber claims in 2023, the highest annual total in Marsh’s dataset at the time. That record was specific to Marsh’s client portfolio and included several types of coverage; it was not a count of every cyber-insurance claim worldwide. Newer Marsh data show a different direction: its 2025 US-and-Canada notifications were down 29% from 2024, although they remained elevated compared with 2022.
What does the 2023 record actually measure?
Marsh’s analysis covered more than 1,800 claims submitted in the US and Canada during 2023. The claims included cyber coverage as well as technology and telecommunications errors-and-omissions and media coverage. The figures describe Marsh clients, not the whole insurance market or every cyber incident.
Among Marsh clients with a cyber policy, 21% reported an event in 2023. Marsh said that annual share had ranged from 16% to 21% over the preceding five years. The claim total and the share of policyholding clients reporting an event are different measures: neither is a count of all attacks, and a claim does not necessarily represent a unique attacker or incident.
Marsh attributed the higher 2023 volume in part to more sophisticated attacks, the MOVEit event and supply-chain vulnerabilities, privacy claims, and more Marsh clients purchasing cyber insurance. Those are the broker’s explanations of contributing factors, not a quantified breakdown of how much each caused the increase. Marsh’s 2023 cyber claims report provides the original context.
Are cyber insurance claims still rising?
Not in Marsh’s latest annual comparison for its US-and-Canada clients. In a report published February 2, 2026, Marsh said notifications in 2025 fell 29% from 2024. The 2025 data were collected through November 30 and extrapolated for the full year, so the figure is an estimate rather than a final count of claims for every day of 2025.
The comparison also depends on how exceptional, related incidents are treated. Marsh said that after removing correlated claims from 2024—including those associated with CrowdStrike and Change Healthcare—2025 still had about 20% fewer events. Notifications nevertheless remained elevated compared with 2022, and Marsh reported that frequency rose quarter over quarter late in 2025. These measures describe Marsh’s portfolio, not a universal market trend. See Marsh’s US-and-Canada report published in 2026.
Marsh’s global overview uses a volume index with 2021 set to 100 for privacy reasons, rather than publishing absolute claim counts. It says adjusted 2024 and 2025 totals were broadly comparable after correlated events were taken into account. The index should not be converted into a number of claims. Marsh’s global claims overview also cautions against equating fewer notifications with lower severity: incidents may combine privacy exposure, extortion, business interruption, third-party failure, and litigation, creating complex, long-running losses.
Why can annual claim totals swing?
Annual counts can move because the underlying incident environment changes, but also because the population and measurement change. A useful comparison checks the reporting year, geography, insured population, kinds of claims included, treatment of correlated events, and whether the statistic measures frequency or severity. Sector groupings can change too.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesLarge related events can make a single year unusually high and complicate comparisons with the next. They do not necessarily signal a lasting change in the baseline. Conversely, a lower count does not mean the financial consequences of the remaining incidents are smaller. As Coalition research vice president Tiago Henriques put it, “An upward trend in one specific attack method doesn’t mean a cyberattack is imminent, and, conversely, a downward trend doesn’t mean the threat has disappeared.” His observation is about interpreting attack trends, not a forecast of insurance claims.
Which industries have the most cyber insurance claims?
For Marsh’s 2023 US-and-Canada data, a 2024 Dark Reading report gave these sector shares: healthcare, 17%; communications, 16%; education, 9%; retail and wholesale, 8%; and financial institutions, 8%. These are historical shares reported by Dark Reading from Marsh data, not current rankings or universal industry rates. Marsh’s own 2023 report identified the same five sectors among the most affected but did not state those precise percentages in the inspected text. Dark Reading’s June 13, 2024 report gives the attributed breakdown.
The later Marsh US-and-Canada report said communications, media, and technology companies had the most events for several quarters. Looking at the countries separately, healthcare remained the most targeted industry in Canada. Those newer groupings and time periods are not directly interchangeable with the 2023 sector shares.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What do extortion and ransom figures tell policyholders?
Extortion was a conspicuous but minority part of the claims mix. In Marsh’s 2023 data, extortion events reached their highest annual level in its dataset, while ransomware and extortion together made up less than 20% of reported cyber claims in both 2022 and 2023. Privacy claims and system attacks without an extortion component accounted for a larger share.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Marsh recorded 282 extortion events in 2023, 64% more than in 2022. Its median ransom demand rose from $1.4 million in 2022 to $20 million in 2023; median payment rose from $335,000 to $6.5 million. These are Marsh’s reported medians for its claims data, not a typical insured’s expected loss or a prediction of what any particular organization would face. Marsh said negotiations generally reduce the final payment, while stressing that each situation is unique. In 2023, 23% of Marsh clients affected by cyber-extortion paid the ransom and 77% refused; this describes those affected clients, not a recommended response. The figures are in Marsh’s June 11, 2024 announcement.
For the 2025 US-and-Canada population, Marsh reported a 33% decline in cyber-extortion events from 2024. Its global report separately described extortion volumes as down since 2023 while average severity rose over the last two years. These statements concern different populations and measures, so a decline in event count should not be read as a decline in the size or complexity of every loss.
What should an organization do when it has a claim?
Marsh’s 2023 report advises organizations handling a claim to notify their insurer, broker, and relevant stakeholders and to maintain appropriate documentation. Organizations should follow the notification and consent requirements in their own policy and work through the response contacts and procedures applicable to that policy; the reports do not establish one universal claims procedure.
Prevention and recovery planning matter alongside insurance. Coalition vice president of research Tiago Henriques recommends keeping consistent offline backups of important data, patching software and firmware regularly, and reducing the attack surface. A drive alone is not a backup strategy: organizations need a dependable backup routine and should test that data can be restored. Marsh’s more recent global overview also highlights privacy exposure, vendor governance, business interruption, and correlated events as considerations in complex claims.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




