Insiders for Hire: What the Underground Market for Employee Access Tells Us About Insider Risk

The typical image of an insider threat being a disgruntled employee or departing contractor is out of date. Today’s insider is often recruited, not self-motivated, sourced through an underground market of recruiters, brokers and service providers. Even high-profile schemes such as North Korean IT workers hired under false identities are only one part of the picture. Behind them sits a broader underground market where recruiters, brokers and service providers compete to turn employee access into criminal capability. The people adversaries seek aren’t necessarily the most senior or privileged, either. They’re increasingly the employees who control specific workflows.
On a criminal forum in July 2026, one actor offered a US $50,000 referral fee for an introduction to an employee at a major crypto exchange working in KYC or compliance. The actor didn’t want credentials or a database, but a person who controls a specific workflow. Others try to create insider capability through deliberate employment placement. In January 2026, an actor posted offers on a forum seeking unemployed U.S. residents to apply for jobs at a major U.S. telephone carrier and then conduct subscriber identity module (SIM) swaps. Participants were offered a cut of the proceeds rather than upfront payment.
These cases come from our latest white paper, Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services. It examines insider activity at the demand stage, before anything has necessarily happened inside a victim organization. The paper studies what adversaries are asking for, what they are offering and how they are organizing. This provides threat intelligence, insider threat programs and security teams with evidence of adversary demand to help guide external monitoring, detection and resilience strategies. While many insider risk programs are scoped around privileged users, this report gives CTI and security teams evidence to extend that scope to support, logistics, moderation, finance and verification staff.
A year of underground insider activity
Intel 471 analyzed 85 insider-related leads tied to 80 actor handles, collected between Aug. 25, 2025, and Aug. 23, 2026, across criminal forums, Telegram groups, messaging platforms and marketplaces. The sample is limited, and an advertisement doesn't prove a genuine insider exists or that a capability works. It does, however, show what adversaries want and how they are organizing to get it.
Recruitment accounted for 53% of observed records, well ahead of claimed insider access, insider-enabled services and data sales. Much of the underground's energy goes into finding, approaching and converting the people who can deliver internal capabilities, rather than into employees independently selling access.
Workflow beats seniority
For CTI and insider risk teams, the most important finding may be who is being targeted. Privileged IT administrators remain in demand, but they share the target list with KYC personnel, bank tellers, customer support agents, moderation teams, logistics employees and verification staff.
These roles matter because of what they can do. A support agent can reset an account. A carrier employee can perform a SIM swap. A logistics worker in a shipping company can hold or reroute a package. A social media moderator can unban a profile. Each of these outcomes is something an external attacker would otherwise have to work hard to circumvent, and each can be sold as a reusable insider capability across multiple transactions.
The industry data reflects this. Transportation appeared in 22% of leads, technology in 20% and telecommunications in 18%. FedEx and UPS were each named in nine leads, more than any other organization. That concentration reflects demand for repeatable operational workflows, not sector size.
Outcomes as a service
Some actors have stopped selling access altogether and started selling results. The white paper documents one actor advertising a "full-cycle" service at a U.S.-headquartered global logistics firm with a price list ranging from US $30 to $3,000, covering shipment holds, historical shipment data, customs and billing documents, employee correspondence and claims information. Others advertised lookup and account recovery services spanning major telecom, social media, e-commerce and payment platforms, with tiered pricing and escrow.
In this model the customer never meets the insider. The employee stays hidden behind a service provider, and a single internal capability serves many buyers.
Recruitment is being outsourced, and started earlier
The report also exposes a recruitment supply layer. Brokers advertise recruitment-as-a-service, promising to find an insider at a specified company. One actor we profiled in depth published a recruitment guide instructing contractors to build profiles of support staff through LinkedIn and OSINT tools, research their financial circumstances and family details, then approach them sympathetically as a "lifeline" before moving the conversation to Telegram.
At the far end of the spectrum, we examine how the ShadowByt3$ extortion group built a formal insider program offering insiders up to 85% of proceeds, using employees to fill skills gaps its core members lacked.
Learn more in the white paper
Insider risk programs built only around conventionally privileged users may miss much of what adversaries are actually hunting. Security teams need to identify which roles and workflows would be valuable to an outsider, then apply least privilege, segregation of duties, secondary approval for high-risk actions and behavioral monitoring for unusual use of legitimate functions.
Threat intelligence teams should be tracking recruitment posts, access claims and insider-enabled services that mention their organization, brands, employee roles or workflows. This can provide early warning, even when an individual advertisement can't be verified.
The full white paper includes a breakdown of the underground insider ecosystem by role, from recruiters and brokers to self-proclaimed insiders, service providers and operational partners. It maps threat actor objectives, from information retrieval and account manipulation to physical process abuse, fraud, intrusion and intelligence collection. It details recruitment methods including open solicitation, referrals, brokered recruitment, deliberate employment and deceptive recruitment. It compares the compensation models behind insider deals, from per-action payments to revenue sharing and escrow. And our analysts provide practical recommendations across threat intelligence, workflow controls, detection, recruitment resilience and response.
[Download Insiders for Hire to see the full analysis, case studies and recommendations.]
Verity471 customers can access the complete, unredacted report, including firsthand insights from Intel 471's direct actor engagements, and set up automated watchers to track insider recruitment activity targeting their organization.
