Business email compromise (BEC) claims were 57% higher in the second quarter of 2026 compared with the same period last year, according to the Travelers' Q2 2026 Cyber Threat Report.
"Business email compromise scams drove a big increase in claims during the first six months of 2026, with account takeovers surging due to a variety of factors, including a shift in tactics by attackers, who are stealing authentication tokens instead of
A token is
The report has several suggestions to defend against token theft including:
- Treat identity as the unit of compromise.
- Review device code authentication.
- Monitor beyond passwords and endpoints like unexpected token issuance and new application consents and sign-ins.
- Build token response into the incident plan instead of just a password reset.
- Keep verifying high-risk requests.
Fraudsters are also using deep fake videos and phone calls in social engineering, and AI in the process of ransomware negotiations, according to the report.
Eighty-nine distinct threat groups were active in the second quarter, up from the 84 in the first quarter of this year. The three most active groups accounted for 31% of the leak site postings. Data shared on leak sites typically includes information from a person who has refused to pay a ransom, so the data is likely a portion of overall activity.








