Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles
Insiders for Hire (TL-2026-2799), also tracked as Insiders for Hire, is a medium-severity tracked intrusion set, first published 2026-09-30. It is attributed to SHADOWBYT3$ with low confidence, affects Multiple Employee/insider access at transportation, technology, maps to 9 MITRE ATT&CK techniques (T1078, T1199, T1213), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2799
- Threat ID
- TL-2026-2799
- Also known as
- Insiders for Hire, Criminal insider recruitment market
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution
- SHADOWBYT3$
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- transport, technology, telecoms, finance, cryptocurrency, social-media, ecommerce, payments
- Target regions
- Global, North America, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Insiders for Hire
Malware and tooling: shadowbyt3$, telegram
Intel 471 analyzed 85 insider-related leads across 80 actor handles (Aug 25, 2025 - Aug 23, 2026) and found recruitment accounts for 53% of observed activity. Adversaries increasingly target support, KYC, logistics and verification staff, and some actors have moved from selling access to outcome-based insider services priced at $30-$3,000.
How Insiders for Hire works
Intel 471 (published 2026-09-29) reviewed 85 insider-related leads tied to 80 actor handles collected from criminal forums, Telegram groups, messaging platforms and marketplaces between 2025-08-25 and 2026-08-23. Recruitment of insiders made up 53% of observed records; the remainder comprised claimed insider access, insider-enabled services and data sales. Leads concentrated in transportation (22%), technology (20%) and telecommunications (18%). FedEx and UPS were each named in nine leads, the highest concentration of any organization.
The market is broadening beyond privileged IT roles. Targeted roles include KYC/compliance personnel, bank tellers, customer support agents, moderation teams, logistics employees, verification staff and IT administrators. Documented recruitment methods are open solicitation, referrals, brokered recruitment, deliberate employment placement, and deceptive recruitment in which actors profile staff using LinkedIn/OSINT and approach financially vulnerable employees with a sympathetic 'lifeline' pitch. Compensation models include per-action payments, revenue sharing, escrow arrangements and referral fees.
Notable cited examples: in July 2026 one actor offered a US $50,000 referral fee for an introduction to an employee at a major crypto exchange working in KYC or compliance; in January 2026 an actor posted on a forum seeking unemployed U.S. residents to apply for jobs at a major U.S. telephone carrier and then conduct SIM swaps; a logistics-focused seller priced 'outcomes as a service' from $30 to $3,000 (shipment holds, historical data, customs documents, employee correspondence, claims information); and the extortion group ShadowByt3$ operates a formal insider program offering insiders up to 85% revenue share under a tiered structure. Third-party reporting corroborates the trend: TrendAI (2026-08-07) cites FedEx employee access at $1,000 per day, account-ban removal at $1,000-$7,000, and one-in-eight British workers having sold logins or knowing someone who has (Cifas); Flashpoint (2026-08-20) counted 7,282 unique insider-threat posts, 34 unique posts per day on average, 12,653 total insider posts in July 2026, and a $15,000 crypto offer to approve a single push notification. ShadowByt3$ itself is tracked by ransomware.live and others as a double-extortion RaaS group first observed October 2025 with a small victim list (21 confirmed, including Starbucks, Nintendo and University of Georgia); the insider-program details come only from Intel 471 and were not independently corroborated.
No CVEs, malware hashes or IP infrastructure are stated in the sources. This is trend intelligence on an active criminal market rather than a discrete intrusion, so severity is conservative.
MITRE ATT&CK techniques used in TL-2026-2799
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship
Collection
T1213 Data from Information Repositories
initial-access
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information
Credential Access
T1621 Multi-Factor Authentication Request Generation
Resource Development
Impact
Affected products and versions in Insiders for Hire
- Multiple — Employee/insider access at transportation, technology, telecommunications, financial, crypto-exchange and platform organizations
Vulnerable versions: N/A - human/process risk
Remediation for Insiders for Hire
Immediate actions
- Monitor underground forums, Telegram and marketplaces for recruitment posts that mention your organization, brands, roles or workflows
- Require secondary approval for high-risk actions (SIM swaps, shipment holds, account recovery, KYC overrides, bulk data export)
Workarounds
- Limit standing access to customer data and internal tooling; use just-in-time access for sensitive functions
Longer-term hardening
- Enforce least privilege and segregation of duties for support, KYC, verification and logistics roles
- Deploy behavioral monitoring for unusual use of legitimate functions by staff
- Build an insider-risk program covering financially vulnerable staff and third-party/contractor placement
Timeline of Insiders for Hire
- Start of Intel 471's observation window for insider-related leads (85 leads across 80 actor handles through 2026-08-23)
- ShadowByt3$ first observed (October 2025) as a Telegram/Tox-based double-extortion RaaS group; day not specified in sources
- Actor posts on a forum (January 2026) seeking unemployed U.S. residents to get jobs at a major U.S. telephone carrier and perform SIM swaps; day not specified
- ShadowByt3$ attacks Starbucks and demands $500,000 in cryptocurrency (per SOCRadar/WatchGuard-indexed reporting); Starbucks refuses to pay
- Actor offers a $50,000 referral fee for an introduction to a KYC/compliance employee at a major crypto exchange (July 2026); day not specified
- TrendAI/ITPro report a structured Telegram and forum insider market: FedEx access at $1,000/day, account-ban removal at $1,000-$7,000
- Flashpoint publishes July 2026 data: 12,653 insider posts, 7,282 unique yearly posts, 34 unique posts/day, and a $15,000 offer to approve one push notification
- End of Intel 471's observation window
- Intel 471 publishes 'Insiders for Hire' finding recruitment is 53% of activity and outcome-based services are priced $30-$3,000
Sources cited for Insiders for Hire
- Insiders for Hire: What the Underground Market for Employee Access Tells Us About Insider Risk (Intel 471)
- Hackers are building a global insider threat recruitment network and offering referral bonuses (ITPro / TrendAI)
- Insider Threat Report: Dark Web Recruitment and Access Trends (Flashpoint)
- ShadowByt3$ group profile (ransomware.live)
- ShadowByt3$ ransomware intelligence (SOCRadar)
- ShadowByt3$ ransomware tracker (WatchGuard)
More in threat intel
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt Injection
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
Detection coverage for TL-2026-2799
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2799 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.