Initial Access Broker
An initial access broker (IAB) is a criminal who breaks into organizations and sells that access to other attackers, such as ransomware groups.
An initial access broker (IAB) is a cybercriminal who specializes in one thing: gaining a foothold inside an organization's network and then selling that foothold to other criminals. The buyers — most prominently ransomware affiliates, but also data-theft and fraud crews — pay for working access the way a legitimate business pays for qualified sales leads. IABs are a defining feature of the modern cybercrime economy because they let each criminal specialize: one group is good at getting in, another at monetizing what's inside.
How it works
IABs acquire access through the same human-layer techniques that dominate breach statistics: harvested and infostealer-stolen credentials, credential harvesting pages, vishing calls to employees, MFA fatigue prompts and help desk fraud that talks a service desk into resetting a password. Once inside, the broker validates the access — confirming what the account can reach, whether it carries VPN or admin rights, and the victim's size and revenue — then lists it for sale on dark web forums or private channels. Listings typically advertise the industry, country, revenue and access type rather than the company name, with prices ranging from tens of dollars for a single mailbox to thousands for domain-admin access at a large enterprise. The elapsed time between purchase and ransomware deployment can be days or hours, which is why an unexplained password reset or suspicious login deserves urgent attention rather than a ticket in the queue.
How to defend against it
Defending against IABs means treating every "minor" credential incident as the potential first stage of a major one. Deploy phishing-resistant MFA so stolen passwords alone are not saleable goods, monitor for infostealer infections and mass failed-login patterns, and harden the help desk's identity-verification process — brokers actively exploit it. Monitor dark-web sources for mentions of your organization's access being offered. Most importantly, compress time-to-report: an employee who immediately reports a suspicious login page or an unexpected MFA prompt can invalidate the access before it is ever sold. That reporting reflex is trainable and measurable — it is a core signal in a human risk score, and the containment sequence that follows is covered in our incident response guide.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo