Nisos
Shielded on All Sides: How Company Executives Can Mitigate Virtual Kidnapping Schemes
Virtual kidnapping, or virtual kidnapping for ransom, is a coercive telephonic scheme used to extort ransom payments from victims. Victims are contacted, via telephone, and tricked into believing their loved one has been kidnapped, is at risk of being kidnapped, or is in imminent danger. [1] The Federal Bureau of Investigation (FBI) cautioned in October 2024 that recent instances of virtual kidnapping have grown more sophisticated by using AI technology to simulate a loved one’s voice. [2] While virtual kidnapping scams target the public indiscriminately, high-wealth individuals and individuals with access to critical company information, such as company executives in chief executive officer (CEO) and chief information security officer (CISO) roles, are at higher risk. Media reporting shows that these scams have been targeting high-networth individuals and company executives since at least 2022, however instances of virtual kidnappings have been reported as early as 2000. [3][4]
Social media accounts often provide scammers with the information they need to approach and target their victim. [5] Nisos partners with corporate security and executive protection teams to evaluate online vulnerabilities, including on social media, that pose a risk to executives and their family members. Through our detailed Executive Vulnerability Assessment, we identify content revealing personally identifiable information (PII) and pattern-of-life details that can enable scammers to build a profile to assist virtual kidnapping scams.
According to the FBI Internet Crime Complaint Center’s (IC3) 2023 annual report the number of complaints and financial losses related to cyber crimes increased between 2022 and 2023. IC3 reported that they received 880,418 complaints in 2023, a record number, with potential losses exceeding $12.5 billion. This represents a nearly 10% increase in total number of complaints received, and a 22% increase in losses suffered, compared to 2022. IC3 also reported that the total number of complaints for extortions, which likely includes virtual kidnapping scams, increased in 2023 compared to 2022. This increase is the second highest year-over-year increase compared to all other crime types IC3 tracks, which include phishing, employment fraud, tech support, and business email compromise. The total loss reported due to extortions increased by $20 million between 2022 and 2023. [6]
The executive protection work we do for clients involves manual, analyst-drivenThe executive protection work we do for clients involves manual, analyst-driven social media review and analysis for cyber-fraud protection – such as victims and targets of virtual kidnapping scams, identity theft, and romance scams. We also provide threat monitoring and alerting to mitigate digital vulnerabilities that can enable digital and even physical attacks. An analyst’s coordination with and understanding of an individual’s life helps identify unique, dated-yet-relevant, or nuanced data that automated services likely miss. for cyber-fraud protection – such as victims and targets of virtual kidnapping scams, identity theft, and romance scams. We also provide threat monitoring and alerting to mitigate digital vulnerabilities that can enable digital and even physical attacks. An analyst’s coordination with and understanding of an individual’s life helps identify unique, dated-yet-relevant, or nuanced data that automated services likely miss.
Effective protection against scammers requires more than only identifying personal information on deep/dark web marketplaces, public records sites, and data breaches. According to the FBI: “Virtual kidnappers scour the Internet for targets by searching for social media posts by international travelers. Scammers then contact the target’s loved ones claiming to have taken the target hostage.”[7] Posting about travel in real time and allowing public access to friends lists gives threat actors insight that enables virtual kidnapping scams. The same scammers are also looking for additional personal information about the victims, their family members, and estimated net worth to make their scams more believable.
Executive protection services are most effective when social media analysis is combined with ongoing monitoring. PII removals from people search sites, data marketers, data brokers, ancestry sites, residence listings, telephone lookups, and business records are only effective if sensitive data is not otherwise available to threat actors, including on social media. Social media posting habits can negatively impact an individual’s online footprint.
Nisos’ Executive Shield service offers a proactive approach to mitigating threats—preparing for the worst while eliminating nefarious actors’ access to information that can enable attacks. Combining effective social media analysis with ongoing monitoring and vulnerability mitigation efforts protects our clients from ever increasing threats. Nisos recognizes that individuals and companies place a significant level of trust in our partnership and capabilities when undergoing this level of monitoring and proactive protection. Through this trust and relationship, Nisos can help protect an individual’s family, assets, and reputation and mitigate vulnerabilities.
1. https://www.colorado.edu/isss/sites/default/files/attached-files/slicksheet_-_virtual_kidnapping-english_version[.]pdf
2. https://www.kulr8.com/news/fbi-cautions-citizens-about-a-i-ransom-scams/article_f133106c-8821-11ef-bbe1-3752337cb54a[.]html
3. https://www.rollingstone[.]com/culture/culture-news/virtual-kidnappings-wealthy-elite-entertainment-1392918/
4. https://pmc.ncbi.nlm.nih[.]gov/articles/PMC10256574/#Sec8
5. https://www.fbi[.]gov/contact-us/field-offices/chicago/news/press-releases/fbi-chicago-warns-public-about-virtual-kidnapping-scams
6. https://www.ic3[.]gov/AnnualReport/Reports/2023_IC3Report.pdf
7. https://www.fbi[.]gov/contact-us/field-offices/chicago/news/press-releases/fbi-chicago-warns-public-about-virtual-kidnapping-scams
8. https://www.ic3[.]gov/AnnualReport/Reports/2023_IC3Report.pdf
To obtain the complete marketing research report, including endnotes, please click the button below.
Nisos is the Managed Intelligence Company. We are a trusted digital investigations partner, specializing in unmasking threats to protect people, organizations, and their digital ecosystems in the commercial and public sectors. Our open source intelligence services help security, intelligence, legal, and trust and safety teams make critical decisions, impose real world consequences, and increase adversary costs. For more information, visit: https://www.nisos.com.
The post Shielded on All Sides: How Company Executives Can Mitigate Virtual Kidnapping Schemes appeared first on Nisos by Nisos
*** This is a Security Bloggers Network syndicated blog from Nisos authored by Nisos. Read the original post at: https://www.nisos.com/research/mitigate-virtual-kidnapping-schemes/