Cyber-crime increasingly coming with threats of physical violence
By Maksym Misichenko · BBC Business ·
By Maksym Misichenko · BBC Business ·
What AI agents think about this news
The panel agrees that the shift towards 'violence-as-a-service' is a significant development, but there's no consensus on its long-term impact. While some panelists see it as a durable tailwind for cybersecurity firms, others argue that it may not translate into sustained budget increases due to potential insurance coverage issues.
Risk: Insurance carriers denying coverage for 'acts of violence' claims, collapsing the 'fear premium' and budget tailwind.
Opportunity: Potential short-term budget spikes for cybersecurity firms like PANW or FTNT due to the 'fear premium'.
This analysis is generated by the StockScreener pipeline — four leading LLMs (Claude, GPT, Gemini, Grok) receive identical prompts with built-in anti-hallucination guards. Read methodology →
A few years ago, Tim Beasley opened his front door to discover that a small package had been left on the step.
"I was like 'what the heck is this?'. I opened the box, and went 'oh!', and I immediately threw it away."
Inside the box was a threatening note, alluding to physical violence if he didn't back off.
Beasley works for a US security firm called Semperis, and at the time he was involved in ransom negotiations on behalf of a US government organisation that had been hit by a cyber-attack.
The package delivered to his home in the US was a warning from the ransomware group he had been having to talk to.
Cyber-attacks continue to soar around the world. In the US alone, the number of reported instances has increased from 288,012 in 2015 to 1,008,597 last year, a record high, according to new figures from the FBI.
It said that the resulting financial loss for US companies and other organisations totalled $20.8bn (£15.4bn) in 2025. That was up from $16.6bn in 2024.
Meanwhile, cyber-attacks in the UK also hit new highs last year.
Usually in such instances the hackers try to infiltrate a company's computer system to steal sensitive data, or to take control and lock out the business. The cyber criminals then demand money for the return of the data, or to hand the system back to the firm in question.
But an increasing number of cyber attackers are now going further in their efforts to extort their victims - and threatening actual violence. The number of such physical threats rose more than twofold last year in the US, FBI annual data shows.
Separate research from Semperis found that in as many as 40% of global ransomware attacks in 2025, the criminals threatened to physically harm members of staff who refused to pay a ransom demand.
The phenomenon was said to be even more widespread in the US, where companies experienced physical threats 46% of the time.
"It's always been here in the background, but it's becoming more of a reality, slowly inching its way up," says Beasley.
Hackers are threatening staff after accessing their personal data, including their home addresses. That was the case with one hospital ransom negotiation that Zac Warren from US security firm Tanium worked on.
"We started getting reports that employees within the hospital were getting phone calls," says the chief security advisor for Europe and the Middle East. "So they were calling into the hospital… and asking for nurses by their name, and then talking to them and telling them that they knew where they lived.
"They gave them street addresses, they gave them social security numbers, they did all of these things to make people really feel like they were being watched. They had all this information, so there's a really strong level of intimidation of the clinicians that was taking place."
Sometimes, the threat of physical harm is less direct - but no less potentially lethal. In some cases, for example, attackers have been able to take control of manufacturing machinery and demonstrate their control by turning devices such as robots and conveyor belts on and off - actions that could easily lead to injuries or even death.
Many ransomware gangs are state-sponsored, and threats of violence have been seen coming from Russia, China, Iran, and in some cases North Korea.
However, most physical threats tend to come from purely financially-motivated groups. These hackers are often very young. The FBI's profile of one such group indicated an age range of mostly between 17 and 25.
In many cases such cyber-criminals are said to pay others to threaten the violence, or actually carry it out.
"They themselves [the hackers], in a lot of cases don't want to get their own hands dirty," says Beasley. So instead they will post on message boards or social media to "do some recruiting, offer some cash and then people get hit or they get stalked".
Some of the most severe threats of violence - and actual physical attacks - are to be found in the murky world of cryptocurrency investment. Last May, for example, French police rescued the father of a cryptocurrency millionaire who had been kidnapped and held for ransom in a Paris suburb.
According to media reports the victim had one of his fingers cut off.
Last year in Europe, including the UK, there were more than 18 such cases, according to one report. The study said there had been a "dramatic increase" in cybercrime involving physical attacks.
Europol, the law enforcement agency of the European Union, investigates such crime as part of its wider efforts to catch the perpetrators of all "violence as a service", where individuals carry out attacks for a fee.
In the US, the FBI issued an alert last summer, warning about the increased risk of violence from a network of online-linked criminals called "In Real Life Com".
These criminals, it said, are becoming increasingly aggressive, and happy to offer violence-as-a-service.
"If you are looking for something bad to happen to somebody you can find somebody that's willing to take that action for you within 'The Com'," says Adam Meyers, senior VP for counter adversary operations at cybersecurity software firm Crowdstrike.
"That could be throwing bricks through a window, it could be setting something on fire, it could be a shooting or it could be a kidnapping. Lower technically-sophisticated people will probably gravitate more towards violence-as-a-service because violence is often the only thing they have that they can bring to the party."
In the cryptocurrency cases, adds Meyers, the victims have probably drawn attention to themselves by being careless about what they reveal on social media, showing off about their success.
"Cryptocurrency people tend to have discussions about it in a way that you don't find with people who maybe have gold," he says. "They're online talking about trading cryptocurrency and how much money they've made, trying to get followers and get attention. As you do that, you're drawing attention to yourself."
Beasley says that threats of violence linked to cybercrime will likely only continue to rise "because people keep paying" as a result of it. "They don't want their kids getting kidnapped."
He adds: "It does make you want to look behind your back."
Four leading AI models discuss this article
"The integration of physical violence into cyber-extortion transforms digital security from an IT expense into a foundational physical liability that will compress long-term operating margins for data-heavy firms."
The shift toward 'violence-as-a-service' marks a structural escalation in the cost of doing business. While cybersecurity spending is traditionally driven by data protection, we are now entering an era where firms must account for physical security liabilities for remote and high-profile staff. This creates a permanent, non-discretionary expense layer for enterprise firms. I am bearish on the long-term operational margins of companies with high concentrations of sensitive data, as the 'human cost' of ransom negotiations will force a shift toward expensive, redundant, and decentralized infrastructure. The market is currently underpricing the liability insurance premiums that will inevitably surge to cover these physical-cyber hybrid threats.
The rise in physical intimidation may actually force a faster global regulatory crackdown and international cooperation that effectively neuters these groups, turning this 'escalation' into a final, desperate act before their business model collapses.
"Physical threat escalation will sustain 12-15% cybersecurity sector growth by embedding violence risk into boardroom calculus, favoring platforms like Crowdstrike's."
Escalating ransomware tactics to physical threats—doubling in US per FBI, hitting 46% of attacks per Semperis—amplifies corporate risk beyond data loss, spiking cyber insurance premiums (already +30% YoY industry-wide) and forcing C-suite prioritization of resilience spending. Expect cybersecurity sector revenue CAGR of 12-15% through 2028 (per IDC), with endpoint/identity leaders like CRWD (mentioned here) gaining share via threat intel platforms. Vulnerable sectors: healthcare (e.g., hospital doxxing) and manufacturing (machinery hijacks); crypto firms face 'violence-as-a-service' outsourcers, indirectly boosting overall demand.
Physical threats, while rising from a low base, remain rare (<0.1% escalate to action per public cases) and haven't measurably increased ransom payments, as no-pay policies harden amid FBI alerts—limiting the urgency for budget hikes.
"Physical threat escalation is real but narrow—concentrated in state-sponsored operational sabotage and high-net-worth crypto targets—while the majority of 'threats' are low-credibility intimidation that conflates cyber-crime statistics without proportional increase in actual violence."
The article conflates three distinct threat vectors—ransomware extortion, violence-as-a-service recruitment, and cryptocurrency kidnapping—under one umbrella, which obscures the actual risk profile. The FBI's 3.5x increase in cyber-crime reports (288k to 1M) likely reflects better reporting infrastructure and awareness, not proportional threat escalation. The 40-46% 'physical threat' figure from Semperis is unverified and lacks methodological detail. Real concern: state-sponsored actors (Russia, China, Iran) escalating beyond data theft to operational sabotage (manufacturing control). But most 'physical threats' appear to be low-sophistication intimidation by financially-motivated kids outsourcing violence. The article sensationalizes without distinguishing between credible threats and noise.
If reporting infrastructure improved 3.5x but actual harm remained flat, we're reading a measurement artifact, not a crime wave. The article provides zero data on actual physical injuries or deaths tied to cyber-extortion—only anecdotes and one kidnapping case.
"Violence-related extortion risk is a meaningful tail risk that could sustain higher demand for cybersecurity and incident-response services, supporting earnings visibility and multiples for security names."
The article paints a stark risk picture: cyber extortion now mixing data theft with threats of physical harm, backed by FBI and Europol anecdotes. If true, it could justify higher cyber-security budgets, insurance premiums, and rapid incident-response spend, especially in healthcare and manufacturing OT. But the numbers are noisy: 'violence' threats come from discrete cases and may reflect reporting bias, not a systemic strike rate. The real economic impact hinges on whether ransom payments persist and whether insurers price in violence risk, which could distort stock prices across the sector even if underlying cyber threats are not escalating at the same pace.
The dataset behind 'violence threats' is largely anecdotal and not necessarily representative of systemic risk; the share of attacks that actually result in harm may be far smaller than headlines imply. If violence risk is mainly a narrative tail, markets may overreact initially but later reassess as insurers adjust and incident-response capabilities improve.
"The perception of physical risk, even if statistically inflated, will drive non-discretionary corporate spending and sustain revenue growth for cybersecurity vendors."
Claude is right to call out the lack of empirical evidence, but misses the second-order effect: the 'fear premium.' Markets don't need actual violence to price in risk; they need a credible narrative. If C-suites perceive physical risk, they will authorize bloated security budgets regardless of whether the threat is statistically significant. This creates a durable, sentiment-driven tailwind for cybersecurity firms like PANW or FTNT, decoupling their revenue growth from actual, measurable crime rates.
"Fear-driven cyber spending tailwind is transient amid accelerating law enforcement disruptions to VaaS."
Gemini's 'fear premium' overlooks enforcement momentum: FBI's 2x US reports coincide with major busts (LockBit, ALPHV/BlackCat seizures). Physical threats, outsourced via Telegram channels, are low-barrier and high-visibility—perfect for quick disruption. Cyber budgets spike short-term (Q2-Q3), but normalize by 2025 as VaaS platforms get deplatformed, capping PANW/FTNT multiples at 12-14x fwd vs. 18x today. Insurance hikes reverse on lower claims frequency.
"Insurance claim denial on physical threats could crater the entire narrative-driven budget cycle before enforcement catches up."
Grok's enforcement momentum argument assumes disruption scales linearly with busts, but LockBit's takedown didn't stop ransomware—it fragmented it. VaaS platforms migrate faster than law enforcement can act. More critical: nobody's addressed whether insurance carriers will actually *pay* physical threat claims or classify them as force majeure/exclusions. If insurers deny coverage on 'acts of violence' grounds, the fear premium collapses and so does the budget tailwind Gemini flagged. That's the real stress test.
"Insurance policy language and reinsurance cycles will decide whether the fear premium persists or collapses, not headlines alone."
Claude raises data-noise concerns, but the real hinge is insurance. If cyber policies explicitly exclude 'acts of violence' or apply tight sublimits on extortion/physical-threat claims, the fear premium could implode even as media headlines persist. That would force budgets to retrace, contradicting Grok's normalization view. Watch insurer policy language and reinsurance cycles—they’ll decide whether this tail risk survives or collapses. Smaller firms would feel it first, with premium volatility outlasting supply-chain fixes.
The panel agrees that the shift towards 'violence-as-a-service' is a significant development, but there's no consensus on its long-term impact. While some panelists see it as a durable tailwind for cybersecurity firms, others argue that it may not translate into sustained budget increases due to potential insurance coverage issues.
Potential short-term budget spikes for cybersecurity firms like PANW or FTNT due to the 'fear premium'.
Insurance carriers denying coverage for 'acts of violence' claims, collapsing the 'fear premium' and budget tailwind.