Many ransomware incidents begin with a transaction rather than a hack. Initial access brokers sell working access harvested from infostealer logs or exposed remote services. Organisations can measure part of their risk from outside by watching for their own credentials and remote-access exposure.
The narrative of a ransomware attack often begins with a breach. We imagine a sophisticated actor bypassing firewalls or exploiting a zero-day vulnerability in a critical service. This image suggests a contest of technical skill between defender and attacker. The reality is frequently more mundane and more commercial.
The intrusion you suffer was often bought, and your leaked logins set the price. A growing segment of the cybercrime ecosystem operates as a marketplace for entry. These actors do not necessarily write malware or build complex exploit chains. They harvest and sell the keys that open the door.
This shift changes how we must view our defensive posture. We cannot rely solely on perimeter defence if the keys are already in the hands of criminals. We must understand the mechanics of this trade. We must recognise that many ransomware groups are now customers of these supply chains.
What an access broker sells
The product is not abstract potential. It is verified, working access to a specific organisation. Brokers sell the ability to log in as a user who already has network privileges. This access is often granted through remote desktop protocols or web applications that are already trusted by the victim’s infrastructure.
The value lies in the time saved. A ransomware group that purchases access skips the initial phase of discovery and exploitation. They start with a foothold inside the perimeter. This allows them to move laterally and deploy their payload much faster. Speed is critical in ransomware operations because it reduces the window for detection and response.
Brokers often provide additional context with the access credentials. They may include screenshots of the internal network. They might list the software installed on the compromised machine. This information helps the buyer assess the value of the target. It confirms that the target is a viable candidate for encryption.
The transaction is straightforward. The buyer pays for a specific set of credentials. The seller verifies that the credentials still work. Once the payment clears, the access is transferred. The buyer then uses this access to establish persistence and escalate privileges.
Where the inventory comes from
The inventory for these brokers is harvested from multiple sources. One primary source is infostealer malware. This type of malware runs on employee devices and captures saved passwords. It extracts session cookies and browser history. The data is then exfiltrated to command and control servers.
These stolen credentials are often sold in bulk. Brokers aggregate these logs from various sources. They clean the data and verify which accounts are active. They then list these accounts on underground forums or private marketplaces. The price depends on the perceived value of the account.
Another source is exposed remote services. Many organisations leave remote desktop protocol ports open to the internet. These services are often poorly configured or lack multi-factor authentication. Automated scanners probe these ports and attempt to log in using common username and password combinations.
When a scan succeeds, the access is recorded. The broker adds this verified access to their inventory. The process is automated and scalable. It allows brokers to build a large catalogue of potential targets. The inventory is constantly updated as new credentials are stolen or new services are exposed.
The overlap between these sources is significant. A single employee might have their credentials stolen via malware and also use those same credentials to access an exposed service. This creates multiple opportunities for brokers to sell the same access. It also increases the likelihood that the access will be sold to multiple buyers.
From listing to intrusion
The journey from a listing to an active intrusion is short. A ransomware affiliate browses the marketplace for suitable targets. They filter by industry, size, or specific software. They look for accounts with high privileges or access to critical systems.
Once a target is identified, the affiliate purchases the access. They verify the credentials themselves. They may attempt to log in during off-hours to avoid detection. If the login succeeds, they establish a foothold. They often deploy a small agent to maintain access. This agent survives reboots and credential changes.
The affiliate then moves laterally within the network. They search for sensitive data and backup systems. They map the network topology to identify high-value targets. This phase is where the real damage begins. The ransomware group prepares to encrypt the data they have found.
The broker’s role typically ends after the sale. However, some brokers offer ongoing support. They may provide additional credentials if the initial access is revoked. They might offer guidance on bypassing security controls. This support increases the value of their product.
The speed of this process is alarming. An organisation may have its access sold and exploited within days of the credentials being stolen. This rapid cycle makes traditional detection methods less effective. We need to detect the sale, not just the intrusion.
Watching your own exposure
Organisations can measure part of their risk from outside. They can monitor the dark web for their own credentials. This involves searching for their domain name in stolen data dumps. It also includes monitoring for their IP addresses in exposed service lists.
Tools are available to alert you when your data appears in breaches. These tools scan underground forums and paste sites. They notify you if your employees’ credentials are found. This allows you to reset passwords before they are exploited.
You should also audit your external attack surface. Identify all services exposed to the internet. Check for any that use default credentials or weak authentication. Remove any services that are not essential. This reduces the inventory available to brokers.
Regularly review who has access to your critical systems. Ensure that granting access permissions follows the principle of least privilege. Remove access for former employees and inactive accounts. This limits the value of any stolen credentials.
Monitoring is not a one-time task. It requires continuous effort. The threat landscape changes daily. New credentials are stolen every hour. Your defensive posture must adapt to these changes.
Controls that devalue stolen access
The most effective defence is to make stolen credentials useless. Multi-factor authentication is the primary control, greatly reducing the value of stolen passwords. However, it does not stop stolen session tokens, which allow attackers to bypass MFA entirely. Consequently, sessions must also be revoked and kept short.
However, not all multi-factor authentication is equal. SMS-based codes are vulnerable to interception. While hardware tokens are robust, authenticator apps are not immune to phishing or man-in-the-middle attacks, as their codes and push approvals can be intercepted or relayed in real time. Only hardware security keys and passkeys offer genuine phishing resistance. Organisations should prioritise these stronger methods.
Network segmentation is another critical control. It limits the ability of an attacker to move laterally. If an attacker compromises one segment, they cannot easily access others. This contains the damage and slows down the ransomware deployment.
Regular patching and vulnerability management are essential. They reduce the number of entry points available to attackers. They also make it harder for brokers to find exposed services. A well-maintained network is less attractive to cybercriminals.
Employee training is also important. It helps users recognise phishing attempts and avoid downloading malware. This reduces the number of infostealer infections. Fewer infections mean less inventory for brokers.
Why this changes incident timelines
Understanding the role of access brokers changes how we view incident response. The timeline of a ransomware attack is no longer linear. It begins long before the ransom note is sent. It starts when the credentials are stolen or the service is exposed.
This means that detection must happen earlier. We cannot wait for the ransomware to encrypt files. We must detect the initial access attempt. This requires monitoring for unusual login patterns and failed authentication attempts.
It also means that prevention is more complex. We cannot rely on a single control. We need a layered defence. We need to secure endpoints, networks, and identities. We need to monitor the dark web for our own data.
The commercial nature of this threat means it will persist. As long as there is a market for access, there will be brokers. Organisations must adapt to this reality. They must treat stolen credentials as a constant threat.
This shift requires a change in mindset. We must think like the buyer, not just the defender. We must understand what makes our access valuable. We must take steps to devalue it. This is the only way to stay ahead of the market.
Questions people ask
What is an initial access broker?
An initial access broker is a cybercriminal who buys and sells verified access to computer networks. They harvest credentials from malware or exposed services and sell them to ransomware groups. This allows the ransomware group to bypass the initial break-in, though they must still escalate privileges, move laterally and often steal data before encrypting.
How do hackers get into company networks?
Hackers often enter company networks by purchasing access from brokers rather than breaking in themselves. The access is usually obtained through stolen credentials from infostealer malware or by exploiting unsecured remote services. Once inside, they use these credentials to move laterally and deploy ransomware.
How are stolen credentials sold online?
Stolen credentials are sold on underground forums and private marketplaces. Brokers aggregate logs from various sources, verify that the accounts are active, and list them for sale. The price depends on the perceived value of the account, such as its privileges or the size of the organisation.
Close
The market for initial access is a critical part of the ransomware ecosystem. It transforms cybercrime from a technical challenge into a commercial transaction. This shift makes the threat more scalable and more dangerous.
Organisations must respond by securing their digital identity. They must monitor for their own exposure and remove unnecessary access. They must implement strong authentication and network segmentation. These steps reduce the value of stolen credentials.
The goal is not to eliminate the threat entirely. That is impossible in a connected world. The goal is to make the cost of attack higher than the potential gain. When access is hard to buy and easy to detect, the market shrinks. This is the only sustainable path forward.
