Skip to content

Initial Access Broker (IAB)

Definition

An initial access broker is a cybercriminal who obtains access to corporate networks and sells that access on the dark web to other groups, usually ransomware operators.

Also known asIABAccess brokerNetwork access broker

Updated:

Compromised identities3 new hits
m.hu•••@beispiel-gmbh.atStealer log, 2 h agoEmployee
Microsoft 365 session cookieStealer log, 5 h agoEmployee
k.wa•••@gmx.atCombolist, 3 days agoCustomer

Visuals show sample data.

How blacklens.io covers this

An initial access broker (IAB) is a cybercriminal or group specialising in the first step of an attack: access to a corporate network. The broker sells this access, such as VPN credentials, RDP logins, Citrix accounts, web shells or compromised domain admin rights, in underground forums to other groups that carry out the actual attack, in most cases ransomware affiliate programmes.

Why initial access brokers matter

The division of labour in cybercrime is the reason ransomware attacks have scaled so much. A broker needs to master neither encryption nor extortion; they only need to get in. The buyer no longer has to search; they get verified access with details on industry, revenue, number of hosts and existing privileges. Listings are often sold within hours. For the affected company an IAB listing means: the attacker is already inside, the attack itself just has not started yet. This window is the last chance to close it without damage.

How initial access brokers operate

  • Acquisition: credentials from infostealer logs and combolists, exploitation of publicly known vulnerabilities in VPN gateways, firewalls and remote access, brute force against RDP, phishing.
  • Refinement: the broker checks whether the access works, which privileges it has and how large the company is. The higher the privileges and revenue, the higher the price.
  • Sale: the listing appears in underground forums, usually with industry, country, revenue, access type and privileges, but without the company name. Prices typically range from a few hundred to several tens of thousands of US dollars.
  • Handover: the buyer, often a ransomware affiliate, takes over and starts lateral movement, data exfiltration and encryption.

How blacklens.io addresses initial access brokers

blacklens.io works on the precursors, because a listing without a company name can rarely be attributed directly. Dark web monitoring finds the credentials and session cookies from stealer logs that brokers use as raw material and attributes them to your employees. The external attack surface shows exposed VPN, RDP and admin access, and the Threat Center matches new CVEs in exactly these products against your inventory in real time. Ransomware monitoring additionally shows whether suppliers from your watchlist appear on leak sites.

How do initial access brokers know where to get in?

Mostly from two sources: stealer logs, which contain the company's login URL alongside the password, and mass scans for known vulnerabilities in remote access products. Both are automated; brokers do not look for specific companies, they take what is open.

How do I know whether my access is being sold?

Listings rarely name the company but state industry, country, revenue and access type. A dark web monitoring hit on credentials for your VPN or Citrix portal is a much earlier and more reliable signal than the listing itself.

What protects most effectively against initial access brokers?

MFA on all remote access, timely patching of VPN gateways and firewalls, dark web monitoring with immediate reset of affected accounts, and a current inventory of exposed administrative access.

See which of these apply to your company.

The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings