What Are Initial Access Brokers?

Key Takeaways

  • Initial access brokers, or IABs, specialize in one thing: sneaking into environments and selling that access to other attackers.

  • IABs commonly get in through stolen credentials, vulnerable internet-facing systems, and phishing or social engineering that helps them validate or capture access.

  • IABs help cybercrime scale. When one group specializes in access and another handles the next stage, cybercrime becomes faster, more efficient, and easier to repeat.

  • Defenders have the best chance to stop the chain early by adding friction—use MFA, lock down remote access, patch internet-facing systems fast, and watch for suspicious identity activity before a quiet foothold turns into a business interruption.

Cybercriminals don't need to do the whole job alone anymore.

Today’s threat landscape operates as a highly commoditized ecosystem built on a sophisticated supply chain of handoffs. That’s exactly where initial access brokers (IABs) come into play.

IABs are specialized cybercriminals who break into organizations and sell that foothold to other attackers. Instead of carrying out every stage of an attack themselves, they master the first part: getting in.

From there, they can sell that access to the highest bidder: a ransomware crew, someone planning a business email compromise (BEC) attack, or a group looking to steal data.

If that sounds a little like subcontracting, that's because it is. Modern cybercrime works more like a supply chain, with different players handling different parts of the attack. Access is sold across underground forums, marketplaces, and encrypted channels. IABs are at the beginning of that chain, doing the early work so other cybercriminals can buy validated access into your environment.

How do initial access brokers work?

At a high level, IABs focus on one job: getting unauthorized access that can be sold.

Instead of carrying out the full attack, they verify the access, determine its market value, and package it for downstream buyers. That could mean selling a basic user login, a foothold on a business network, or higher-value enterprise access with admin privileges.

The IAB process usually looks something like this:

  • Infiltration - First, they get in

  • Assessment - Next, they assess what kind of access they have

  • Valuation - Then, they decide how valuable that foothold is

  • Monetization - And finally, they sell it to another attacker on dark web forums

Listings can include details like the victim's industry, country, revenue, and access type, all of which help shape the price.

A basic login may sell for less. Admin-level access into a higher-value environment, like a hospital network or a Fortune 500 enterprise, can sell for much more.

Figure 1: Average prices of high-value stolen credentials across multiple markets.

How do initial access brokers get in?

To gain access, IABs typically rely on a few common entry points.

Infostealers and credential theft: Infostealer malware is designed to collect valuable data like usernames, passwords, cookies, and session tokens. IABs can use that stolen information to gain access and resell it.

Internet-facing system abuse: When patching lags and security misconfigurations are overlooked on web apps, exposed RDP or RDWeb, VPN appliances, and other internet-facing systems, they create easy entry points for IABs.

In one incident our SOC investigated, what looked like a straightforward brute-force intrusion against an exposed RDP server turned into something bigger. Investigators uncovered tradecraft and infrastructure linked to a suspected ransomware ecosystem tied to IABs. That's an important reminder that a small alert at the access stage can point to a much larger operation.

Figure 2: Forensic evidence of a likely IAB looking through password-themed files.

Phishing and social engineering: IABs trick users into giving up credentials or running malicious content, then use that access as a foothold to sell onward.

With generative AI, these campaigns are getting faster and easier to tailor to real workflows, trusted tools, and everyday prompts, which helps them blend in and avoid suspicion.

Figure 3: Example of an EvilTokens lure using a proposal-and-bid-documents pretext.

How do IABs reshape the cybercrime ecosystem?

By acting as the entry point in the cybercrime supply chain, IABs make it faster, more efficient, and easier for cybercrime to scale.

An IAB gives downstream attackers a shortcut. They don't need to spend time finding a victim and breaking through the perimeter if someone else has already done it.

That saved time can mean faster ransomware deployment, quicker lateral movement, and less time for defenders to shut the attack down before it spreads.

It also changes the cybercrime ecosystem. Specialization makes the attack chain more organized, more repeatable, and easier to scale.

That's the bigger risk for businesses. Once access changes hands, a quiet foothold can turn into an unwanted interruption that pulls teams away from their normal work and into incident response.

Why is IAB activity so hard to trace?

"You could have an IAB break into an organization in 2025, sell the access to someone else, and then maybe that new threat actor would break into the org five months later in 2026. So when our SOC sees these break-ins, it's really hard to definitively point to activity that initially stemmed from an IAB selling the access."

- Lindsey O'Donnell Welch
Principal Technical Community Engagement Writer, Huntress

That delay is part of what makes IAB activity so hard to track. Even when defenders can trace an intrusion back to how access was first gained, proving who sold that access, who bought it, and when the handoff happened is much harder.

By the time follow-on activity appears, the original break-in may be weeks or months old, and the attacker in the environment may not be the one who first got in. That's why early access matters: Even when attribution is murky, those first signs of compromise can still give defenders a chance to interrupt what comes next.

How can businesses reduce IAB risk?

To defend against initial access brokers, businesses can focus on adding more friction to getting that access in the first place. Start with these essentials:

  • Require multi-factor authentication on every account that supports it. If credentials get stolen, MFA can keep a bad password from turning into a real intrusion.

  • Lock down remote access and retire tools you don't use. If Remote Desktop Protocol (RDP) doesn't need to be open to the internet, close it. If remote access is necessary, lock it down and monitor it closely.

  • Patch fast, especially anything facing the internet. Unpatched software gives attackers openings they're happy to reuse.

  • Educate your people with security awareness training to recognize phishing and social engineering. A lot of initial access still depends on getting a person to trust the wrong message at the wrong time.

  • Watch for suspicious identity behavior, not just known malware. The earlier you spot suspicious logins, unusual account behavior, or signs of credential abuse, the better your chance of stopping an intrusion before it turns into a business interruption.

Initial access is where the bigger story begins

IABs usually aren’t the ones deploying ransomware or stealing data themselves. Their role is earlier and quieter: breach the perimeter, verify the foothold, sell it off, and move to the next target.

If defenders catch those early signals, they have a real chance to break the chain before it turns into a larger business interruption.

We break down threats like these every month at Tradecraft Tuesday. Join us for the next one!