“In a suit involving 10,000 claimants, for example, these non-refundable fees can exceed $10m before the merits of the case are even heard,” Chubb wrote.
Chubb’s headline: fewer claims but much higher average losses in 2025
Chubb’s 2026 Cyber Claims Report, published on August 25, says that for large and middle-market companies the average cost per cybersecurity insurance claim surged in 2025 even as the overall number of claims fell. The insurer reports a pronounced rise in claim severity across regions and company sizes, driven by a mix of legal exposure and business-interruption damage.
United States: steep jumps in severity tied to litigation and interruption
In the US, Chubb recorded a 22% increase in the average cost of claims for middle-market firms in 2025 compared with 2024. For large companies the change was far larger: an increase of 100% in average claim cost year-over-year. The insurer attributed the growing severity in the US largely to rising costs of both data-breach and privacy-related litigation alongside higher business-interruption expenses.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildUK and Europe: fewer filings, rising per-claim costs without third-party litigation expenses
Across the UK and Europe, Chubb observed the same pattern of declining claim volumes but higher average costs per claim in 2025 versus 2024. Severity rose by 34% for middle-market companies and by 98% for large firms. Chubb pointed out that the average cost per claim remained far higher in the US than in the UK and Europe, which the insurer said can be explained by “the absence of any material third-party litigation expenses from either data breach or non-data breach privacy claims” in the latter region.
SMEs diverge: frequency up, costs fall in US but rise in UK/Europe
Small and medium-sized enterprises bucked the large-company pattern on costs while mirroring it on frequency. Chubb reported that the frequency of claims increased for SMEs in both the US and UK/Europe in 2025. Average claim costs for US SMEs fell from $215,297 to $141,931 during the same interval, while in the UK and Europe average SME claim costs rose from $51,095 to $82,621.
Privacy laws, ransomware leaks, and administrative fees
Chubb highlighted a growing body of privacy laws in both the US and the EU that impose “complex, layered obligations” on companies that store or transfer personal data. The insurer cited new obligations that include the right to opt out of profiling or automated decision-making and disclosure requirements for AI-driven processing. Chubb also warned that ransomware actors increasingly combine encryption with intentional data leakage after successful attacks, a tactic that raises the risk of litigation under data-protection regimes.
On procedural costs in the US, Chubb noted companies are often required to pay substantial upfront administrative fees “for each individual filing, regardless of the merit of the claim.” The report gave the concrete example that, in a suit involving 10,000 claimants, those non-refundable fees can exceed $10m before case merits are addressed.
What this means for technologists, policymakers, and procurement leaders
- Technologists and security teams: rising business-interruption and litigation costs — and the specific threat of combined encryption-plus-data-leak ransomware tactics — mean incident response planning must account for legal exposure and public-disclosure risk as well as technical recovery.
- Policymakers and regulators: the report underscores how layered privacy obligations, including opt-outs for profiling and AI-processing disclosures, are changing the legal landscape companies must navigate when personal data is exposed or processed.
- Procurement and risk managers at affected enterprises: higher average claim costs and sizable administrative fees in the US highlight the need to revisit insurance terms, limits, and the potential for significant outlays before litigation merits are determined.
Chubb’s figures present a clear, numeric picture: 2025 brought fewer claims but larger bills for many insured organizations, especially in the US and among large firms. The interplay of evolving privacy law obligations, procedural fee structures, and ransomware tactics that combine theft with encryption is changing not just incident response but the economics of cyber risk transfer. The report leaves a pointed question for insurers, buyers and regulators alike: if claim severity continues to climb, how will the market and the regulatory frameworks adapt to contain legal and financial exposure?
https://www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/




