Scammers pivot as business email fraud claims surge: Travelers

Business email compromise (BEC) claims were 57% higher in the second quarter of 2026 compared with the same period last year, according to the Travelers' Q2 2026 Cyber Threat Report. 

Processing Content

Ransomware claims have seen no significant rise this year, and even declined 5% from the first quarter, as fraudsters have shifted their attention to authentication tokens to enable account takeovers, according to the same study.

"Business email compromise scams drove a big increase in claims during the first six months of 2026, with account takeovers surging due to a variety of factors, including a shift in tactics by attackers, who are stealing authentication tokens instead of passwords," Lauren Winchester, head of Cyber Risk Services at Travelers, told Digital Insurance.

A token is proof of authentication that allows the user to bypass required passwords or other multi-factor authentication controls. There has also been a shift to use phishing kits that are augmented by AI tools to control an enterprise workspace like Microsoft 265 or Google Workspace, which includes email, file storage, collaboration tools and cloud applications. 

The report has several suggestions to defend against token theft including:

  • Treat identity as the unit of compromise.
  • Review device code authentication.
  • Monitor beyond passwords and endpoints like unexpected token issuance and new application consents and sign-ins.
  • Build token response into the incident plan instead of just a password reset.
  • Keep verifying high-risk requests. 

Fraudsters are also using deep fake videos and phone calls in social engineering, and AI in the process of ransomware negotiations, according to the report.

Eighty-nine distinct threat groups were active in the second quarter, up from the 84 in the first quarter of this year. The three most active groups accounted for 31% of the leak site postings. Data shared on leak sites typically includes information from a person who has refused to pay a ransom, so the data is likely a portion of overall activity. 


For reprint and licensing requests for this article, click here.
Cyber Security Claims Fraud Ransomware
MORE FROM DIGITAL INSURANCE
Load More