/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A threat actor is selling access to Office 365 and Microsoft accounts of hundreds of C-level execs at companies around the world, for $100 to $1,500 per account

Access is sold for $100 to $1500 per account, depending on the company size and exec role.  —  A threat actor is currently …

ZDNet Catalin Cimpanu

Context & Ripple Effects

This listing is the retail end of a supply chain the coverage has been documenting for years. The FBI traced $2.3B+ in CEO-fraud losses since 2013 to attackers impersonating executives, and CISA later confirmed an intrusion into a US federal agency that began with valid Microsoft 365 credentials rather than an exploit. What changed here is packaging: instead of one crew using stolen logins itself, hundreds of C-level accounts are being resold at tiered prices ($100–$1,500 by company size and role).

The seller side has professionalized too — Microsoft's takedown of a phishing-as-a-service operation selling 120+ templates for $80–$100 showed credential harvesting had become subscription software. A marketplace for pre-harvested executive accounts is the logical next step, and it lands on Microsoft just as it disclosed how Russian group Midnight Blizzard breached its own executives' email ([[a:848741]]) and how a campaign hit 10K+ organizations by hijacking Office 365 authentication even on MFA-protected accounts.

First-order effects

  • Buyers get turnkey entry into executive mailboxes — the exact vantage point CEO fraud requires — so the immediate risk shifts from companies being targeted to companies already listed for sale needing emergency credential resets and mailbox audits.
  • Microsoft faces renewed pressure on Office 365 identity security, coming on top of its own disclosures about MFA-bypassing phishing and the Midnight Blizzard executive-email breach.

Second-order effects

  • The pricing tiers create a secondary market where low-cost buyers run volume scams while premium-priced Fortune-scale accounts go to targeted intrusion crews, forcing security teams to treat exposed credentials as a procurement problem, not just a defense one.
  • Access brokers feeding this market sustain demand for harvesting tools like the PhaaS kits Microsoft disrupted, meaning takedowns of sellers push buyers toward new suppliers rather than out of the market.

Third-order effects

  • If executive-account resale becomes routine, the unit of cybercrime commerce shifts from stolen data to standing access — pushing regulators and insurers toward treating credential exposure as a reportable, priced liability.
  • Identity providers like Microsoft become the de facto battleground: as exploits matter less than valid logins, authentication hardening (hardware keys, conditional access) turns from best practice into the industry's core control point.

The trend: Stolen corporate credentials are maturing into a tiered commodity market, with executive account access sold as inventory rather than used directly by the thieves who harvest it.

Discussion

  • @adam_k_levin Adam Levin on x
    A threat actor is currently selling passwords for the email accounts of hundreds of C-level executives at companies across the world. https://www.zdnet.com/...