Skip to content
Analysis

Access Broker Economy: When Network Access Is Sold on the Dark Web

Ransomware attacks rarely start with the ransomware. They start with a compromised account or stolen credentials – sold on by Initial Access Brokers.

  • by blacklens.io Team
  • Published
  • 2 min read
Access Broker Economy: When Network Access Is Sold on the Dark Web

Initial Access Brokers – an industry of their own

The dark web has developed a functioning division of labour. Initial Access Brokers (IABs) are specialised actors who concentrate on a single task: obtaining access to corporate networks and reselling that access.

Their offering is precisely catalogued and includes VPN credentials with details of company name, industry and annual revenue, RDP access to specific servers, compromised admin accounts with known privilege levels, and active sessions to Citrix or VMware environments. Buyers – including ransomware groups, espionage actors and extortionists – know exactly what they are getting before they even complete the purchase.

Prices depend on the value of the target. Access to a mid-sized European industrial company with high revenue fetches considerably more than access to a small service provider. The market runs on supply and demand.

Why this division of labour is dangerous

For affected companies this model means a structural shift: the actual breach – the moment someone gains unauthorised access – is not the same as the moment the damage becomes visible.

By the time ransomware is deployed, the initial access may be weeks old. During that time the original attacker has explored the network, documented credentials, prepared the listing and found the buyer. The ransomware actor walks into an environment that has already been opened up.

Classic reaction patterns come too late here: anyone who only reacts once files are being encrypted has already missed the decisive window.

What the dark web says about your company

IAB listings are often surprisingly extensive. Alongside the access route and company name, they frequently include the number of reachable systems, the privilege level of compromised accounts, the security software in use and sometimes even hints about which EDR solutions are already present and would need to be bypassed in a follow-up attack.

This information does not come from database leaks. It was actively extracted from the network before the listing was created. An IAB entry means: someone was already inside.

How blacklens.io detects IAB activity

blacklens.io's Dark Web Monitoring does not only track classic credential dumps – leaked email/password combinations from known breaches. It also captures active IAB listings on the relevant dark web forums and marketplaces.

If a listing is discovered that is linked to a company's public domain, an alert is issued immediately with all available context on the entry in question, such as the time of publication or the affected access point, for example a Citrix or VPN login page.

This is exactly where the difference to classic, reactive incident response lies: an IAB finding does not necessarily mean the actual attack has already taken place. Rather, it shows that a compromise has already occurred and that a follow-on attack could be imminent – which often leaves a limited window for targeted countermeasures.

Frequently asked questions

An Initial Access Broker is a specialised cybercriminal who obtains access to corporate networks – via VPN credentials, RDP access, compromised admin accounts or active Citrix and VMware sessions – and resells it on dark web forums and marketplaces. Buyers include ransomware groups, espionage actors and extortionists, and prices depend on the value of the target.

Share

More articles

See your attack surface within 24 hours.

We set up your workspace and walk you through the first findings.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings