Skip to main content

Recognized as a Champion in the Omdia Global Cybersecurity Platform Ecosystems Leadership Matrix 2026

Return to TrendAI™ Deep Research
Cyber crime

What Cybercriminals Look For in Corporate Insiders

The supply and demand for insider threat actors have evolved from isolated opportunism into a structured, thriving criminal market, complete with brokers, recruiters, referral bonuses, guarantor services, and revenue-sharing arrangements. This research examines that market across different industries.

Telecommunications Healthcare & life sciences Financial services Oil & gas General Markets Cybercriminal underground Cyber crime Deep dives

Key Takeaways

  • Insider recruitment is now part of a structured underground economy. Brokers, escrow services, and recurring partnerships operate openly on forums and Telegram channels.
  • The most valuable insiders hold workflow authority, not just system access. Criminals seek employees who can approve transactions, restore accounts, bypass fraud controls, and authorize actions that external attackers could not perform convincingly from outside.
  • Insider-enabled services are becoming commoditized. Social media unbans, refund fraud, SIM swaps, tracking updates, and account recoveries are openly marketed with fixed pricing, turnaround expectations, and reseller programs.
  • The AI sector is the next high-value target. As AI companies accumulate model weights, proprietary training data, and privileged system access, demand for employees who can quietly extract or abuse that access is expected to rise.

AI has entered every industry and is even reshaping the nature of cybercrime, but the human element stays a constant through all of it. For cybercrime, the insider remains an ever-needed commodity. Over a two-year observation period, we watched the insider market move further from one-off opportunism toward a mature, organized economy. Brokers now offer fixed payments, profit-sharing agreements, referral bonuses, and ongoing partnerships.

Human behavior is difficult to predict, but tracking the supply and demand for this commodity helps organizations anticipate where threats and potential insiders may emerge.

We offer a quick overview of our findings and the trends we’ve observed across different industries. For the complete picture, the full report provides examples of the ads and services we found on underground forums and messaging channels, along with cases showing how the access, information, and services insiders provide have translated into documented crimes.

Public sector: Access-as-a-service fueled by insiders

Insiders are selling ready-made access-as-a-service, collapsing the entire intrusion chain—including government-linked systems—into a single purchase that lets buyers skip the break-in altogether. That makes insider-enabled access among the most efficient and most dangerous products documented in this report.

Government: The scarcest commodity with the highest stakes

Government insiders are the scarcest commodity in the underground market. They appeared only occasionally in our research, likely because of credibility concerns, limited demand, or recruitment that moves to private channels. But the few listings that do appear command premium prices and reach toward sensitive access and nation-state intelligence.

Healthcare: Patient records for the right price

Healthcare faces insider risk from two fronts. Employees steal and quietly alter permanent medical records that victims cannot reissue, while some of the cybersecurity professionals hired to defend against ransomware have secretly worked with the attackers against their own clients.

Social media: The trust marketplace

Social media insiders are recruited to approve fraudulent ads, reinstate banned accounts, and manipulate verification and takedowns. Their access turns platform trust into a standing, openly priced market that persists even after companies fire the insiders behind it.

Telecom: Hijacking the signal

Telecom insiders are among the most sought-after and highest-paid in the underground, because a single bribed carrier employee can perform a SIM swap that defeats text-message two-factor authentication (2FA) and hands attackers a victim’s email, banking, and cryptocurrency accounts.

Finance: The high price of a banker’s access

Financial insiders are the necessary link in large fraud schemes. They are recruited to approve payments, extract customer and transaction data, and disable the fraud controls that would stop a transaction. A parallel strand of insiders handles the physical cash-out through ATM and point-of-sale (POS) skimming and fraudulent financing.

Industrial and energy: Skimming at the pump

The industrial and energy sector is the industry seemingly least targeted by insiders. Where recruitment does occur, it is concentrated in turnkey payment-skimmer schemes: threat actors hold the hardware and know-how, but they still need to recruit frontline gas-station and store employees for the one thing they cannot manufacture: physical, unsupervised access to the terminal.

Shipping and logistics: Whoever controls the scan controls the money

In shipping fraud, the insider’s entire value comes down to control of a single data point: the tracking scan that marketplaces, sellers, and buyers all treat as ground truth. A logistics insider who can post a false “Delivered” scan releases a fraudulent payout, and one who can post a “Return to sender” scan reverses a legitimate sale—which is why carrier insiders command steady, recurring demand.

Retail: Limitless refunds

Refunding fraud has matured from a hobbyist scam into an organized service. Insiders at major chains are recruited to process fraudulent refunds while the customer keeps the merchandise, with brokers taking a percentage of each refund. Recurring relationships, fixed price lists, and named operators have turned a once-casual scam into a professional operation with no caps on order value.

Reviews and reputation: Selling the platform’s credibility itself

On a reputation platform, the rating is the product. An insider who can delete a negative review, reinstate a banned host, or inflate a score is selling the platform’s credibility itself. That is a uniquely damaging asset, because it corrodes the trust signal every other user relies on rather than stealing money or data just once. Thus, part of the underground market trades on reputation, selling unbanning and negative-review-removal services on reputation and review platforms such as Airbnb.

Conclusion

It is clear from this research that what cybercriminals value most is not simply network access but authority and trust. We often talk about new and sophisticated attacks, but the truth is that the most efficient way into an organization is rarely a clever technique against its perimeter—it is a well-placed employee. As AI raises the value of proprietary data and privileged access, that market is likely to grow rather than recede.

The full report documents the underground recruitment economy across every sector, with pricing tables, forum listings, real case examples, and concrete recommendations for security and fraud teams.