Executive Summary
Adversaries are utilizing an underground market for recruiting individuals with specific employee access, rather than relying on self-motivated insiders. This market involves recruiters, brokers, and service providers who aim to transform employee access into criminal capability. Examples include offering referral fees for introductions to employees in sensitive roles like KYC or compliance, and facilitating illicit activities such as SIM swaps through job placement schemes. The activity focuses heavily on finding people who control specific workflows rather than just privileged users.
The demand in the market is distributed across various operational functions. While high-profile access is sought, there is significant interest in employees controlling workflows such as customer support, moderation, logistics, and verification staff. This suggests an expansion of insider risk beyond traditionally focused privileged roles to encompass functional access that enables repeatable operational capabilities.
Furthermore, actors are shifting from selling direct access to selling results, offering "full-cycle" services for tasks like shipment holds or account recovery. This model hides the actual insider behind a service provider, allowing a single internal capability to serve multiple buyers. Recruitment itself is being outsourced, with brokers advertising recruitment-as-a-service and documented methods for profile building and approach.
Facts Only
* One actor offered a US $50,000 referral fee for an introduction to an employee at a major crypto exchange working in KYC or compliance.
* An actor posted offers seeking unemployed U.S. residents to apply for jobs at a major U.S. telephone carrier and conduct subscriber identity module (SIM) swaps.
* Participants in SIM swap offers were offered a cut of the proceeds rather than upfront payment.
* Intel 471 analyzed 85 insider-related leads tied to 80 actor handles collected between August 25, 2025, and August 23, 2026.
* Recruitment accounted for 53% of observed records.
* Transportation appeared in 22% of leads, technology in 20%, and telecommunications in 18%.
* FedEx and UPS were each named in nine leads.
* Actors have advertised "full-cycle" services ranging from US $30 to $3,000 for logistics tasks.
* A recruitment guide was published instructing contractors on building profiles of support staff through LinkedIn and OSINT tools.
Full Take
The narrative reveals a structural shift in insider threat targeting, moving the focus from protecting static privileged users to exploiting dynamic operational workflows. The critical pattern is the commodification of functional access; the value lies not in possessing high-level credentials but in executing specific, repeatable actions that adversaries require, regardless of seniority. This suggests that security strategies built narrowly around "privileged users" are inherently incomplete if they ignore the distribution of control across service and logistics roles.
The transition from selling access to selling outcomes is a significant evolution, demonstrating an adaptation against potential detection mechanisms. By outsourcing the sourcing and execution layers—recruitment being outsourced and results being sold via service providers—actors achieve distance from the end-user risk while capitalizing on latent internal capabilities. This introduces an evasion layer that complicates traditional threat hunting focused solely on employee vetting or access logs.
The implication for organizational resilience is that segmentation of duties and least privilege must be assessed not just by formal job titles, but by the specific functional workflows employees manage. If adversaries are targeting roles like customer support or logistics because those functions grant repeatable operational capabilities (e.g., resetting accounts or rerouting packages), then threat intelligence must map these workflow intersections rather than relying on traditional hierarchical privilege models.
What assumptions are being challenged here? Does focusing solely on external recruitment and service monetization miss the internal pressures that drive individuals to seek illicit opportunities within legitimate workstreams? How does an organization move from recognizing *demand* for capability to building systems resilient against *process abuse* by non-privileged actors? What specific workflows, beyond those mentioned (transportation, telecom), present a systemic risk when viewed through this lens?
From the original · Intel 471 Blog
Insiders for Hire: What the Underground Market for Employee Access Tells Us About Insider Risk The typical image of an insider threat being a disgruntled employee or departing contractor is out of date. Today’s insider is often recruited, not self-motivated, sourced through an underground market of recruiters, brokers and service providers.Read the full story at intel471.com
Sentinel — Human
This text reads as expert synthesis based on specific research findings, blending investigative narrative with high-level strategic recommendations, consistent with human-authored threat intelligence reporting.
