Ransomware groups are increasingly seeking employees, contractors, and business partners who can provide valid credentials, network access, or sensitive data, as stronger perimeter defenses make external intrusion more difficult. Dark-web recruitment activity reflects demand for access to high-value organizations, though insider assistance remains a less common initial-access method than other intrusion routes.
Organizations face elevated exposure where offboarding is delayed, privileges are excessive, and access by third parties is insufficiently controlled. Security teams should rapidly deprovision departing personnel, enforce least privilege, MFA, and privileged-access controls, protect backup and hypervisor administration, and monitor endpoints and anomalous access while encouraging employees to report mistakes or suspicious approaches promptly.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Flashpoint reported that more than 75% of unique threat-actor posts it examined on the dark web came from insiders advertising access to malicious third parties.
Mimecast's State of Human Risk 2026 reported that organizations experienced a 42% year-over-year increase in malicious-insider activity.
SentinelOne reported that insider threats cost organizations $19.5 million annually on average in 2026, with negligent insiders accounting for 56% of incidents. It also reported an average $4.9 million cost for incidents involving malicious insiders with elevated privileges.
Christopher Dobbins was sentenced to federal prison for hacking his former medical-packaging employer and sabotaging its electronic shipping records. The sabotage caused more than $200,000 in damage and delayed COVID-19 personal protective equipment shipments.
LockBit 2.0 reportedly used ransom notes and desktop wallpapers to seek insider recruitment, requesting VPN, Remote Desktop Protocol, and email credentials.
Scattered Spider was cited as having bribed telecommunications employees to facilitate SIM-swapping attacks against targeted users.
Coalition investigated a malicious-insider case in which an employee allegedly siphoned victim funds into a personal bank account.
A fired IT director reportedly retained credentials after leaving an organization and later deployed malware that locked down its systems.
An alleged Medusa ransomware-as-a-service member offered BBC World Service correspondent Joe Tidy 25% of a ransom payment in exchange for access to his computer, seeking secret access to the BBC corporate environment.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.