Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door

Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

ThreatVectr Newsdesk· 4 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Share

Key points

  • The average cost of a malicious insider breach reached $4.9 million per incident in 2026, according to SentinelOne.
  • Organizations recorded a 42% rise in malicious insider incidents over the past year, per Mimecast's 2026 State of Human Risk report.
  • Ransomware group LockBit 2.0 embedded insider recruitment pitches directly into ransom notes left on infected machines.
  • A Medusa ransomware member offered a BBC journalist 25% of any ransom payout in exchange for access to his employer's network.
  • Insiders on criminal forums have claimed payments of up to $15,000 for a single set of valid company credentials.

Breaking into a company used to mean finding a crack in its defenses. Increasingly, ransomware gangs are skipping that step and simply paying someone who already has the keys.

Security researchers and incident responders interviewed by Dark Reading describe a growing trend: criminal groups actively recruiting employees, contractors, and trusted partners, offering cash or a cut of the ransom in exchange for legitimate login credentials or system access. The tactic is not dominant yet, but it is gaining ground precisely because corporate defenses everywhere else are improving.

How does an inside job actually work?

Sometimes an employee approaches criminals. Sometimes criminals approach the employee. Either way, the result is the same: attackers walk straight past the firewall, the VPN (a private tunnel companies use to protect remote connections), and every other perimeter control that security teams have spent years building.

Over 75% of unique posts from criminal insiders found on the dark web advertised existing access for sale, according to Flashpoint research published in July. Buyers are not hard to find.

Jamie Levy, senior director of adversary tactics at security firm Huntress, describes cases where ransomware operators explicitly plant contacts inside target organizations. "We'll pay you to give us access," is a pitch she has heard used. Notorious criminal group Scattered Spider, for example, bribed telecoms workers to perform SIM swapping, a scam where a victim's phone number is moved to a criminal-controlled device, letting attackers intercept one-time login codes sent by text message.

Money is one motivator. Anger is another.

What happens when a fired employee keeps their access?

Access that is not revoked the moment someone leaves becomes a weapon. Justin Miller, a retired US Secret Service agent and now a professor at the University of Tulsa, worked a case where an IT director was fired at 8 a.m. but told to finish his shift. Nobody cancelled his credentials. He came back at 2 a.m. and deployed malware, software designed to damage or disable computers, that locked the company's entire system.

"You don't want to piss off the guy who's in charge of your network," Miller says.

The fix sounds straightforward: when someone leaves, cut their access immediately. Levy recommends what she calls same-hour deprovision, meaning the moment an employee is let go, their single sign-on account (the one central login that opens all company tools), VPN, cloud systems, and code repositories are all shut off at once. Crucially, that means revoking live session tokens, the digital passes that keep someone logged in even after a password is changed, not just resetting the password.

Metric Figure Source / Date
Average cost, malicious insider breach $4.9 million per incident SentinelOne, 2026
Overall insider threat cost per organisation $19.5 million per year SentinelOne, 2026
Rise in malicious insider incidents 42% year-on-year Mimecast, 2026
Insider payment claims on criminal forums Up to $15,000 per access set Flare research
LockBit 2.0 recruitment method Ransom notes and desktop wallpapers Tenable research

Should ordinary employees be worried?

If you work at a mid-to-large company, you may receive an approach you do not recognise as criminal. It might look like a job offer, an unusual bonus, or a message from someone claiming to be a consultant. The ask will seem small: a username, a temporary login, a screenshot of an internal tool.

Report anything that feels off. Researchers note that recruitment attempts often fail because the targeted employee turns the criminals in, which is exactly what happened when a Medusa ransomware member approached BBC journalist Joe Tidy. Tidy played along long enough to document the scheme before exposing it publicly.

For organisations, the practical checklist is short: enforce multi-factor authentication (MFA, which requires a second proof of identity beyond a password) across every system, apply least-privilege access (give each person only the access their role actually needs), and treat offboarding as a security event that deserves the same urgency as a detected breach.

© 2026 Threat Vectr