Industry the September 2026 issue

Target: CEO

From murder and character assassination to home invasion and state-sponsored detention, executives face a tech-driven threat matrix that can compromise their personal safety and business.
By Russ Banham Posted on September 1, 2026

But a select segment of insurance brokers with expertise in highly specialized crime insurance policies had already noticed a substantial uptick in threats against executives.

“We were absolutely aware of a significant increase in notifications of threats of harm against high-profile targets, either thinly veiled threats or direct threats to life, along the lines of, ‘I have an issue with your organization, I know where you live, and you will pay a price for this,’” says Phil Seel, head of special risks for North America for broker WTW’s crisis management business.

Since Thompson’s killing, the risk of harm to CEOs and other high-profile business leaders has also involved terrifying home invasions and violent family abductions, according to crisis management firms. Kidnap and ransom schemes now encompass two distinct threats: virtual abductions, in which criminals use AI-enabled deepfakes to feign a kidnapping, and physical abductions, where they target executives traveling through supposedly secure Western cities.

Threats against CEOs and other executives are rising—one survey found a 43% increase in online and physical threats, along with sophisticated stalking, at major multinational corporations. The killings of UnitedHealthcare CEO Brian Thompson and Turning Point USA CEO Charlie Kirk demonstrate that threats can escalate into violence.

Potential crimes targeting business leaders include online smear campaigns to extort the target, virtual ransoms that use deepfake technology to convince an executive that a loved one has been kidnapped, and actual abductions such as the 2025 taking of a French cryptocurrency firm co-founder and his wife.

As criminals become more sophisticated, corporations increasingly rely on insurance brokers to secure a combination of risk transfer and active physical protection. As the threat matrix evolves, brokers are pushing for specific policy enhancements to address more recent digital and financial risks like virtual kidnap threats.

Other dangers include relentless stalking, state-sponsored detentions abroad, and deepfake character assassination campaigns using audio and video to paint a scandalous picture of an executive’s private life to erode public trust. By weaponizing any aspect of a leader’s personal or digital life, adversaries can easily inflict severe reputational damage to destabilize an organization until money changes hands.

All these varied threats are escalating. “We’re seeing exponential growth” in threats, says Jacqueline Day, managing partner of global security at Control Risks, one of several security consulting firms that spoke on the record with Leader’s Edge.

Recent intelligence from Ontic, a protective intelligence software provider, and Allied Universal, a security services firm, confirms that the threat level has been steadily rising for high-level business leaders, putting their organizations’ financial value and continuity at risk. Ontic’s 2025 survey of 96 chief security officers from major multinational firms showed that 54% of respondents increased their executive protection budget in 2025, suggesting the CSOs perceived higher risk for executives. In line with that, Allied Universal’s 2026 World Security Report, which surveyed 2,352 chief security officers across 31 countries, found that 42% reported an increase in threats of violence toward company executives. That response increased to 66% when considering security chiefs at just U.S.-based technology companies.

While no data was available regarding how often threats against executives escalate to real-life crimes, Thompson’s killing and other incidents show the risk is real. Events in recent years include the fatal stabbing in April 2023 of tech entrepreneur Bob Lee and the murder later that year of EcoMap Technologies founder and CEO Pava LaPere.

Public Protection and Radicalization

The fatal shooting of the UnitedHealthcare CEO exposed a critical vulnerability in corporate executive protection during public events. Law enforcement findings revealed that alleged assailant Luigi Mangione traveled to the city over a week beforehand to case the venue, identifying a gap in Thompson’s routine during which he might be vulnerable. Subsequent high-profile attacks highlighted this growing danger at public venues and private homes.

“It’s a hard truth to explain to executives. You might think you’re flying completely under the radar, but oftentimes people are pushed to the brink. You have to look at reality strictly through their eyes,” says Matthew Dumpert, managing director at global risk consulting firm Kroll and a former special agent for the U.S. State Department’s Diplomatic Security Service. “While people historically talked about executive protection in the abstract, the Thompson assassination thrust this issue directly to the forefront of every corporate boardroom.”

In January 2025, an organized criminal gang in France targeted David Balland, co-founder of cryptocurrency firm Ledger, abducting him and his wife from their home. The kidnappers cut off one of Balland’s fingers and sent a video to his business partner demanding a 10-million-euro cryptocurrency ransom. French authorities rescued the Ballands within days and arrested 10 suspects in the kidnapping.

Months later, the fatal shooting of Turning Point USA CEO Charlie Kirk by a sniper at an outdoor campus debate in Utah emphasized the extreme security challenges of protecting high-profile leaders during large, highly publicized public gatherings. The suspect in the killing, Tyler James Robinson, is reported to have become increasingly politicized prior to the incident.

“Each successive attack generates more threats because of the copycat phenomenon,” Day says. “Extremist views are amplified inside mainstream online echo chambers, directly inspiring the next round of perpetrators, creating a dangerous feedback loop.”

The growing array of threats has made targeted executive violence a critical priority for Control Risks. “When trending societal radicalization collides with severe mental illness, deep personal grievances, ready access to weapons, and a total lack of stabilizing influences, the physical risk spikes,” says Day, who advises boards of directors at the top of the Fortune 500 on crisis response and executive protection.

She is not alone in this view. There are high volumes of red flags for possible acts of violence, including individuals facing significant financial, emotional, and personal pressures, Dumpert says. Over the past three years, Kroll has tracked a “dangerous convergence” of stolen personal data, rising negative public sentiment against corporate executives, and rapid online radicalization, he adds.

Executive Abductions

Targeted violence against senior corporate executives and their immediate families has reached record levels. Data from the Security Executive Council, a research and advisory firm focused on corporate security strategy, shows that targeted physical violence against senior executives, including assaults and kidnappings, doubled from 2024 to 2025. Such aggressive actions constitute 85% of documented threats, with 64% of incidents specifically targeting CEOs.

While some adversaries are driven by ideology, professional criminal syndicates are in it purely for financial gain, says Paul Hatcher, CEO and managing partner of international security risk advisory and crisis response firm Merrill Herzog. “Ultimately, senior executives are heavily targeted because of their perceived individual wealth, their occupational proximity to corporate wealth and power, and the ease with which criminals can isolate and target them during the planning cycle,” notes Hatcher, an expert in high-stakes crisis response, international extractions, and global security contingency planning.

After identifying possible targets, the criminal operation narrows its list of potential abductees down to one, according to Hatcher. “They search for proximity to their own location or locate a soft target during the initial snapshot assessment,” he says. “The next phase involves advanced digital targeting using both public online data and the dark web to aggressively build out the executive’s pattern of life.”

When trending societal radicalization collides with severe mental illness, deep personal grievances, ready access to weapons, and a total lack of stabilizing influences, the physical risk spikes.
Jacqueline Day, managing partner of global security, Control Risks

This digital profiling informs the various types of kidnap crimes. They include express or rapid kidnaps, which exploit opportunistic victims on the road; home invasions, where targets are selected and surveilled based on perceived wealth; and “wrench attacks,” ultraviolent residential abductions designed to extort cryptocurrency, bypass traditional banking interventions, and rapidly move illicit gains across borders.

To mitigate abduction risks in high-risk zones, multinational firms enforce strict executive security protocols. Corporations use specialized logistics to arrange armored transport, vet local drivers, and minimize public itineraries. Security teams track movements in real time using satellite telemetry and encrypted communications, while strictly limiting digital footprints. Finally, executives must undergo mandatory situational awareness training to detect surveillance, withstand aggressive interrogations, and survive captivity.

Another type of abduction risk for corporate leaders is virtual kidnapping. In these fast-paced schemes, threat actors use psychological manipulation to convince an executive that a loved one has been abducted, forcing them to pay an immediate ransom before they can verify the victim’s safety.

With the rapid maturation of generative artificial intelligence, this tactic has evolved into a highly precise, technologically advanced crime. Virtual kidnappings have increased by at least 300% since 2024, primarily over the past year, says Adam Kibble, vice president of the executive liability practice at Marsh McLennan Agency.

Criminal syndicates now weaponize deepfake audio and video to simulate live hostage scenarios, exploiting the ever-improving capacity to imitate human voices and imagery to induce immediate panic in their targets, Kibble says.

“A threat actor will call an executive or force them on to a Zoom call with a visual component and falsely allege that they have kidnapped a dependent,” he says. “Or they will call the corporation directly and claim they are holding an executive hostage. It’s a parent’s absolute worst nightmare.”

To deter victims from quickly confirming the status of the alleged abductee or seeking help, the criminals fabricate extreme urgency, keeping the victim continuously on the phone to prevent independent verification and threatening instant harm if the call is disconnected.

Hostage Diplomacy

When traveling across international borders into a geopolitical flashpoint, high-profile executives may find themselves detained under false pretexts as pawns in state-sponsored hostage diplomacy. Sovereign nation-states and terrorist organizations alike actively hold corporate citizens to extract political, financial, or economic concessions from the victim’s home country.

Grabbing a corporate executive connected to a powerful government instantly gives the threat actors a global audience. “Less influential adversaries know they do not hold the upper hand in a long-term strategic conflict,” Hatcher says. “So, they use high-profile corporate detentions to force a level playing field at the negotiating table.”

Western nations engage in these tactical maneuvers as well, the security consultants note. A prominent example is the detention of Meng Wanzhou, chief financial officer for Chinese telecommunications giant Huawei, in Canada in December 2018 at the request of the United States, which was prosecuting her for breaching sanctions against Iran. The high-stakes standoff was resolved in September 2021, when a deferred prosecution agreement allowed Meng to return to China, prompting Beijing to immediately release two Canadian citizens who were held in retaliation for her detention.

To mitigate this type of risk, executives should when possible avoid traveling to hostile locations. For mandatory travel, organizations must meticulously plan for scenarios in which a leader might be pulled into an international airport or border checkpoint for secondary questioning. In those instances, the subject’s electronic devices will be confiscated, and their data extracted and copied, while they undergo intense interrogation, Hatcher warns.

When resolving these incidents, corporate leadership must understand that state-sponsored detentions are not standard negotiations. “What you’re actually experiencing is a form of coerced diplomacy,” Hatcher emphasizes. “While maintaining a facade of legality, hostile entities exploit the vulnerability of public pressure over citizen safety, making these scenarios one of the absolute greatest challenges in security.”

While maintaining a facade of legality, hostile entities exploit the vulnerability of public pressure over citizen safety, making [state-sponsored detentions] one of the absolute greatest challenges in security.
Paul Hatcher, CEO and managing partner, Merrill Herzog

Resolving these deadlocks requires navigating complex international regulations and diplomatic gridlock, which often prevents direct communication with the detaining regime or nongovernmental organization.

Wrecking a Reputation

Beyond the threat of physical violence, high-profile executives are also at risk of sophisticated extortion schemes that target their personal reputation, credibility, and public trust—assets directly tied to their companies’ market capitalization. The ultimate goal of the perpetrators—who range from transnational criminal syndicates to politically motivated activist groups to disaffected employees—is character assassination, the systematic destruction of an executive’s standing through fabricated narratives engineered to instantly destroy shareholder value.

“Sometimes this involves impersonation, selectively editing content or distributing entirely false media to make an executive appear unethical, dishonest, politically controversial, or unsafe,” says Olga Polishchuk, senior director of threat analysis and investigations at external cybersecurity company ZeroFox. “The threat actors are frequently driven by economic motives, such as shorting a company’s stock or demanding massive extortion payouts, but they are also increasingly fueled by ideological grievances over wealth inequality, data privacy policies, or corporate societal stances.”

To create a damaging smear campaign, the attackers meticulously scan the internet and public record clearinghouses for vulnerabilities in an executive’s digital footprint, such as private addresses, family photos, or old court filings, Polishchuk says, adding that artificial intelligence enables them to orchestrate highly believable narratives with perfect grammar. They then “leverage automated bot networks and coordinated social media strategies to ensure their fabrications dominate public search parameters.”

The critical data pieces used in these attacks are within the public domain rather than hidden online. The Venmo mobile payments app, for instance, can allow attackers to view an executive’s transactions, as the default setting for transaction feeds is public, she explains.

ZeroFox recently assisted a prominent financial services leader who invested heavily in physical security and digital executive protection and was highly sophisticated and disciplined in safeguarding himself. Despite these rigorous precautions, an overlooked historical digital asset exposed his profile.

“What completely compromised his exposure and led to a targeted smear campaign was a collection of personal pictures posted 20 years ago by his former spouse on her Facebook account. The photos connected him to a politically controversial person back in the day,” Polishchuk says. “That single breadcrumb was enough for adversaries to bring the entire narrative back up to create a dangerous public rhetoric around him.”

Another example reveals the extreme lengths to which threat actors will go to harvest compromising data. The case involved the files released by the U.S. Justice Department related to the late financier and sex offender Jeffrey Epstein, which stoked intense online speculation regarding notable names that appear on the flight logs for his jet. “Our client was completely unconnected to any of this; however, he was highly private about his fleet of private jets and went to great lengths to register those flights through mechanisms that prevent them from appearing in public tracking records,” Polishchuk says.

The compromise originated from a selfie the client’s daughter took at an airfield. As an aspiring digital entrepreneur, she maintained a highly visible online presence and openly shared her travel itineraries on social media. In the posted picture, the reflection in her sunglasses revealed the private aircraft’s tail number. That was enough for bad actors to attempt to harm the client’s reputation by faking a connection to Epstein.

“That single photo started intense online speculation regarding who the jet belonged to and exactly where it was located on a specific day someone was traveling to Southeast Asia,” Polishchuk says. “My point is that threat actors pay attention to the most minute details, ruthlessly scrutinizing a family member’s social media account to create corporate disruption.”

To counter these targeted social media leaks, corporate security teams are proactively hardening leaders’ online footprints, partnering with privacy firms to scrub executive addresses, family data, and private histories from public registries and data brokers, while communications teams use automated tools to detect and counter negative sentiment before it spreads. Finally, legal and IT departments work directly with social media companies to swiftly remove defamatory content and dismantle malicious bot networks.

The threat actors are frequently driven by economic motives, such as shorting a company’s stock or demanding massive extortion payouts, but they are also increasingly fueled by ideological grievances over wealth inequality, data privacy policies, or corporate societal stances.
Olga Polishchuk, senior director of threat analysis and investigations, ZeroFox

Coverage Needs Increase

Faced with these expanding dangers, companies increasingly rely on insurance brokers to secure a combination of risk transfer and active physical protection. With proactive risk consulting and crisis response services from security firms like Control Risks, Kroll, and Merrill Herzog embedded directly into special crime policies, organizations secure a financial safety net to recover capital alongside the tactical means to neutralize active threats.

This approach provides corporate insureds with expert guidance and security support in addition to their own protective resources and aid from local law enforcement agencies, WTW’s Seel says.

Complementing these services is the broad reach of standard kidnap and ransom (K&R) programs. These policies feature an exceptionally wide definition for an “insured,” safeguarding senior management while also extending to other company employees and their direct relatives.

Many standard K&R programs also cover non-physical extortion risks, including cyber extortion, data breach extortion, and property damage threats, although this requires careful tailoring by the insurance broker, carrier, and risk manager. Chris Hughes, managing director of executive liability at brokerage Brown & Brown, notes that the policy will generally cover reputational extortion—a threat to release sensitive or compromising information about an executive. “In that case, the policy pays for specialized consultants, like Control Risks, to launch an investigation, determine the threat’s credibility, and involve law enforcement, if necessary,” Hughes says.

As the threat matrix evolves, brokers are pushing for specific policy enhancements to address more recent digital and financial risks like virtual kidnap threats. Insurance markets are responding constructively to this shifting risk landscape, Kibble believes.

“Top global insurance carriers have minted specific policy definitions to explicitly cover virtual kidnappings in an AI-driven world,” he says. “Corporate policyholders are protected against psychological and technological extortion alike.”

In negotiating the coverage, he emphasizes that corporate risk managers must ensure that bitcoin transfers are covered, alongside a rider explicitly acknowledging virtual kidnapping as a trigger for both crisis response services and financial indemnity. Those measures are needed because traditional crime and K&R policies might classify virtual kidnappings as simple phone scams rather than actual abductions and define “currency” as government-issued cash, thwarting payouts for cryptocurrency extortions.

Rising executive threats are forcing insurance market changes, with over 25% of companies suffering direct revenue losses and public valuations falling up to 32% following security incidents, according to Allied Universal’s 2025 World Security Report. In response, underwriters are shifting portfolios to include expanded coverage and specialized options like stalking threat protection. As Seel puts it, “Insurance coverages are expanding, policy limits are increasing based on recent claims, and new options such as stalking threat coverage are becoming selectively available. Insurers are actively adapting to meet these modern needs.”

Nevertheless, managing compounding threats against executives through fragmented insurance policies can leave dangerous coverage gaps, as a cyber carrier may deny a physical extortion claim while a traditional kidnap and ransom policy might exclude cyber-based digital asset thefts. Insurance brokers and global risk consulting firms are collaborating with corporate risk managers to eliminate these vulnerabilities, combining disparate policy lines into a single, unified executive risk transfer solution to ensure the corporation is not left to fund an expensive, high-stakes response alone.

“Given the recent sharp increase in high-profile threats to executives and the potential need to move people swiftly and safely from complex environments, the conversation surrounding organizational preparedness and the adequacy of insurance coverage has been completely challenged,” says Jonathan Gregory, head of special risks at Ascot Group, a specialty insurer and reinsurer. “There is now a firm stakeholder expectation for corporations to provide an all-encompassing solution.”

To meet this demand, Ascot, Chubb, AIG, and other carriers have bundled comprehensive protection covering physical, operational, and personal threats. Ascot’s suite of solutions underwrites geopolitical risks including terrorism, civil commotion, emergency evacuation, and political instability. The policy also fortifies organizational resilience with consulting on potential loss scenarios, emergency response support, crisis containment, reputation management, and business interruption coverage.

Top global insurance carriers have minted specific policy definitions to explicitly cover virtual kidnappings in an AI-driven world. Corporate policyholders are protected against psychological and technological extortion alike.”
Adam Kibble, vice president of executive liability practice, Marsh McLennan Agency

In partnership with Merrill Herzog, the program addresses severe physical threats including hostage crises, active assailants, and the evacuation and repatriation of personnel during a sudden security collapse. It also mitigates deeply personal dangers, including stalking, child abduction, coercion, assaults, express kidnaps, and tiger kidnaps—where attackers hold family members hostage to force corporate wire transfers.

“When a crisis becomes intimate, targeted, and personally harmful to an executive or their family, we have to look at what specific protective provisions we can provide,” Gregory says. “We have done extensive underwriting to properly assess that intimate exposure and provide active, contractual mitigation for it.”

Preparing for these scenarios is a basic business requirement under a corporation’s duty of care, says Andrew Taylor-Preston, head of crisis management advisory at Ascot.

More in Industry

Things Fall Apart
Industry Things Fall Apart
Corporate threats aren't limited to the C-Suite.
Industry Parametric Reputation Policies
For corporations, a personal attack can have severe financial effects.
Cyberstalking
Industry Cyberstalking
Business leaders must harden their cyber defenses alongside their physical defen...