Threat reportThreat IntelligenceTL-2026-2078

Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026

mediumACTIVE

Insider Threat Landscape (TL-2026-2078), also tracked as Insider-as-a-Service, is a medium-severity tracked intrusion set, first published 2026-08-20. It has no confirmed attribution, affects Financial Services Banking and Cryptocurrency Platforms, maps to 19 MITRE ATT&CK techniques (T1005, T1021.001, T1048), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-2078

Threat ID
TL-2026-2078
Also known as
Insider-as-a-Service, Insider Recruitment Ecosystem, IAB Underground Economy
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial-services, telecoms, government administration, technology, retail, health, news - media, manufacturing, logistics, supply-chain, cryptocurrency, critical-infrastructure
Target regions
North America, Europe, Asia, Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in Insider Threat Landscape

Malware and tooling: telegram

How Insider Threat Landscape works

Flashpoint Intel Team reports 7,282 unique insider threat posts on dark web forums year to date (average 34/day), with over 75% of July 2026 posts from insiders proactively advertising their legitimate access to third parties. 58.6% of July posts target non-traditional industries, signaling adversaries broadening toward supply chain partners, logistics hubs, manufacturing platforms, and specialized service providers as alternative entry points. The broader underground economy shows initial access broker (IAB) asking prices surging 4,055% year-over-year to an average of $113,275 per listing, driven by a market shift from volume-based access sales to high-impact, high-value enterprise targeting.

This threat intelligence report, published by the Flashpoint Intel Team on August 20, 2026, documents the evolving insider threat recruitment and access broker ecosystem across deep and dark web forums, illicit marketplaces, and encrypted messaging platforms. The analysis draws on data collected via Flashpoint's Primary Source Collection (PSC) engine, which monitors thousands of dark web forums, illicit marketplaces, and underground chat networks.

**Scope and Scale.** Year to date through July 2026, Flashpoint identified 7,282 unique insider threat posts, averaging 34 per day. In July 2026 alone, 12,653 total insider communications were detected, of which 1,132 were classified as unique posts. For context, Flashpoint observed 91,321 instances of insider recruiting, advertising, and threat actor discussions across 10,475 channels involving 17,612 unique authors during the full calendar year 2025 — indicating that 2026 is on track to match or exceed that volume.

**Two Core Mechanisms.** The insider threat ecosystem operates through two distinct but overlapping mechanisms: (1) Insider Recruitment — an employee is actively recruited by an external malicious party, often through social engineering on platforms like Telegram, Signal, or dark web forums; and (2) Insider Advertising — an employee or contractor proactively lists their legitimate access or skills for sale on illicit marketplaces. Critically, over 75% of July 2026 unique posts came from insiders advertising their access, representing a self-motivated, supply-driven market where disgruntled or financially motivated employees actively seek out buyers. The report characterizes a trusted sysadmin 'moonlighting on the deep and dark web, advertising their trust and access to the highest bidder,' with specific offers as low as $15,000 in cryptocurrency to approve a single push notification at 2 AM.

**Industry Shift.** Historically, telecommunications, retail, and financial services were the most adversely affected sectors. In July 2026, 58.6% of unique posts (663 of 1,132) affected 'Other' industries — a marked deviation from historical norms. The remaining posts targeted Financial (150), Retail (112), Technology (84), Telecom (74), Public Sector (43), Healthcare (3), and Media (3). This diversification signals adversaries broadening their target base toward supply chain partners, logistics hubs, manufacturing platforms, and specialized service providers as alternative entry points into high-value networks.

**Convergence with the Initial Access Broker (IAB) Market.** The insider threat ecosystem directly feeds the IAB underground economy. Rapid7's H2 2025 IAB analysis documents a dramatic market transformation: the average alleged victim revenue surged to $3.242 billion (up 45% from $2.232 billion the prior year), while average base asking prices skyrocketed to $113,275 — a 4,055% increase from $2,726. The dominant marketplaces are DarkForums (221 threads, 37.6% of IAB activity) and RAMP (208 threads, 35.4%), together accounting for 81% of observed IAB thread volume. Legacy forums XSS and Exploit have declined sharply as threat actors migrate to newer platforms. Access vectors are predominantly RDP (21.2% of offers), VPN (12.8%), and RDWeb (11.2%), with SSO session cookies and cloud infrastructure credentials (AWS, Azure, GCP) emerging as the fastest-growing premium categories at $3,000–$25,000 per listing. Domain admin access with verified network sketches commands $50,000–$250,000+. Overall listing volumes on public forums are declining (~620 in Q1 2025 to ~370 in Q1 2026), but this reflects migration to private Telegram and Tox channels (Tox usage up 5x from 2.2% to 11.6%), not a reduction in threat activity.

**Threat Actor Activity.** Multiple dedicated IAB actors operate across forums. Notable operators include Big-Bro (active since 2022, selling across DarkForums and RAMP, predominantly Fortinet access), lacrim (an alleged Albanian actor responsible for 78.8% of RAMP IAB threads alongside Big-Bro), Saturned33 (appeared 2025), and Vexin (appeared early 2026). On the recruitment side, a threat actor on the Dready forum (July 7, 2026) actively solicited insiders at Kraken and Charles Schwab, offering $100,000 to $1,000,000 USD for personnel with access to backend infrastructure, KYC verification systems, and internal technical operations. The actor 'LocalVulture,' newly registered on Exploit in January 2026, posted a recruitment solicitation targeting major cryptocurrency exchanges (Binance, CoinTracker, Robinhood, ZenLedger, CoinStats, CoinMarketCap), offering $5,000 per recruited insider plus 15% of all profits, with an accompanying guidance manual on OSINT-based profiling and social engineering of low-level support agents from developing countries.

**Notable 2025 Case Studies.** Among the 91,321 instances tracked by Flashpoint in 2025, specific documented incidents include employees at a government agency accessing 94,000+ individuals' PII for fraud, a cybersecurity insider sharing internal dashboard screenshots with the Scattered Lapsus$ Hunters group, a contractor at a cryptocurrency firm selling customer data and recruiting colleagues, and contractors accessing and deleting sensitive IRS and GSA databases. These cases illustrate that the threat spans government, financial, technology, and critical infrastructure sectors.

**Enabling Factors.** The report identifies that as perimeter security, EDR coverage, and other security tools mature, threat actors are finding it faster and cheaper to target the human element. Identity has become the primary attack surface. Malicious activity relies on valid credentials and legitimate access privileges, meaning internal logs alone are insufficient for detection — breaches are often identified only after data exfiltration or system sabotage has occurred. The Mimecast State of Human Risk 2026 report corroborates this: 42% of organizations reported an increase in malicious insider incidents (up from 33% in 2024), with insider-related incidents now at parity with negligent incidents for the first time. The average organization experiences 6 insider-driven incidents per month at an estimated $13.1 million per incident. Despite 66% of organizations expecting insider-related data loss to increase, only 59% have deployed behavioral analytics, and only 28% coordinate training with continuous monitoring.

**Outlook.** Threat actors are migrating from Telegram (following bans on illicit groups) to Signal and other encrypted platforms where monitoring is harder. The AI sector is emerging as a high-value target as companies accumulate proprietary model weights and training data. The insider recruitment pipeline has become formalized — brokers, escrow services, referral bonuses, and recurring partnerships now operate openly. This ecosystem directly enables ransomware operations, data extortion, corporate espionage, and financial fraud at scale.

MITRE ATT&CK techniques used in TL-2026-2078

Collection

T1005 Data from Local System; T1530 Data from Cloud Storage

Lateral Movement

T1021.001 Remote Desktop Protocol; T1550.004 Web Session Cookie

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Discovery

T1069 Permission Groups Discovery; T1087 Account Discovery; T1518 Software Discovery

Command and Control

T1071.001 Web Protocols; T1095 Non-Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1078.002 Domain Accounts; T1078.004 Cloud Accounts

Persistence

T1098 Account Manipulation

Execution

T1204 User Execution

Impact

T1485 Data Destruction

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

Affected products and versions in Insider Threat Landscape

  • Financial Services — Banking and Cryptocurrency Platforms
    Vulnerable versions: Kraken; Charles Schwab; Binance; Robinhood; CoinTracker; ZenLedger; CoinStats; CoinMarketCap
  • Telecommunications — Mobile Carrier Infrastructure
    Vulnerable versions: SIM-swap-accessible carriers — 42% of 2025 insider posts targeted Telecom
  • Government — Public Sector Agencies
    Vulnerable versions: Federal agencies — 14.2% of H2 2025 IAB listings targeted Government
  • Technology — Enterprise SaaS and Cloud Infrastructure
    Vulnerable versions: M365 tenants; Okta deployments; Google Workspace; AWS; Azure; GCP environments
  • Retail — E-Commerce Platforms
    Vulnerable versions: Major online retailers — 13.1% of IAB listings
  • Supply Chain and Manufacturing — Logistics and Production Infrastructure
    Vulnerable versions: Logistics hubs; manufacturing platforms; supply chain partners — 58.6% of July 2026 posts target 'Other' industries

Remediation for Insider Threat Landscape

Immediate actions

  • Deploy external threat intelligence monitoring of dark web forums for mentions of corporate domains, VPN endpoints, and employee recruitment solicitations
  • Implement credential leak monitoring across infostealer logs and illicit marketplaces
  • Enforce multi-party authorization (MPA) for all high-risk operations including privileged account changes, large data transfers, and production deployments
  • Audit all privileged access accounts and remove stale or unnecessary permissions

Workarounds

  • Replace SMS-based authentication with hardware security keys (FIDO2/WebAuthn) to prevent SIM-swap-enabled account takeover
  • Enforce strict VPN segmentation with per-application access policies rather than full network-level access
  • Implement impossible-travel analytics and new-hire data access monitoring for North Korean IT worker infiltration vector
  • Deploy data loss prevention (DLP) controls on cloud storage and SaaS platforms

Longer-term hardening

  • Deploy User and Entity Behavior Analytics (UEBA) to detect anomalous data downloads, off-hours access, and unauthorized software installation
  • Implement strict least-privilege access controls with zero-standing-privilege for cloud and on-premises infrastructure
  • Establish continuous dark web and encrypted channel monitoring for insider recruitment targeting key personnel
  • Deploy session token rotation and hardware-bound authentication to mitigate SSO cookie theft and MFA bypass
  • Implement rigorous third-party vendor risk management programs addressing supply chain access
  • Integrate HR and security workflows for automated offboarding and insider risk flagging

Weaknesses (CWE) in Insider Threat Landscape

CWE-287, CWE-522, CWE-798, CWE-863

Timeline of Insider Threat Landscape

  • Nisos begins monitoring a rapid increase in insider threat activities across mainstream and alternative social media platforms, cloud-based messaging applications, and dark web forums
  • IAB actor Big-Bro begins operating across dark web forums, predominantly selling Fortinet access, establishing a long-tenured presence in the underground IAB economy
  • Nisos identifies a thriving insider threat digital recruitment marketplace spanning Telegram, dark web forums, and cloud-based messaging apps — targeting telecommunications, e-commerce, and refund service sectors. 83% of organizations report at least one insider attack in the preceding year, a 5x increase over 2023
  • Flashpoint observes 91,321 instances of insider recruiting, advertising, and threat actor discussions across 10,475 channels involving 17,612 unique authors during calendar year 2025 — averaging 1,162 posts per month
  • DarkForums and RAMP overtake legacy forums XSS and Exploit as the dominant IAB marketplaces, driven by law enforcement seizures and user migration. DarkForums and RAMP together account for 81% of IAB thread volume in H2 2025
  • IAB actor Saturned33 appears on dark web forums, joining the underground access broker economy alongside established operators
  • IntelBroker (Kai West), a dominant IAB actor on BreachForums, is apprehended by law enforcement, contributing to BreachForums' 52% year-over-year decline in IAB thread volume
  • Flashpoint documents multiple insider threat incidents including: government agency employees accessing 94,000+ individuals' PII for fraud; a cybersecurity insider sharing internal dashboard screenshots with the Scattered Lapsus$ Hunters group; a cryptocurrency contractor selling customer data and recruiting colleagues
  • Rapid7 H2 2025 IAB analysis reveals dramatic market transformation: average victim revenue surges to $3.242B (up 45%) and average base asking prices skyrocket to $113,275 (up 4,055% from $2,726), driven by premium listings on DarkForums
  • Threat actor 'LocalVulture' registers on the Exploit dark web forum
  • LocalVulture posts a recruitment solicitation on Exploit seeking partners to recruit insiders at major cryptocurrency exchanges (Binance, CoinTracker, Robinhood, ZenLedger, CoinStats, CoinMarketCap), offering $5,000 per recruited insider plus 15% profit share and a guidance manual on OSINT-based profiling
  • IAB actor Vexin appears on the dark web, joining the underground access broker market alongside Saturned33 and Big-Bro
  • Microsoft reports on the Jasper Sleet threat actor (North Korea-aligned) exploiting hybrid hiring by posing as legitimate IT workers using stolen identities and AI-assisted deception, onboarding through HR SaaS workflows to access internal systems
  • A threat actor on the Dready dark web forum actively recruits insiders at Kraken and Charles Schwab, offering $100,000 to $1,000,000 USD for personnel with access to backend infrastructure, KYC verification systems, and internal technical operations
  • July 2026 closes with 1,132 unique insider threat posts observed — over 75% from insiders advertising their access to third parties. 58.6% of posts target non-traditional industries, signaling a strategic broadening of adversary targeting toward supply chain, logistics, manufacturing, and specialized service providers
  • Flashpoint Intel Team publishes the Insider Threat Report: Dark Web Recruitment & Access Trends — July 2026, documenting 7,282 unique insider threat posts YTD (average 34/day) and detailing the convergence of insider advertising and the IAB economy

Sources cited for Insider Threat Landscape

Detection coverage for TL-2026-2078

As of 2026-08-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2078 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats