Express Kidnapping and the New Face of K&R Risk:
What Every Business Traveler Needs to Know

On the evening of February 10, 2026, Nancy Guthrie, the mother of NBC Today show host Savannah Guthrie, was abducted from her home in St. Paul, Minnesota. She was released unharmed several days later following what law enforcement described as a ransom demand. The case generated significant national attention not because such incidents are rare in the United States (they are) but because it landed on the front page of publications whose readership had previously treated kidnapping and ransom as risks confined to conflict zones and Hollywood plotlines, and because it forced a public conversation that the insurance and security industries have been trying to have with corporate America for years: kidnap and ransom is not an exotic, low-probability risk that only frontier-market executives need to manage. It is a growing, diversifying, and technically sophisticated threat category that K&R insurance premiums grew 14% globally in 2025 to reflect, and that the dominant criminal model of 2026 makes relevant to any organization sending employees into Latin America, Sub-Saharan Africa, or any other environment where organized crime has identified foreign business travelers as an accessible and lucrative target (UPI, 2026; Market.us, 2026). The dominant model is not the prolonged hostage scenario of the movies. It is express kidnapping, a 24-to-48-hour forced financial extraction that drains a victim’s digital banking access, empties their accounts, and releases them before any organized law enforcement response can develop. It is fast, low-profile, and surging.

What Express Kidnapping Actually Is

The terminology matters because the threat model matters. Traditional kidnap-for-ransom, the model that generated the K&R insurance market, trained the crisis negotiation profession, and produced the operational protocols that corporate security programs have historically been built around, involves an extended detention, a ransom demand directed at the victim’s employer or family, a negotiation process, and a payment and release sequence that can take days, weeks, or months (Gallagher, 2026). It is operationally complex, intelligence-intensive, and expensive for the criminal organization to sustain. Traditional K&R remains a genuine threat in specific high-risk environments such as the Gulf of Guinea, parts of rural Mexico and Colombia, conflict-zone adjacent markets, but it requires a level of organizational commitment and risk tolerance that limits its practitioners to well-resourced criminal networks with established operational infrastructure.

Express kidnapping requires none of that. A victim is intercepted, typically at an airport arrival, exiting a hotel, or in a taxi, held for between 12 and 72 hours, forced to access their banking applications, cryptocurrency wallets, and digital payment platforms under duress, and released once the available digital liquidity has been exhausted (LegalClarity, 2026). The criminal organization’s investment is minimal: a small team, a vehicle, and an understanding of how mobile banking applications work. The victim’s smartphone is simultaneously the target and the tool because the device they carry to stay connected in an unfamiliar city is the device that gives their captors access to everything of immediate financial value they possess. The UK Foreign, Commonwealth and Development Office travel advice for Colombia defines the model with operational precision drawn from documented incidents: criminals — “often posing as taxi drivers — may track and select a target victim, often from around ATMs and often at night. The kidnappers force the victim to empty their bank account by making multiple transfers or drive them to ATMs and force them to withdraw cash. Normally, victims are quickly released, but there have been incidents where those who have resisted the kidnappers’ demands have been killed” (UK FCDO, 2026, para. 2). The Government of Canada’s travel advisory for Colombia confirms the same operational pattern: “Criminals kidnap the victim from the street or a taxi and force the person to withdraw funds from an ATM. The victim is sometimes held overnight so that a second withdrawal can be made the next day” (Government of Canada, 2026, para. 3). Control Risks — which maintains the world’s largest proprietary commercial database of kidnaps and extortive crime, containing details of more than 71,000 incidents, has identified the shift toward financially motivated short-term abduction as a defining feature of the current threat landscape across Latin America and Sub-Saharan Africa, driven by the intersection of extreme economic inequality, weak prosecution rates, and the explosive growth in mobile banking access among foreign nationals in these environments (Control Risks, 2025).

The Geographic Threat Map

The State Department and OSAC’s current country security analysis establishes a clear geographic architecture for the express kidnapping threat, concentrated in regions that are simultaneously among the most commercially active frontier markets and the least adequately managed from a corporate travel security perspective.

Mexico presents the most immediately relevant risk profile for U.S. business travelers by volume of exposure. OSAC’s Mexico Country Security Report documents Transnational Criminal Organizations operating with varying degrees of impunity across virtually every state, with express kidnapping and virtual kidnapping, in which criminals make threatening calls to victims’ families claiming to have a family member in captivity and demand immediate payment, among the documented threat categories for foreign nationals in business and tourist environments (OSAC, 2026a). Control Risks’ 2024 analysis of Mexico’s security risk trajectory documented that 60 percent of companies operating in Mexico report feeling somewhat or considerably affected by crime, with 58 percent of firms investing between 2 and 10 percent of their annual budgets in security measures — a baseline that reflects how deeply the organized crime threat has penetrated the operational reality of doing business in the country (Control Risks, 2024). The State Department maintains Level 4 Do Not Travel designations for Sinaloa and six other states, designations that many corporate travel programs either do not monitor in real time or do not translate into active travel restrictions for employees with business in those regions.

Nigeria represents the most acute K&R risk environment in Sub-Saharan Africa by documented incident volume. On April 8, 2026, the U.S. State Department authorized non-emergency government employees and their families to depart the U.S. Embassy Abuja due to a deteriorating security situation, a formal designation whose implications for private sector organizations operating in Nigeria without equivalent security resources are significant (U.S. Department of State, 2026b). The Nigeria Travel Advisory documents kidnapping as a prevalent threat across the majority of the country’s states, with documented tactics including stopping drivers on interstate roads, carjacking, and targeted abduction of foreign nationals and explicitly warns travelers to “be extra vigilant when visiting banks or ATMs” (U.S. Department of State, 2026b, para. 6). The Niger Delta region, which concentrates the energy sector operations that bring most international business travelers to Nigeria, carries specific kidnapping risk from armed groups whose operational history in maritime kidnapping mirrors their land-side tactics. Colombia’s risk profile, Level 3 Reconsider Travel, with documented express kidnapping in Bogotá, Medellín, and Cartagena, has been substantiated above through both State Department and allied government advisories. Kenya and South Africa add the Sub-Saharan dimension of the threat: both countries host substantial NGO and development sector operations, regional commercial expansion, and energy sector activity, generating significant Western business traveler presence against a backdrop of urban crime environments where express kidnapping of foreign nationals has been documented in Nairobi’s commercial districts and South Africa’s Johannesburg and Cape Town business corridors.

The Crypto-Kidnapping Variant and the Digital Threat Expansion

The surge in K&R insurance premiums in 2025 was driven not only by the geographic expansion of traditional and express kidnapping but by a new variant that has introduced an entirely different target population to the threat landscape: crypto-kidnapping. In July 2025, insurers reported a surge in inquiries tied to virtual kidnappings and ransom demands in digital assets, following a pattern of organized gangs using leaked data from cryptocurrency platform breaches to identify and target high-net-worth cryptocurrency holders (Market.us, 2026). On February 12, 2026, masked assailants targeted Binance France CEO David Prinçay outside his Paris residence in a failed home invasion and kidnapping attempt, an attack that placed the entire cryptocurrency industry on alert and demonstrated that the crypto-kidnapping threat was no longer confined to emerging markets or frontier environments but was operating in Western European capital cities (UPI, 2026). Control Risks has documented crypto-ransom kidnaps across 12 countries, with a gradual year-on-year increase in reported cases as cryptocurrency ownership has expanded beyond early adopters into mainstream wealth management portfolios, creating a target population that organized criminal networks are actively mapping through breached platform data (Control Risks, 2025a).

Matthew Humphries, head of crisis management at Lockton Companies, identified the structural shift this represents: “Kidnap and ransom insurance is available for people and organizations whose profile or operations are exposed to heightened security risks, whether abroad or closer to home” — a formulation that explicitly acknowledges the threat has moved beyond the international business travel context that historically defined the K&R market (UPI, 2026, para. 6). AXA XL Senior Vice President and Head of U.S. Security Risks Denise Balan identified the duty of care dimension that gives the crypto-kidnapping development its broadest organizational significance: K&R insurance is fundamentally a duty of care product, provided by businesses “as part of their legal duty to protect their employees”, and the expanding threat population means an expanding organizational obligation to assess who within the workforce, and which family members and associates, face elevated risk that the organization has not yet modeled (UPI, 2026, para. 9). A technology company whose CFO holds significant personal cryptocurrency holdings, whose CTO attends blockchain conferences in Latin America, and whose NGO partnership officer travels regularly to Lagos and Nairobi is carrying K&R exposure across three different threat vectors that a traditional corporate security program designed around physical protection of the CEO would not capture. The K&R insurance market’s $2 billion scale in 2025, projected to nearly double by 2033, reflects the market’s own actuarial assessment of how far that exposure gap extends (UPI, 2026).

The Protocol Gap: Why Most Organizations Are Exposed

The most operationally consequential finding in the current K&R risk landscape is not the sophistication of the threat. It is the systematic absence of preparation among the organizations most exposed to it. AIG’s crisis response documentation describes the fundamental operational requirement: the moment an insurance carrier receives notification that an insured person has been taken, it mobilizes specialized resources immediately, but this response architecture functions only when the organization has a K&R policy in place, has trained its relevant personnel to initiate the notification protocol immediately, and has established pre-incident communication procedures that allow crisis responders to act before critical intelligence about the victim’s location and status becomes stale (AIG, 2025). In most organizations, none of these conditions exist.

The State Department advisories provide the most operationally specific guidance available to private sector organizations on pre-incident preparation for K&R environments. The Colombia advisory’s operational recommendations illustrate the level of pre-travel preparation that a functioning K&R protocol requires: establish a unique alert word with trusted contacts to use during a phone call if under duress; avoid street-hailed taxis and use only dispatch or app-based services; use ATMs inside banks or shopping malls rather than on the street; avoid displaying phones, jewelry, or visible signs of wealth; vary routines and routes; and travel in daylight wherever possible (U.S. Department of State, 2026a). These are not complex security measures. They are basic operational hygiene practices that reduce the targeting opportunity for express kidnapping operations, and they are systematically absent from the pre-travel briefings of most corporate travel programs operating in these environments.

The Gallagher K&R insurance analysis documents a fundamental confidentiality requirement that further complicates organizational preparedness. Companies must limit knowledge of the existence of a K&R policy because advertising its presence could prompt the insurer to deny coverage, meaning employees who need to know their organization has a response capability in place cannot be told about it through conventional communication channels (Gallagher, 2026). This confidentiality dynamic creates a specific training and protocol challenge that most corporate security programs have not resolved: building institutional awareness of the response architecture without communicating the policy’s existence to the population whose behavior it is designed to shape. The HUB Private Client analysis of the current K&R risk environment documents what genuine pre-incident preparation looks like for high-exposure individuals: evaluate travel patterns across the entire household, assess digital banking application access from the perspective of what a captor could extract under duress, establish emergency communication protocols, vary predictability in routines and locations, and maintain relationships with crisis response professionals who can be activated before an incident escalates (Insurance Business Magazine, 2026). The fundamental principle, as Patti Clement of HUB Private Client put it directly, is that “having resources in place before something happens is critical,” and that the difference between an organization that navigates a K&R incident with limited damage and one that compounds the victim’s trauma through improvised, uninformed response is determined entirely by decisions made before anyone is taken (Insurance Business Magazine, 2026, para. 8).

What a Functioning K&R Program Actually Requires

The K&R program architecture that the insurance market has converged on as operationally necessary for organizations with genuine exposure combines four components that individually provide incomplete protection but together create genuine resilience. The first is intelligence-led country and route risk assessment, not a static annual review of State Department travel advisories, but a continuous monitoring function that tracks the specific threat patterns, incident reporting, and criminal operational dynamics in each country where employees travel, calibrated to the specific profile of those employees. Control Risks’ LatAm Outlook Report 2026 documented that the U.S. designation of several Mexican organized criminal groups as Foreign Terrorist Organizations in January 2025 “significantly altered the legal, reputational and financial risk landscape for companies operating in or with ties to Mexico”, a development whose implications for corporate K&R exposure assessments required real-time analysis, not a scheduled annual review cycle (Control Risks, 2026). An energy company executive traveling to Lagos faces a materially different threat profile than an NGO program officer visiting Nairobi, and both face profiles distinct from a technology company representative attending a cryptocurrency conference in Bogotá. The risk assessment must be as specific as the threat.

The second component is pre-travel preparation, meaning operational briefings that go beyond generic country advisories to cover the specific express kidnapping and fraud tactics documented in the destination, the communication protocols the employee should establish with their organization before departure, the digital hygiene practices that reduce the extractable value of a captured smartphone, and the immediate response steps the employee should take if targeted. The Canadian Government’s Colombia advisory provides the specific operational detail that effective pre-travel briefings must incorporate: express kidnappings “are frequent and often occur in affluent areas, as well as in tourist areas” and victims are “sometimes held overnight so that a second withdrawal can be made the next day”, operational intelligence that shapes the specific protective behaviors a traveler needs to internalize before arrival (Government of Canada, 2026, para. 2). The third component is the K&R insurance policy itself, sized and scoped to the organization’s actual exposure, covering all relevant employees rather than only the most senior, and including the crisis response services that activate the specialized negotiation and response infrastructure when an incident occurs. The Gallagher analysis of policy selection criteria is precise about what constitutes adequate coverage. The response firm must be able to respond worldwide, obtain visas where required, have in-house language capabilities, and have full-time, dedicated response consultants, not a contracted network activated on an ad hoc basis when an incident is already in progress (Gallagher, 2026). The fourth component is post-incident support, the medical care, psychological rehabilitation, legal assistance, and organizational response management that determine whether a victim and their organization recover effectively from an incident whose consequences extend far beyond the duration of the detention itself.

Conclusion

The K&R threat facing business travelers in 2026 is broader, faster, more digitally enabled, and less geographically predictable than the threat model most corporate security programs were designed to address. Express kidnapping, the forced financial extraction that drains a victim’s digital banking access over 24 to 72 hours before release, is the dominant criminal model in Latin America and Sub-Saharan Africa, requiring none of the operational infrastructure of traditional ransom-based kidnapping and generating returns that make every Western business traveler with a smartphone a viable target. The K&R insurance market’s 14% premium growth in 2025 reflects the industry’s own actuarial assessment of how rapidly this threat is spreading across previously lower-risk environments (Market.us, 2026). The crypto-kidnapping surge, the State Department’s April 2026 authorization of non-emergency staff departures from Abuja, and the near-fourfold expansion in K&R policy binding rates documented by HUB Private Client all point in the same direction: organizations that have not yet built a functioning K&R program, intelligence-led threat assessment, pre-travel preparation, adequate insurance coverage, and tested crisis response protocols, are not operating in a risk environment that allows them to defer that investment without consequence.

References

AIG. (2025). CrisiSolution kidnap, ransom and extortion insurance. https://www.aig.com/home/risk-solutions/business/management-and-professional-liability/kidnap-ransom-and-extortion

Control Risks. (2024, November 12). Increase in Mexico’s security risk rating. https://www.controlrisks.com/our-thinking/insights/increase-in-mexico-s-security-risk-rating

Control Risks. (2025). Kidnap, extortion and threat response. https://www.controlrisks.com/our-services/crisis-response/kidnap-extortion-and-threat-response

Control Risks. (2025a). Kidnapping for crypto-ransom: The latest fashion or here to stay? https://www.controlrisks.com/our-thinking/insights/kidnapping-for-crypto-ransom

Control Risks. (2026). Doing business in Latin America: LatAm Outlook Report 2026. https://www.controlrisks.com/campaigns/latam-outlook-report

Gallagher. (2026, March 19). Kidnap and ransom insurance: The insurance coverage no one discusses. https://www.ajg.com/news-and-insights/kidnap-and-ransom-insurance/

Government of Canada. (2026). Travel advice and advisories for Colombia. https://travel.gc.ca/destinations/colombia

Insurance Business Magazine. (2026, March 16). Kidnap-and-ransom insurance demand surges among high-net-worth families. https://www.insurancebusinessmag.com/us/news/travel/kidnapandransom-insurance-demand-surges-among-highnetworth-families-568688.aspx

LegalClarity. (2026, April 16). Is Colombia safe for travelers? US travel advisory for Colombia. https://legalclarity.org/us-travel-advisory-for-colombia-safety-levels-and-risks/

Market.us. (2026, January 27). Kidnap and ransom insurance market growth, size, CAGR. https://market.us/report/kidnap-ransom-insurance-market/

OSAC. (2026a). Mexico country security report. https://www.osac.gov/Content/Report/8f3ac9f0-a827-455f-bf61-1c4142378221

OSAC. (2026b). Nigeria country security report. https://www.osac.gov/Country/Nigeria/Detail

OSAC. (2026c). Colombia country security report. https://www.osac.gov/Content/Report/6d125573-ba04-4021-81c8-1d10613d89a3

OSAC. (2026d). Kenya country security report. https://www.osac.gov/Country/Kenya/Detail

UK Foreign, Commonwealth & Development Office. (2026). Colombia travel advice: Safety and security. https://www.gov.uk/foreign-travel-advice/colombia/safety-and-security

UPI. (2026, February 24). Nancy Guthrie abduction puts focus on ‘kidnap and ransom’ insurance. https://www.upi.com/Top_News/US/2026/02/24/guthrie-abduction-new-focus-kidnap-ransom-insurance/6011771352834/

U.S. Department of State. (2026a). Colombia travel advisory. https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories/colombia-travel-advisory.html

U.S. Department of State. (2026b, April 8). Nigeria travel advisory. https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories/nigeria-travel-advisory.html