Initial access broker
In the criminal economy, an initial access broker is a specialist who compromises organisations and sells that access to somebody else rather than using it. They are the reason an intrusion can begin with no exploitation at all: the buyer logs in with access that was obtained weeks earlier by a different party.
How it works
The broker’s product is a working way in: valid remote access or VPN credentials, an exposed remote desktop service, a web shell on an internet-facing application, an account in a cloud tenant, or a foothold on an internal host. They obtain these at scale through commodity means, principally credentials from infostealer logs, password spraying against exposed services, and mass exploitation of edge appliances shortly after a fix is published.
Listings are advertised with the details a buyer needs to price them: sector, country, approximate revenue, the level of access and the security tooling observed. Buyers are frequently ransomware affiliates, which is why this role and ransomware as a service describe two parts of the same market.
What goes wrong
The separation of roles defeats intuitions about incident timing. The compromise and the impact can be months apart and performed by unrelated people, so an organisation that finds ransomware on Monday is looking at an access that was sold in the spring. It also means the entry point is usually mundane and rarely reflects the sophistication of whoever eventually arrives.
For defenders the practical consequence is that the exposures brokers harvest are exactly the ones treated as routine hygiene: an old VPN appliance, a remote desktop service opened for a supplier, an account without a second factor, a service account whose password has never been changed. These are not exotic findings and they are the entire supply side of the market.
The second consequence is that detection has a window. Access is often held for a period before it sells, and during that time the activity is minimal: a login, a look around, nothing destructive. Detecting an unusual authentication is the cheapest possible intervention and is the one that is missed.
Where this shows up in an audit
Two engagements meet here. External testing finds the exposures on the supply side and reports them as what they are: not merely a missing patch, but a sellable asset. Intelligence work watches the demand side, for the client’s domains appearing in listings and in stealer logs. When a broker advertises access matching a client’s profile, the useful part of the report is not the listing but the reconciliation with what we know is exposed. This is part of how we find your exposed access before somebody buys it.