A survey of 100 IT firms with 5,000+ employees: 65% say that they or their employees were approached to help ransomware hackers establish insider access
Bill Toulas / BleepingComputer :
Context & Ripple Effects
Ransomware operators have spent years industrializing the attack itself — FireEye found 76% of enterprise attacks land outside business hours when support is thin — but this BleepingComputer survey points at a cheaper step in their chain: buying the way in. Two-thirds of 100 large IT firms report staff being approached to hand over insider access, which reframes the threat from perimeter breach to personnel compromise.
That lands on top of an existing insider-risk baseline: earlier reporting tied 60% of insider threats to employees leaving their jobs, and the Kaseya episode showed how ignored internal warnings about lax practices compound into attack surface. The new data suggests attackers are now actively recruiting rather than waiting for negligent exits.
First-order effects
- Security teams at large IT firms must treat job offers, bribes, or flattery aimed at staff with system access as an attack vector, adding screening and reporting channels alongside technical defenses.
- Employees become a monitored risk surface: firms that already track departing-employee behavior now have to extend that scrutiny to current staff being solicited mid-employment.
Second-order effects
- Vendors selling insider-threat detection, privileged-access management, and employee-monitoring tools gain a concrete sales trigger, as the CrowdStrike finding that 56% of organizations were hit by ransomware within a year gives buyers urgency to close the human gap.
- Managed service providers and outsourced IT shops face heightened client due diligence, since one recruited insider at a provider exposes every downstream customer at once.
Third-order effects
- If recruitment-for-access becomes a standard ransomware playbook step, enterprise security structurally shifts budget from perimeter tooling toward identity vetting, offboarding controls, and anomaly detection on internal actions.
- Regulators and insurers may begin treating unreported insider approaches as a governance failure, pushing boards to require disclosure channels the way they require financial-controls reporting.
The trend: Ransomware economics are migrating from breaking through defenses to recruiting insiders, making human access the contested perimeter of enterprise security.