/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A survey of 100 IT firms with 5,000+ employees: 65% say that they or their employees were approached to help ransomware hackers establish insider access

Bill Toulas / BleepingComputer :

BleepingComputer Bill Toulas

Context & Ripple Effects

Ransomware operators have spent years industrializing the attack itself — FireEye found 76% of enterprise attacks land outside business hours when support is thin — but this BleepingComputer survey points at a cheaper step in their chain: buying the way in. Two-thirds of 100 large IT firms report staff being approached to hand over insider access, which reframes the threat from perimeter breach to personnel compromise.

That lands on top of an existing insider-risk baseline: earlier reporting tied 60% of insider threats to employees leaving their jobs, and the Kaseya episode showed how ignored internal warnings about lax practices compound into attack surface. The new data suggests attackers are now actively recruiting rather than waiting for negligent exits.

First-order effects

  • Security teams at large IT firms must treat job offers, bribes, or flattery aimed at staff with system access as an attack vector, adding screening and reporting channels alongside technical defenses.
  • Employees become a monitored risk surface: firms that already track departing-employee behavior now have to extend that scrutiny to current staff being solicited mid-employment.

Second-order effects

  • Vendors selling insider-threat detection, privileged-access management, and employee-monitoring tools gain a concrete sales trigger, as the CrowdStrike finding that 56% of organizations were hit by ransomware within a year gives buyers urgency to close the human gap.
  • Managed service providers and outsourced IT shops face heightened client due diligence, since one recruited insider at a provider exposes every downstream customer at once.

Third-order effects

  • If recruitment-for-access becomes a standard ransomware playbook step, enterprise security structurally shifts budget from perimeter tooling toward identity vetting, offboarding controls, and anomaly detection on internal actions.
  • Regulators and insurers may begin treating unreported insider approaches as a governance failure, pushing boards to require disclosure channels the way they require financial-controls reporting.

The trend: Ransomware economics are migrating from breaking through defenses to recruiting insiders, making human access the contested perimeter of enterprise security.

Discussion

  • @auscsec @auscsec on x
    Ransomware gangs increase efforts to enlist insiders for attacks https://www.bleepingcomputer.com/ ... A recent study found that over 60% of all data breaches involved insider involvement. Organizations must take steps to protect against insider threats. AUSCSEC can assist.
  • @threatintel Threat Intelligence on x
    Ransomware gangs step up efforts to recruit insiders https://www.bleepingcomputer.com/ ...