Travelers' Q2 2026 Cyber Threat Report states the divergence outright. Business email compromise claims in the first half of 2026 ran 57% above the same months of 2025. "By contrast," the report says, "ransomware claims have seen no corresponding rise this year." That is not because ransomware receded. Leak-site postings for the quarter ran 53% above Q2 2025. Attack activity and claim experience are separating, and the mechanism behind it is specific enough to price.
The Attack Series and the Claim Series
The quarter recorded 2,274 victims posted to ransomware leak sites, about 5% below Q1 2026's 2,405 and 53% above the same quarter of 2025. The step down is the least interesting number in the paragraph. What matters is the seasonality that did not happen: in 2025 the second quarter fell nearly 34% from the first, and this year the comparable drop was under 5%. Travelers reads it as the sustained level overwhelming the seasonal pattern, with each new high watermark tending "to set the floor for what follows rather than a temporary peak."
Against three quarters of activity at or near record levels, ransomware claims have not moved with it. The Q1 report put the long-run version on the record: since 2022, ransomware activity measured by leak-site postings has tripled, while Travelers' own ransomware claims rose 80%.
Before treating that as a puzzle, read the footnote Travelers attaches to its own series. Leak-site data "provides a proxy for overall ransomware activity. A victim's information will typically be posted if the victim has refused to pay a ransom." That is a selection rule, not a census. The series counts the subset who declined to pay, so if payment behaviour shifts across a period, the proxy's coverage of the underlying event count shifts with it and no change in attack frequency is required to move the line.
Add the obvious asymmetry, that postings count attacks across the whole economy while claims count insured losses on one underwritten book after risk selection, controls, retentions and a policyholder's decision to file, and the two were never going to track. The useful question is what the claim side is made of instead.
| Measure | Q2 2025 | Q1 2026 | Q2 2026 |
|---|---|---|---|
| Victims posted to leak sites | not disclosed; Q2 2026 ran 53% higher | 2,405 | 2,274 |
| Change from the prior quarter | down nearly 34% | not disclosed | down less than 5% |
| Distinct groups active | 76 | 84 | 89, a new dataset high |
| Top three groups' share of postings | 37% | 34% | 31% |
Where the Claims Actually Are
Business email compromise carried the growth twice over. The average number of BEC claims per month across the first half of 2026 ran 50% above the monthly average for all of 2025, and the half-year total was 57% above the same period a year earlier. The Q1 report gives the standing share: social engineering fraud and business email compromise together account for roughly 40% to 50% of all cyber claims at Travelers, with the severity of claims combining the two up more than 30% since 2023. The peril that dominates the threat reporting is not the peril that dominates the claim file.
What changed about the attack is the part that matters for pricing. A workspace issues a device "a digital token that spares them from having to enter their password again for some period of time," and attackers have found a way to acquire it. In the report's own words: "The token is proof that authentication has happened, so the attacker, with token in hand, bypasses it entirely."
That is a pricing problem, because multi-factor authentication is the most heavily weighted single control credit in cyber underwriting, and it earned that weight from loss experience gathered when credential theft meant password theft. Travelers notes that more organisations are moving to phishing-resistant forms of MFA using passkeys or device certificates, which does reduce the most common adversary-in-the-middle attacks. Token theft "sidesteps the login page entirely." So the control is getting better at the attack it was built for while the fastest-growing attack stops going through the door it guards.
The consequence for a rating plan is narrow and specific. The expected-loss differential between an MFA-yes and an MFA-no risk should compress across the portion of the book that is social engineering and account takeover, which is already 40% to 50% of claims and rising in severity. Nothing in a control questionnaire records that compression, because the answer to the question being asked is still yes.
The report's remediation list is the tell. Monitor token issuance, new application consents and sign-ins from unfamiliar locations. Build token response into the incident plan, because "a password reset is not enough": revoke active sessions, invalidate refresh tokens, review OAuth consents. Those are different questions from whether MFA is deployed, and a rating variable built on the old question will not separate risks on the new one.
A Threat Population That Will Not Hold Still
Eighty-nine distinct threat actor groups were active in Q2 2026, a new high in a dataset going back to 2020, up from 84 in Q1 2026 and 76 in Q2 2025. Twenty appeared in leak-site data for the first time. Twenty-one groups that had been active in Q1 went quiet while 20 new ones debuted, which Travelers describes as turnover that "has become a structural feature of the ecosystem rather than a temporary phase."
Concentration fell as the count rose. The three most active groups took about 31% of all postings in Q2 2026, against 34% in Q1 2026 and 37% a year earlier. Travelers draws the defensive consequence: disrupting any single group through law enforcement becomes less consequential to overall volume as attacks distribute across a larger population of operators.
A frequency model wants a reasonably stable generating process behind the counts it is fitted to. Here the total sits at a sustained high while the roster is, in the report's phrase, "meaningfully different from one quarter to the next." Fitting to the aggregate treats the mix as stationary, and three consecutive quarters of falling concentration are the aggregate saying it is not. Different groups run different playbooks, target different sectors and demand different amounts, so a stable total assembled from a rotating cast is a weaker basis for a severity distribution than the total alone suggests.
It lands on wordings too. Named-actor exclusions, sanctions screening and war or state-actor language all require deciding who did it. A roster replacing roughly a quarter of itself each quarter, and rebranding across those transitions, makes attribution slower and less certain than the wording assumes. That cost shows up in claim handling time and disputed coverage rather than in the rate.
None of this argues for ignoring the leak-site series, which remains one of the few high-frequency public signals in a class starved of them. It argues for reading it as what its own footnote says it is: a proxy for one peril, counting one subset of victims, across an economy rather than a book. The claims are somewhere else, and Travelers has now said so in as many words.
Further Reading
- Cyber Claims Frequency-Severity Divergence Reshapes Rate Models in 2026: The Coalition data showing the same frequency-up, severity-down shape earlier in the year, with the split-trend and ILF mechanics.
- Beazley’s Combined Ratio Jumps 8 Points as Cyber Premiums Retreat 15.4%: What a softening cyber market does to the rate adequacy these mix shifts are measured against.
- Chubb Cyber Report Shows Large-Account Severity Doubled and Supply Chain Losses Multiplied 2.5x: A second carrier's read on how AI-enabled attack tooling is changing the claim mix.
- Silent Cyber PML: How AI Wording Scanners Are Changing Actuarial Cat Model Certification: How scan-derived exposure signals feed portfolio accumulation work, the other side of the observable-series question raised here.
- Cowbell’s OMNI Puts an AI Decision Layer on E&S Cyber: Control and signal selection inside an AI-driven cyber underwriting stack.
Sources
- Q2 2026 Cyber Threat Report (Travelers), the primary source for the leak-site counts, group counts, concentration shares, BEC claim figures and token-theft passages quoted here
- Q1 2026 Cyber Threat Report (Travelers), the source for the since-2022 activity and claim growth figures and for the 40% to 50% claim share and severity change, which the Q2 edition does not restate
- Scammers pivot as business email fraud claims surge: Travelers (Digital Insurance) (September 1, 2026)
- Facing Today's Cyber Threat Landscape (Travelers Institute) (2026)