A threat actor is selling access to Office 365 and Microsoft accounts of hundreds of C-level execs at companies around the world, for $100 to $1,500 per account
Access is sold for $100 to $1500 per account, depending on the company size and exec role. — A threat actor is currently …
Context & Ripple Effects
This listing is the retail end of a supply chain the coverage has been documenting for years. The FBI traced $2.3B+ in CEO-fraud losses since 2013 to attackers impersonating executives, and CISA later confirmed an intrusion into a US federal agency that began with valid Microsoft 365 credentials rather than an exploit. What changed here is packaging: instead of one crew using stolen logins itself, hundreds of C-level accounts are being resold at tiered prices ($100–$1,500 by company size and role).
The seller side has professionalized too — Microsoft's takedown of a phishing-as-a-service operation selling 120+ templates for $80–$100 showed credential harvesting had become subscription software. A marketplace for pre-harvested executive accounts is the logical next step, and it lands on Microsoft just as it disclosed how Russian group Midnight Blizzard breached its own executives' email ([[a:848741]]) and how a campaign hit 10K+ organizations by hijacking Office 365 authentication even on MFA-protected accounts.
First-order effects
- Buyers get turnkey entry into executive mailboxes — the exact vantage point CEO fraud requires — so the immediate risk shifts from companies being targeted to companies already listed for sale needing emergency credential resets and mailbox audits.
- Microsoft faces renewed pressure on Office 365 identity security, coming on top of its own disclosures about MFA-bypassing phishing and the Midnight Blizzard executive-email breach.
Second-order effects
- The pricing tiers create a secondary market where low-cost buyers run volume scams while premium-priced Fortune-scale accounts go to targeted intrusion crews, forcing security teams to treat exposed credentials as a procurement problem, not just a defense one.
- Access brokers feeding this market sustain demand for harvesting tools like the PhaaS kits Microsoft disrupted, meaning takedowns of sellers push buyers toward new suppliers rather than out of the market.
Third-order effects
- If executive-account resale becomes routine, the unit of cybercrime commerce shifts from stolen data to standing access — pushing regulators and insurers toward treating credential exposure as a reportable, priced liability.
- Identity providers like Microsoft become the de facto battleground: as exploits matter less than valid logins, authentication hardening (hardware keys, conditional access) turns from best practice into the industry's core control point.
The trend: Stolen corporate credentials are maturing into a tiered commodity market, with executive account access sold as inventory rather than used directly by the thieves who harvest it.