Kaspersky: from January 2020 to June 2022, hacker groups offered salaries from six figures to $1.2M, bonuses, and paid leave to attract talent on the dark web
Despite the obvious risks, tech jobs with hacking groups can be alluring for those who need the money or want to do the work.
Context & Ripple Effects
Kaspersky's dark web job-posting data puts a price tag on a labor market that earlier coverage only sketched: Hacker's List matched freelance hackers with buyers for a few thousand dollars in 2015, and Hacker 'Peace' described making $25K in a month from selling breached data. By 2020-2022, organized groups were offering corporate-style packages — six figures to $1.2M, bonuses, paid leave — to recruit the same skilled researchers who can earn $1M+ legitimately through bug bounty work.
The recruiting push fits Mandiant's finding that [[a:978218|financially motivated criminals, not government spies, accounted for a third of zero-day-exploiting groups in 2021]] — ransomware and data-sale revenue is being recycled into payroll. Defenders are bidding for the same pool: companies were raising cybersecurity salaries and offering autonomy in response to ransomware risk, and platforms like HackerOne have since paid a record $81M in annual rewards.
First-order effects
- Legitimate security employers now compete directly against criminal organizations offering up to $1.2M plus benefits, raising the retention cost for skilled researchers and red-teamers already commanding higher pay.
Second-order effects
- Bug bounty platforms become the legitimate counter-offer channel — HackerOne's record $81M payout year is the defensive market's answer to dark web compensation, and rising criminal payrolls funded by ransomware push more groups toward the hired-specialist model Mandiant documented.
Third-order effects
- Cybercrime consolidates into structured organizations with HR functions — salaries, bonuses, paid leave — shifting the field from opportunistic freelancing toward an employment market that splits the global hacking talent pool between criminal payrolls and defensive bounties.
The trend: Criminal hacking groups are adopting corporate employment structures and competing with the legitimate bug bounty economy for the same scarce talent pool.