Latest News & Updates

September 23, 2026
 / 
Articles
 / 
Threat Analysis

Key Points

  • Kidnapping and extortion are rising globally, with incidents increasing 60% since 2020 and expanding beyond traditional high-risk regions.
  • Criminal tactics are evolving, blending physical coercion with digital tools, crypto-enabled ransom extraction, and fast-moving schemes like tiger kidnaps and virtual kidnaps.
  • Organizations need to reassess their exposure, strengthen personal and operational safeguards, and modernize crisis planning to meet today’s duty-of-care expectations.

Organizations that have never given much thought to the risk of kidnapping and extortion may need to start, according to recently reported data from Control Risks, a global specialist in political and security risk. The number of yearly kidnaps has been growing steadily, with 60% more in 2025 than in 2020. Moreover, perpetrators are increasingly targeting organizations beyond traditional high-risk regions, with increases occurring across every region of the world except the Asia Pacific. (Kidnap and extortion in 2026, Control Risks Insights, July 2026.)

“While much of the world’s attention remains focused on major geopolitical developments, businesses continue to face a broadening and increasingly complex range of extortive and behavioral threats at an operational level,” the firm notes. “Sectors that historically had limited exposure to extortive crime will need to consider the risk to their personnel, as groups diversify their pool of potential victims.”

What’s Driving the Increase in Kidnapping?

Control Risks points to worsening socioeconomic disparities, a fractious geopolitical landscape, and the proliferation of transnational organized crime. Together, these forces are reshaping the global kidnap-for-ransom environment.

  • Geopolitical volatility is creating exploitable security gaps. As governments divert attention to major crises, routine security oversight weakens. Criminal groups move quickly into these vacuums — on land and at sea — taking advantage of disrupted patterns, reduced monitoring, and overstretched state capacity.
  • Criminal actors are adapting faster than security systems can respond. Rapid shifts in political, economic, and regulatory environments push gangs to innovate. They diversify tactics, expand into new geographies, and target people in countries that historically saw little kidnapping activity.
  • Economic stress and conflict are fueling more aggressive forms of kidnapping. In lower-income or conflict-affected regions, mass kidnaps and collective ransom schemes have surged as groups seek higher returns. Economic pressure also drives opportunistic, high-speed tactics such as draining victims’ bank accounts before ransom negotiations even begin.
  • Digital and financial innovations are creating new incentives. Mobile banking and high-value crypto wallets have made ransom extraction faster and harder to trace, giving criminals new ways to monetize coercion. Kidnappers increasingly blend physical pressure with digital theft, and in some markets, crypto-related kidnaps have emerged as a distinct trend.
  • Transnational criminal networks are strengthening local groups. Cross-border alliances expand reach and capability, giving local gangs more confidence and resources to carry out extortive crimes, including kidnapping, when opportunities arise.
  • Grievance-driven hostility is rising amid social polarization. Heightened political anger, social fragmentation, and the coarsening of online discourse are producing more threats and aggressive behavior. While most incidents remain verbal or digital, some can escalate into coercive actions that affect companies and their staff — especially when organizations become entangled in contentious public issues.

Control Risks warns that the threat is unlikely to fade. “AI and digital platforms are reshaping extortion tactics, enabling more scalable, anonymous and credible threat campaigns.”

AI and digital platforms are reshaping extortion tactics, enabling more scalable, anonymous and credible threat campaigns.

As the threat expands and evolves, companies also face growing pressure to act — not only to keep their people safe, but to meet duty-of-care obligations and protect their reputations when incidents occur.

Strengthening Corporate Readiness for Kidnap-for-Ransom Threats

Organizations may need to revisit threat and vulnerability assessments related to kidnap and extortion, including in sectors with traditionally limited exposure. The threat picture has broadened: criminals are no longer focused solely on high-value executives or traditional ransom schemes. They increasingly target the people and processes that allow them to bypass corporate defenses.

Tiger kidnap is one of the clearest examples. Offenders seize or hold a loved one, relative, or coworker under threat of violence to force an employee to grant access or facilitate a theft. The crime works because a frightened person can override even the strongest physical security. For thieves, this type of coercion can open a safe, authorize a transfer, or unlock a system regardless of how sophisticated an establishment’s protections may be.

Virtual kidnapping and phone-based extortion remain a global problem and are evolving. Requiring no physical abduction, criminals contact a target and claim to have taken a loved one, demanding modest immediate payment before the person can verify anything. Digital tools now make these schemes more convincing, with spoofed numbers, harvested details, AI-cloned voices, and even altered photos used to create fake “proof of life.”

Across all variants, the common thread is criminal adaptability.

Across all variants, the common thread is criminal adaptability. Offenders exploit predictable routines, exposed personal information, and gaps in employee awareness. They also benefit from complacency among senior leaders, some of whom underestimate their own exposure or resist security measures they view as inconvenient. That attitude can become a vulnerability for the entire organization.

For companies, the response begins with a more modern understanding of who is at risk. It means identifying roles that criminals might target — not just CEOs, but store managers, logistics supervisors, finance staff, and anyone whose authority can be misused under duress. It means reducing the value of what any one person can be forced to do, separating responsibilities, and ensuring that critical access points cannot be overridden by a single employee under threat.

Personal security awareness also needs to be strengthened.

Staff should know how to spot surveillance, protect their information, and respond calmly to coercive calls or messages. In some environments, families need guidance as well, particularly where virtual kidnaps are common.

Organizations should also pay closer attention to the home-to-work environment, where many incidents begin. Predictable routines, exposed personal information, and remote access to corporate systems can all be exploited under duress.

Finally, companies need plans and practice. Traditional kidnap response protocols often assume time for negotiation and corporate involvement. Modern kidnaps — especially tiger kidnaps and virtual kidnaps — move too fast. Security teams need clear internal notification procedures, coordination with local authorities, and crisis communication plans that reflect the speed and ambiguity of these incidents. Realistic exercises help expose gaps that policies alone cannot.

“[Organizations need] to consider the risk to their personnel and adopt an integrated approach that combines intelligence, behavioral insight, and crisis management capabilities,” the Control Risks report advises.

Conclusion

No longer a niche, geographically isolated threat, kidnapping and extortion is expanding across regions, sectors, and victim profiles — driven by geopolitical volatility, economic pressure, digital innovation, and the growing sophistication of criminal networks. At the same time, new variants are taking aim at the human factors that can override even the strongest security controls.

The threat is evolving, and organizations need to examine how it fits with existing security posture — whether through updated assessments, stronger personal and operational safeguards, or more realistic crisis planning. Companies that scrutinize their approach and take steps to address security gaps will be better positioned to protect both their people and their operations.