Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles

Insiders for Hire (TL-2026-2799), also tracked as Insiders for Hire, is a medium-severity tracked intrusion set, first published 2026-09-30. It is attributed to SHADOWBYT3$ with low confidence, affects Multiple Employee/insider access at transportation, technology, maps to 9 MITRE ATT&CK techniques (T1078, T1199, T1213), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2799

Threat ID
TL-2026-2799
Also known as
Insiders for Hire, Criminal insider recruitment market
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-30
Last reviewed
2026-09-30
Attribution
SHADOWBYT3$
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
transport, technology, telecoms, finance, cryptocurrency, social-media, ecommerce, payments
Target regions
Global, North America, united kingdom
Detection rules
9
Indicators of compromise
10

Malware and tooling in Insiders for Hire

Malware and tooling: shadowbyt3$, telegram

Intel 471 analyzed 85 insider-related leads across 80 actor handles (Aug 25, 2025 - Aug 23, 2026) and found recruitment accounts for 53% of observed activity. Adversaries increasingly target support, KYC, logistics and verification staff, and some actors have moved from selling access to outcome-based insider services priced at $30-$3,000.

How Insiders for Hire works

Intel 471 (published 2026-09-29) reviewed 85 insider-related leads tied to 80 actor handles collected from criminal forums, Telegram groups, messaging platforms and marketplaces between 2025-08-25 and 2026-08-23. Recruitment of insiders made up 53% of observed records; the remainder comprised claimed insider access, insider-enabled services and data sales. Leads concentrated in transportation (22%), technology (20%) and telecommunications (18%). FedEx and UPS were each named in nine leads, the highest concentration of any organization.

The market is broadening beyond privileged IT roles. Targeted roles include KYC/compliance personnel, bank tellers, customer support agents, moderation teams, logistics employees, verification staff and IT administrators. Documented recruitment methods are open solicitation, referrals, brokered recruitment, deliberate employment placement, and deceptive recruitment in which actors profile staff using LinkedIn/OSINT and approach financially vulnerable employees with a sympathetic 'lifeline' pitch. Compensation models include per-action payments, revenue sharing, escrow arrangements and referral fees.

Notable cited examples: in July 2026 one actor offered a US $50,000 referral fee for an introduction to an employee at a major crypto exchange working in KYC or compliance; in January 2026 an actor posted on a forum seeking unemployed U.S. residents to apply for jobs at a major U.S. telephone carrier and then conduct SIM swaps; a logistics-focused seller priced 'outcomes as a service' from $30 to $3,000 (shipment holds, historical data, customs documents, employee correspondence, claims information); and the extortion group ShadowByt3$ operates a formal insider program offering insiders up to 85% revenue share under a tiered structure. Third-party reporting corroborates the trend: TrendAI (2026-08-07) cites FedEx employee access at $1,000 per day, account-ban removal at $1,000-$7,000, and one-in-eight British workers having sold logins or knowing someone who has (Cifas); Flashpoint (2026-08-20) counted 7,282 unique insider-threat posts, 34 unique posts per day on average, 12,653 total insider posts in July 2026, and a $15,000 crypto offer to approve a single push notification. ShadowByt3$ itself is tracked by ransomware.live and others as a double-extortion RaaS group first observed October 2025 with a small victim list (21 confirmed, including Starbucks, Nintendo and University of Georgia); the insider-program details come only from Intel 471 and were not independently corroborated.

No CVEs, malware hashes or IP infrastructure are stated in the sources. This is trend intelligence on an active criminal market rather than a discrete intrusion, so severity is conservative.

MITRE ATT&CK techniques used in TL-2026-2799

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship

Collection

T1213 Data from Information Repositories

initial-access

T1451 SIM Card Swap

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information

Credential Access

T1621 Multi-Factor Authentication Request Generation

Resource Development

T1650 Acquire Access

Impact

T1657 Financial Theft

Affected products and versions in Insiders for Hire

  • Multiple — Employee/insider access at transportation, technology, telecommunications, financial, crypto-exchange and platform organizations
    Vulnerable versions: N/A - human/process risk

Remediation for Insiders for Hire

Immediate actions

  • Monitor underground forums, Telegram and marketplaces for recruitment posts that mention your organization, brands, roles or workflows
  • Require secondary approval for high-risk actions (SIM swaps, shipment holds, account recovery, KYC overrides, bulk data export)

Workarounds

  • Limit standing access to customer data and internal tooling; use just-in-time access for sensitive functions

Longer-term hardening

  • Enforce least privilege and segregation of duties for support, KYC, verification and logistics roles
  • Deploy behavioral monitoring for unusual use of legitimate functions by staff
  • Build an insider-risk program covering financially vulnerable staff and third-party/contractor placement

Timeline of Insiders for Hire

  • Start of Intel 471's observation window for insider-related leads (85 leads across 80 actor handles through 2026-08-23)
  • ShadowByt3$ first observed (October 2025) as a Telegram/Tox-based double-extortion RaaS group; day not specified in sources
  • Actor posts on a forum (January 2026) seeking unemployed U.S. residents to get jobs at a major U.S. telephone carrier and perform SIM swaps; day not specified
  • ShadowByt3$ attacks Starbucks and demands $500,000 in cryptocurrency (per SOCRadar/WatchGuard-indexed reporting); Starbucks refuses to pay
  • Actor offers a $50,000 referral fee for an introduction to a KYC/compliance employee at a major crypto exchange (July 2026); day not specified
  • TrendAI/ITPro report a structured Telegram and forum insider market: FedEx access at $1,000/day, account-ban removal at $1,000-$7,000
  • Flashpoint publishes July 2026 data: 12,653 insider posts, 7,282 unique yearly posts, 34 unique posts/day, and a $15,000 offer to approve one push notification
  • End of Intel 471's observation window
  • Intel 471 publishes 'Insiders for Hire' finding recruitment is 53% of activity and outcome-based services are priced $30-$3,000

Sources cited for Insiders for Hire

More in threat intel

Detection coverage for TL-2026-2799

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2799 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats