Intel 471

Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services.

Threat actors are increasingly targeting employees for the access, capabilities and workflows they control. Intel 471's latest report examines the underground insider ecosystem, drawing on 85 insider-related leads linked to 80 actor handles collected between August 2025 and August 2026.

In this report, you'll learn about:

  • How threat actors recruit insiders through open solicitations, targeted approaches, referrals, brokers and deceptive recruitment
  • The types of insider capabilities being sought, including restricted information, account manipulation, SIM swaps, shipment intervention, fraud, intrusion and extortion
  • How insider access and capabilities are monetized through one-time payments, referral fees, revenue sharing and ongoing arrangements
  • How threat actors turn employee privileges into repeatable, customer-facing services and outsource insider-enabled activity
  • Why transportation, technology and telecommunications were among the sectors with the highest concentration of observed insider-related activity

Download Intel 471's report Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services to explore how threat actors source, monetize and operationalize insider capabilities.

Loading form...