# Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026

> Flashpoint Intel Team reports 7,282 unique insider threat posts on dark web forums year to date (average 34/day), with over 75% of July 2026 posts from insiders proactively advertising their legitimate access to third parties. 58.6% of July posts target non-traditional industries, signaling adversaries broadening toward supply chain partners, logistics hubs, manufacturing platforms, and specialized service providers as alternative entry points. The broader underground economy shows initial access broker (IAB) asking prices surging 4,055% year-over-year to an average of $113,275 per listing, driven by a market shift from volume-based access sales to high-impact, high-value enterprise targeting.

- **Published:** 2026-08-20T14:28:37Z
- **Last reviewed:** 2026-08-20T14:28:37Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2078
- **ID:** TL-2026-2078
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This threat intelligence report, published by the Flashpoint Intel Team on August 20, 2026, documents the evolving insider threat recruitment and access broker ecosystem across deep and dark web forums, illicit marketplaces, and encrypted messaging platforms. The analysis draws on data collected via Flashpoint's Primary Source Collection (PSC) engine, which monitors thousands of dark web forums, illicit marketplaces, and underground chat networks.

**Scope and Scale.** Year to date through July 2026, Flashpoint identified 7,282 unique insider threat posts, averaging 34 per day. In July 2026 alone, 12,653 total insider communications were detected, of which 1,132 were classified as unique posts. For context, Flashpoint observed 91,321 instances of insider recruiting, advertising, and threat actor discussions across 10,475 channels involving 17,612 unique authors during the full calendar year 2025 — indicating that 2026 is on track to match or exceed that volume.

**Two Core Mechanisms.** The insider threat ecosystem operates through two distinct but overlapping mechanisms: (1) Insider Recruitment — an employee is actively recruited by an external malicious party, often through social engineering on platforms like Telegram, Signal, or dark web forums; and (2) Insider Advertising — an employee or contractor proactively lists their legitimate access or skills for sale on illicit marketplaces. Critically, over 75% of July 2026 unique posts came from insiders advertising their access, representing a self-motivated, supply-driven market where disgruntled or financially motivated employees actively seek out buyers. The report characterizes a trusted sysadmin 'moonlighting on the deep and dark web, advertising their trust and access to the highest bidder,' with specific offers as low as $15,000 in cryptocurrency to approve a single push notification at 2 AM.

**Industry Shift.** Historically, telecommunications, retail, and financial services were the most adversely affected sectors. In July 2026, 58.6% of unique posts (663 of 1,132) affected 'Other' industries — a marked deviation from historical norms. The remaining posts targeted Financial (150), Retail (112), Technology (84), Telecom (74), Public Sector (43), Healthcare (3), and Media (3). This diversification signals adversaries broadening their target base toward supply chain partners, logistics hubs, manufacturing platforms, and specialized service providers as alternative entry points into high-value networks.

**Convergence with the Initial Access Broker (IAB) Market.** The insider threat ecosystem directly feeds the IAB underground economy. Rapid7's H2 2025 IAB analysis documents a dramatic market transformation: the average alleged victim revenue surged to $3.242 billion (up 45% from $2.232 billion the prior year), while average base asking prices skyrocketed to $113,275 — a 4,055% increase from $2,726. The dominant marketplaces are DarkForums (221 threads, 37.6% of IAB activity) and RAMP (208 threads, 35.4%), together accounting for 81% of observed IAB thread volume. Legacy forums XSS and Exploit have declined sharply as threat actors migrate to newer platforms. Access vectors are predominantly RDP (21.2% of offers), VPN (12.8%), and RDWeb (11.2%), with SSO session cookies and cloud infrastructure credentials (AWS, Azure, GCP) emerging as the fastest-growing premium categories at $3,000–$25,000 per listing. Domain admin access with verified network sketches commands $50,000–$250,000+. Overall listing volumes on public forums are declining (~620 in Q1 2025 to ~370 in Q1 2026), but this reflects migration to private Telegram and Tox channels (Tox usage up 5x from 2.2% to 11.6%), not a reduction in threat activity.

**Threat Actor Activity.** Multiple dedicated IAB actors operate across forums. Notable operators include Big-Bro (active since 2022, selling across DarkForums and RAMP, predominantly Fortinet access), lacrim (an alleged Albanian actor responsible for 78.8% of RAMP IAB threads alongside Big-Bro), Saturned33 (appeared 2025), and Vexin (appeared early 2026). On the recruitment side, a threat actor on the Dready forum (July 7, 2026) actively solicited insiders at Kraken and Charles Schwab, offering $100,000 to $1,000,000 USD for personnel with access to backend infrastructure, KYC verification systems, and internal technical operations. The actor 'LocalVulture,' newly registered on Exploit in January 2026, posted a recruitment solicitation targeting major cryptocurrency exchanges (Binance, CoinTracker, Robinhood, ZenLedger, CoinStats, CoinMarketCap), offering $5,000 per recruited insider plus 15% of all profits, with an accompanying guidance manual on OSINT-based profiling and social engineering of low-level support agents from developing countries.

**Notable 2025 Case Studies.** Among the 91,321 instances tracked by Flashpoint in 2025, specific documented incidents include employees at a government agency accessing 94,000+ individuals' PII for fraud, a cybersecurity insider sharing internal dashboard screenshots with the Scattered Lapsus$ Hunters group, a contractor at a cryptocurrency firm selling customer data and recruiting colleagues, and contractors accessing and deleting sensitive IRS and GSA databases. These cases illustrate that the threat spans government, financial, technology, and critical infrastructure sectors.

**Enabling Factors.** The report identifies that as perimeter security, EDR coverage, and other security tools mature, threat actors are finding it faster and cheaper to target the human element. Identity has become the primary attack surface. Malicious activity relies on valid credentials and legitimate access privileges, meaning internal logs alone are insufficient for detection — breaches are often identified only after data exfiltration or system sabotage has occurred. The Mimecast State of Human Risk 2026 report corroborates this: 42% of organizations reported an increase in malicious insider incidents (up from 33% in 2024), with insider-related incidents now at parity with negligent incidents for the first time. The average organization experiences 6 insider-driven incidents per month at an estimated $13.1 million per incident. Despite 66% of organizations expecting insider-related data loss to increase, only 59% have deployed behavioral analytics, and only 28% coordinate training with continuous monitoring.

**Outlook.** Threat actors are migrating from Telegram (following bans on illicit groups) to Signal and other encrypted platforms where monitoring is harder. The AI sector is emerging as a high-value target as companies accumulate proprietary model weights and training data. The insider recruitment pipeline has become formalized — brokers, escrow services, referral bonuses, and recurring partnerships now operate openly. This ecosystem directly enables ransomware operations, data extortion, corporate espionage, and financial fraud at scale.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1078.002 Domain Accounts
- T1078.004 Cloud Accounts
- T1204 User Execution
- T1098 Account Manipulation
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1518 Software Discovery
- T1021.001 Remote Desktop Protocol
- T1550.004 Web Session Cookie
- T1530 Data from Cloud Storage
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1095 Non-Application Layer Protocol
- T1048 Exfiltration Over Alternative Protocol
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction

## Sources

- [Insider Threat Report: Dark Web Recruitment & Access Trends](https://flashpoint.io/blog/insider-threat-report-dark-web-recruitment-access-trends/)
- [Insider Threats: Turning 2025 Intelligence into a 2026 Defense Strategy](https://flashpoint.io/blog/insider-threat-defense-2026/)
- [Initial Access Brokers Shift to High-Value Targets with Premium Pricing](https://www.rapid7.com/blog/post/tr-initial-access-broker-shift-high-value-targets-premium-pricing/)
- [Mimecast State of Human Risk 2026](https://www.mimecast.com/resources/press-releases/sohr-26/)
- [Brinztech Alert: Analysis of Insider Threat Recruitment Solicitation](https://www.brinztech.com/breach-alerts/brinztech-alert-analysis-of-insider-threat-recruitment-solicitation/)
- [Insider Threats & Digital Recruitment: A Growing Risk](https://nisos.com/research/insider-threat-digital-recruitment-marketplace/)
- [ZeroFox Flash Report — LocalVulture Insider Recruitment](https://www.zerofox.com/intelligence/)
- [Ransomnews — Initial Access Brokers Pricing in 2026](https://ransomnews.com/initial-access-brokers-pricing-2026/)
- [Cyble — Dark Web Trends 2026](https://cyble.com/blog/dark-web-trends-2026-cyber-threat-landscape/)
- [TrendAI — Insider Recruitment as a Structured Underground Economy](https://trendai.security/)
- [Cybersecurity Insiders — 2024 Insider Threat Report](https://www.cybersecurity-insiders.com/insider-threat-report-2024/)
- [Check Point — Ransomware Groups Recruiting Insiders via Telegram](https://blog.checkpoint.com/)
- [Microsoft — Jasper Sleet North Korean IT Worker Infiltration](https://www.microsoft.com/en-us/security/blog/)
- [DataBreaches.net — Research Report: The Insider Threat Digital Recruitment Marketplace](https://databreaches.net/2025/01/23/research-report-the-insider-threat-digital-recruitment-marketplace/)
- [HelpNetSecurity — Insider Recruitment Posts Function Like Job Listings on Criminal Forums](https://www.helpnetsecurity.com/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2078
