Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services.

Threat actors are increasingly targeting employees for the access, capabilities and workflows they control. Intel 471's latest report examines the underground insider ecosystem, drawing on 85 insider-related leads linked to 80 actor handles collected between August 2025 and August 2026.
In this report, you'll learn about:
- How threat actors recruit insiders through open solicitations, targeted approaches, referrals, brokers and deceptive recruitment
- The types of insider capabilities being sought, including restricted information, account manipulation, SIM swaps, shipment intervention, fraud, intrusion and extortion
- How insider access and capabilities are monetized through one-time payments, referral fees, revenue sharing and ongoing arrangements
- How threat actors turn employee privileges into repeatable, customer-facing services and outsource insider-enabled activity
- Why transportation, technology and telecommunications were among the sectors with the highest concentration of observed insider-related activity
Download Intel 471's report Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services to explore how threat actors source, monetize and operationalize insider capabilities.
Loading form...
