Cybercriminals are increasingly targeting employees within banks, telecommunications companies, and technology firms, offering substantial payments in exchange for insider access to sensitive systems and data. Recent research by Check Point highlights that these recruitment efforts are conducted via darknet forums, with payouts ranging from $3,000 to $15,000 for one-time access or specific information, and even higher for particularly valuable data such as large cryptocurrency exchange records. The campaigns specifically name high-profile organizations, including major banks, cryptocurrency exchanges like Coinbase and Binance, and tech giants such as Apple and Samsung, as well as cloud service providers and consulting firms. Insiders are being solicited to provide network access, leak credentials, disable security defenses, or facilitate attacks such as SIM-swapping, which can be used to bypass two-factor authentication.
The recruitment tactics often employ emotional manipulation, promising financial freedom and long-term arrangements, with some offers including weekly payments for ongoing cooperation. The financial sector remains a primary target due to the direct access to funds and customer data, but the threat extends to other industries, including telecommunications and technology, where employees can enable attacks on infrastructure and user accounts. These developments present a significant security challenge, as insider threats are more difficult to detect and mitigate compared to external attacks, and highlight the need for organizations to strengthen internal monitoring and employee awareness programs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Check Point Research reported a growing trend of threat actors recruiting employees inside banks, telecoms, technology firms, cryptocurrency exchanges, and government entities to provide access or sensitive data. The activity was described as taking place through darknet forums and encrypted channels such as Telegram, with payments ranging from thousands of dollars to, in some cases, six figures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.