The Ransom Bot Is Not Haggling – It Is Taking Away Your Thinking Time

Estimated reading time: 10 minutes

Threat actors are using AI chatbots to negotiate ransoms. Travelers’ Director of Cyber Risk Services says they are not setting the price. They are removing the hours a victim needs to check backups and understand what happened.

The pricing decision is still human. The clock is not.

Matthew Butler, Director of Cyber Risk Services at Travelers, joined the Cyber Insurance News and Information Podcast to walk through the company’s Q2 2026 Cyber Threat Report and what its claims data actually shows about AI in the hands of attackers.

The conversation covers a lot of ground. Why a ransomware group nobody had heard of a year ago is now second in the world by victim count. Whether criminals have frontier-model capability yet, and his flat answer on that. Why he calls multi-factor authentication “definitely not the silver bullet that everyone says it is.” And a half-million-dollar house purchase that went to the wrong bank account and came back.

It starts with the bots.

Get The Podcast Here


Watch On YouTube
Watch Or Listen On Spotify
Listen On Apple Podcasts
Listen On Amazon Music

AI Ransomware Negotiation Automates Urgency, Not Price

Travelers has confirmed threat actors using AI chatbots during ransom negotiations. What those bots do is narrower and smarter than the headlines suggest.

“Our understanding is that bots aren’t negotiating in the sense of deciding what number to accept, but rather they’re using bots which have 24/7 availability across all time zones to expedite the initial rounds of communication,” Butler said.

The effect is on tempo. “AI is being used more for tempo and psychological pressure,” he said. “It’s the automation of urgency and not pricing, if that makes sense. That pricing decision is still very human.”

Think about what pacing buys a victim. Without an instant reply, hours pass. Those hours are when a company stands up its incident response team, works out whether its backups are clean, and starts to understand what was actually taken. An immediate answer at three in the morning removes all of it.

“If someone finds the ransom note and tries to contact that threat actor, if they respond immediately, the victim may be more likely to pay that ransom because they feel that pressure,” Butler said.

For a claims team, that is a severity argument rather than a frequency one. The same incident, negotiated faster, produces a different decision.

Attackers Use AI The Way You Do

Butler’s framing of AI adoption among criminals is the most useful thing in the conversation, because it deflates the mythology without dismissing the risk.

Threat actors are using AI much like you or your company might. “It’s the automation of tasks, but not fully. If I trust it to do 70% of the work, I still need to put in 30% to get it home. And we’re seeing threat actors do the same exact thing,” he said.

The second confirmed use is data triage. Attackers are running AI over exfiltrated material to find what matters, rather than hunting through file structures by hand.

See also  Tax Day = Cyber Scam Day; Watch Out for "Smishing" and "Phishing-as-a-Service (PhaaS)"

There is a practical limit on where they do it. Running heavy analysis inside a victim’s environment burns resources and raises alarms. “Running something inside an environment could be significantly more taxing on infrastructure that could raise more red flags,” Butler said. So the machine work tends to happen after the data leaves.

Take The Cyber Insurance News Survey

Respondents get the results first.

Cyber insurance survey graphic from Cyber Insurance News asking what the market actually sees and whether loss data is good enough, with an eight minute completion time

Is Mythos-Class Capability In Criminal Hands? No.

The Q2 report uses Claude Mythos as shorthand for frontier model risk. Asked directly whether Travelers is saying criminals now have that capability, Butler did not hedge.

“This is a forecast,” he said. “It’s definitely a forecast.”

He points at open-source models closing the gap rather than at the frontier leaking. “Our goal with this report is to focus organizations on hardening against AI-enhanced attacks now while the defenders still have some edge.”

His reasoning is about goalposts. Once the market can see what a top model does, the rest of the field builds toward it. He reaches for cars, which he admits is a habit. One manufacturer shipped good driver assistance, everyone else chased it, and it became a standard selling point.

That assessment sits against the alignment failures Anthropic disclosed this month, where its own models took unauthorized actions against real third-party systems during evaluations. A carrier saying the offensive capability has not reached criminals is a useful counterweight to a developer saying its models misbehaved in testing.

The Gentlemen Came From Nowhere And Took Second Place

The number that surprised Butler was 248. That is how many victims the group operating as The Gentlemen posted to leak sites in Q2, putting them second only to Qilin.

The group did not exist in the data a year ago.

“Starting from nothing is few and far between right now,” Butler said. Groups get disbanded or have their infrastructure seized, and the operators reappear under a new brand carrying everything they learned. “Like any professional team, professional company, they know what to do. They have defined tactics, patterns. They know how to run the business in their space.”

Attribution works through behavior rather than identity. Individual operators hide, but tactics, techniques and procedures travel with them. “Humans are creatures of habit,” Butler said. “They do what works, and by human nature we don’t like failure.”

Regular readers will recognize the name. Gambit Security documented a suspected Gentlemen affiliate running intrusions with Claude Code across six organizations, including an energy utility where the model knocked a firewall offline while trying to reconfigure it. Travelers has the volume. That research has the tradecraft.

Butler declined one question. Asked what being listed on a leak site costs a company beyond the incident itself, he said only that it is impactful to reputation.

A House Purchase, Half A Million Dollars, And A Full Recovery

The business email compromise scenario Butler depicts has a happy ending, which makes it more useful than the usual cautionary tale.

A couple buying a half-million-dollar home received wiring instructions from someone they believed was their attorney. The email came from a look-alike domain rather than the real account. They wired the money.

See also  Ransomware Negotiation, Cyber Insurance, and Cyber Hygiene: Takeaways from Kurtis Minder - NEW PODCAST

When the fraud surfaced, both sides’ attorneys contacted the receiving bank directly. Nothing happened.

What worked was the FBI. The couple filed a complaint with IC3, the Internet Crime Complaint Center, and the recovery asset team triggered what it calls the financial fraud kill chain, requesting a freeze on the receiving account. The money was still sitting there. They got all of it back.

“Full recovery, and it was entirely contingent on that complaint to IC3 and it being filed fast enough so that the funds hadn’t moved out of that second account,” Butler said.

IC3 recorded over $3bn in reported business email compromise losses from almost 25,000 complaints, roughly $123,000 per claim. Butler thinks the real average runs higher, because plenty of victims never file.

The mechanism behind these attacks has shifted. Travelers reports business email compromise claims running 57% higher in the first half of 2026 than the same period last year, driven largely by session token theft. An employee clicks a link, the token leaves the endpoint, and the attacker inherits the session without ever facing a login screen.

Why MFA Stopped Being Enough

Which brings Butler to the control everyone lists first.

“MFA is definitely not the silver bullet that everyone says it is,” he said. It matters, and it has to be enforced, comprehensive, and phishing-resistant. But an attacker holding a valid session token has already cleared authentication.

His recommendation runs past the checkbox. Device-bound passkeys generated inside the device’s security chip. Biometric templates. Anything cryptographic enough that a fake login page produces nothing usable.

For a small manufacturer with no IT director, he names three controls. Phishing-resistant multi-factor authentication on email and anything holding sensitive data. Endpoint detection and response with 24/7 monitoring, because ransomware lands off-hours. And backups on the 3-2-1 rule: three copies, two media types, one offline, offsite, or immutable.

On the monitoring point, he is blunt about who pays for it. “If the AI doesn’t sleep, doesn’t need to eat, it can run all the time,” he said. “If you have someone who can respond to alerts or react faster or live, it could significantly lessen the impact.”

He also wants patch management treated differently in a world of reasoning models. Low and medium vulnerabilities cannot stay parked as technical debt when a model can read source code and find what humans skipped.

Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!

What Butler Would Not Claim

Two moments of restraint are worth recording, because they are rarer than they should be.

On awareness training, he refused the easy answer. “Studies by companies who sell the training tend to show significant reductions in incidents, while independent research tends to be a bit more skeptical.” His view is that both can be true, and the difference is program quality. An annual session every October is not a program.

On leak site data, he named its limits without being pushed hard. There is an unknown gap between real victims and posted ones, and it varies by group. Some post immediately to build pressure. Others sit on the data while they work out whether the victim is worth pursuing. “Not all ransomware victims get listed on a leak site.”

See also  "Fraudulent Instruction" Attack Swipes $690,000 from Senate Campaign 

Ransomware volume held above 2,000 posted victims for a third consecutive quarter, up 53% year over year. Butler reads the slight quarterly dip as a new floor rather than a decline.

His forecast for Q3 comes with an unglamorous explanation. Threat actors take summer holidays, and they come back.

Full Transcript

Download the full transcript of this episode. Transcripts are machine-generated and lightly edited. Accuracy is not guaranteed. Please refer to the audio for the record.

FAQ – AI Ransomware Negotiation

Are ransomware groups using AI to negotiate?

Travelers has confirmed AI chatbots in ransom negotiations. Matthew Butler says the bots are not choosing what number to accept. They provide round-the-clock availability that speeds up early exchanges, applying time pressure while the pricing decision stays with a human operator.

Do criminals have frontier AI model capability yet?

Not according to Travelers. Butler describes the Mythos-class risk in the Q2 report as a forecast rather than an observation, and says the aim is to push organizations to harden their defense while defenders still hold an edge.

How are attackers actually using AI today?

Two confirmed uses. Chatbots to accelerate ransom negotiations, and AI to sort through exfiltrated data for valuable material. Butler compares it to ordinary business use, doing roughly 70 percent of the work with a human finishing the rest.

Is multi-factor authentication still effective?

It remains essential and it is not sufficient. Butler calls it not the silver bullet everyone claims. Session token theft lets attackers bypass authentication entirely, which is why he recommends phishing-resistant methods such as device-bound passkeys.

What should a business do after a fraudulent wire transfer?

File with IC3, the FBI’s Internet Crime Complaint Center, immediately. In the case Butler describes, contacting the receiving bank directly produced nothing, while the IC3 complaint triggered a freeze that recovered nearly 500,000 dollars in full.

Leave a Comment

×