One in eight of your employees has either sold a company login or knows someone who has. That’s Cifas, not a tabloid, and the number should change how you think about your cybersecurity program. Your firewall isn’t being bypassed. Your password manager isn’t being cracked. Somebody on your payroll is taking cash to hand over working credentials, and the buyers are getting better at turning that access into payouts.
The insider market is now a supply chain
Cifas surveyed UK workers and found 13% have either sold credentials, been offered money for them, or know a colleague who has. This isn’t disgruntled-employee territory. It’s a casual labor market with prices, brokers, and repeat buyers.

The buyers aren’t bored kids. Kaspersky’s State of Ransomware 2026 report makes a clean observation: more groups are dropping the encryption phase entirely and going pure data-extortion. Encryption is loud and burns infrastructure. Stealing a database and threatening to publish it is quieter, cheaper, and harder for victims to recover from with backups.
That shift matters because pure extortion crews don’t need to push a payload past your EDR. They need access to data. Working employee credentials, especially from a finance, HR, or admin user, are the cheapest possible delivery mechanism. No CVE. No phish. No malware loader.
Look at what happened to Instructure. ShinyHunters lifted data from Canvas, and Instructure reportedly reached an “agreement” with the group to keep the data off the leak site. Whether that intrusion started with a brute-force attempt or a paid insider doesn’t matter much to the schools whose student records were the leverage. The economics work either way, and a bought login is the lower-friction path.
Standard cybersecurity tooling misses this cleanly
This is the part most security programs are not built for. Brute-force attempts hit the logs. A phishing link gets caught by a URL sandbox. Lateral movement triggers your EDR. A legitimate user signing in from a sanctioned device, during business hours, with the password they were issued, does not trip any of that.
Defense in depth assumes the attacker is outside the trust boundary and trying to get in. Insider-fed access starts inside it. Your threat detection stack is tuned for anomaly, and a paid insider is, by design, not anomalous.
Three operational blind spots make this worse. First, excessive standing privilege: most accounts have far more access than the role actually uses, so a single bought login often unlocks data well beyond the seller’s day job. Second, logging that captures access but not behavior. Knowing a user opened a file is not the same as knowing they queried it differently than they have in the last ninety days. Third, offboarding that doesn’t cover contractors, integrations, or shared service accounts. The credentials with the longest shelf life are usually the ones nobody owns.
The Texas case against Netflix is the policy mirror image. Regulators are pushing back on data hoarding because the more you collect, the more leverage an attacker, or a bought insider, has over you. Data minimization is becoming a defensive control, not a compliance checkbox.
What to actually do this quarter
You will not solve insider risk.
You can make the credential you sell worth much less.
Start with privilege. Audit the accounts with the broadest read access to customer data, financial systems, and source code. If the role doesn’t need it daily, pull it. Just-in-time access elevation, with a ticketed reason, turns a sold credential into a single-use ticket instead of a permanent skeleton key.
Phishing-resistant MFA does heavier lifting here than people give it credit for. A bought password without the bound hardware key is mostly useless to a remote buyer. FIDO2 tokens, platform passkeys, or smart cards raise the price of insider sale dramatically, because the seller now has to ship hardware or stay actively complicit in every login.
Behavioral analytics on identity is the part most teams skip. Your IdP already knows which user touches which app and when. Set baselines per user, then alert on deviations: unusual data volume pulled from a CRM, off-hours queries against a finance system, sudden access to a repository the user has never touched. That’s incident response prep, not surveillance. When the breach starts, the question is always how fast you can scope blast radius, and behavior baselines are the fastest answer.
A few concrete moves for the next 30 days:
- Generate a report of users with access they haven’t exercised in 90 days. Revoke or downgrade.
- Move admin, finance, and HR accounts to phishing-resistant MFA. Not push notifications. Hardware-bound.
- Enable session recording or detailed query logging on the top three data sources an extortion crew would actually want.
- Run a tabletop where the initial access vector is a paid insider, not a phish. Notice which controls fire and which don’t.
Security hardening against bought credentials looks a lot like security hardening against everything else. The difference is that you stop assuming the attacker is on the outside.
One in eight is a market.
Price it out of relevance.
Sources
- 1 in 8 employees have sold company logins or know someone who has (Malwarebytes)
- State of ransomware in 2026 (Securelist)
- Instructure reaches ‘agreement’ with ShinyHunters to stop data leak (BleepingComputer)
- Texas sues Netflix over alleged data practices that create ‘surveillance machinery’ (The Record)
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
