Cybercriminals Recruit Insiders to Bypass Security Controls
A new Intel 471 report reveals that cybercriminals are actively recruiting employees within target organizations to circumvent external security measures and offer illicit services on the black market.

Cybercriminals are increasingly leveraging insider threats as a potent method to bypass robust external security controls that would otherwise be difficult to overcome. A recent report by Intel 471, titled "Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services," details how threat actors are actively seeking out and recruiting individuals within specific organizations to perform actions that can be monetized on the dark web.
These insider-enabled services can range from routine tasks like information lookups and account resets to more impactful actions such as altering shipment details or approving fraudulent transactions. By turning legitimate employee access into a commodity, criminals can effectively exploit internal systems and processes for their own gain, often with a reduced risk of detection compared to traditional external attacks.
The Intel 471 analysis identified recruitment as the most significant activity, accounting for 45 out of 85 analyzed records. Another 15 records involved claims of insider capabilities, including direct claims of insider access, while 12 advertised services that were explicitly enabled by insiders. The remaining records pertained to access and data offerings, recruitment guides, and complaints within the underground economy.
Threat actors are specifically targeting employees who can retrieve restricted information, manipulate accounts, facilitate SIM swap attacks, interfere with logistics, enable fraud, or support broader intrusion and extortion schemes. Some actors directly advertise services based on their alleged employee privileges, while buyers and collaborators seek these capabilities to advance their own criminal objectives. The recruitment, advertising, and negotiation processes are facilitated through various criminal forums, messaging platforms, and other underground marketplaces.
Recruitment methods employed by these actors are diverse, including public solicitations, targeted approaches, referrals, the use of brokers, and partnership offers. Referrals and brokerage allow criminals to outsource the risky task of finding and vetting potential insiders. In some instances, actors may use deception or cultivate relationships over time to gain trust. Other schemes involve recruiting individuals who then apply for jobs at targeted organizations with the explicit intent of misusing their privileges once hired.
Compensation models for insiders vary widely, encompassing per-action payments, one-time sales of access or data, referral and recruitment fees, revenue sharing, and ongoing arrangements. Payments can be directed to the insider, a facilitator, or distributed among multiple participants based on their roles. To manage trust and mitigate risk, threat actors often employ transaction controls such as escrow services, staged payments, and verification requirements.
The transportation industry emerged as the most frequently referenced sector in the analyzed leads, appearing in 19 instances, followed by technology (17) and telecommunications (15). Companies like FedEx and UPS were mentioned in nine leads each, indicating a significant focus on disrupting logistics and supply chains. In telecommunications, the demand is for assistance with SIM swaps and subscriber lookups to facilitate account takeovers and fraud. For technology firms, the focus is on internal user data, account administration, and privileged access.
This trend highlights a critical shift in cybercriminal tactics, moving beyond purely external attacks to exploit the inherent trust and access granted to employees. The report underscores the growing sophistication of insider recruitment and the commodification of internal access, posing a significant challenge for organizations seeking to protect their sensitive data and operations.