How to defend the full social engineering attack chain | Register for the webinar to learn more

General

What Is an Initial Access Broker (IAB)?

Initial access brokers breach corporate networks and sell verified footholds to ransomware groups and other attackers.

Doppel TeamSecurity Experts
September 23, 2026
5 min read

What Is an Initial Access Broker (IAB)?

An initial access broker (IAB) is a cybercriminal who compromises corporate networks and then sells that access to other threat actors instead of exploiting it themselves. Also called intrusion brokers, IABs sell footholds to ransomware operators, business email compromise crews, and espionage groups. The broker's work ends at the foothold; the buyer handles lateral movement, privilege escalation, exfiltration, and payload deployment.

How initial access brokers work

An IAB validates incoming access before reselling it. Brokers absorb large volumes of access, filter for the highest-value victims, buy stolen credentials in bulk or scan for vulnerable systems themselves, then test that the access works and triage the business (opens in new tab) for onward sale. Some plant a second way in before listing, so a password reset or a patch does not invalidate the access.

Infostealers like Vidar, and historically RedLine and Raccoon, harvest VPN credentials, single sign-on cookies, and cloud session tokens in bulk, and brokers buy those logs wholesale to sift for corporate domains and privileged accounts. In the 2025 DBIR, 54% of ransomware victims (opens in new tab) had their internet domains appear in infostealer credential dumps. Scanning of public-facing systems finds exposed RDP endpoints and unpatched perimeter appliances, and social engineering supplies the rest through help desk impersonation and MFA push fatigue. A vishing call can end with the attacker registering a new authentication device.

Brokers write listings for buyers who need to price risk. A broker usually withholds the victim's name and advertises industry, revenue, employee count, privilege level, and access type, then sells through auctions (opens in new tab) with a "Start" opening bid, a "Step" increment, and a "Blitz" buy-it-now price. Listings back the claim with proof, such as the security software running on the network.

On the victim side, the evidence looks mundane. Incident responders routinely find a single suspicious VPN log-in that predates the ransomware event by days, weeks, or months. That log-in is the broker validating the access before selling it.

Why initial access brokers matter

Brokers let ransomware crews skip the slowest, riskiest part of an intrusion. The 2026 DBIR found ransomware present in 48% of all breaches (opens in new tab), the highest share on record. Medusa ransomware actors recruit IABs directly in cybercriminal forums and marketplaces (opens in new tab). Buyers who arrive through a broker start after the broker has finished reconnaissance and propped the door open.

Increasingly, initial access partners pre-stage (opens in new tab) the follow-on group's preferred malware, tunnels, or backdoors during the initial infection, so the buyer inherits a fully equipped foothold the moment it takes over.

Public visibility into the market is narrowing. Brokers publicly list fewer network access sales while ransomware activity remains high, which indicates that transactions are moving into private broker-to-affiliate relationships and Telegram channels.

Defender visibility can also narrow at the entry point. When attackers gain access purely through social engineering and valid credentials, they leave no malware (opens in new tab) for endpoint tools to catch.

What initial access brokers sell

Broker inventory maps to whatever authenticates a stranger into an enterprise. The recurring categories:

  • Remote access services. RDP and VPN remain the top advertised access vectors (opens in new tab), with RDWeb portals drawing more attention as organizations expose and underprotect them.
  • Domain and directory credentials. Domain user, local admin, and domain admin accounts, plus Active Directory and ESXi root access, which brokers price by privilege level.
  • Cloud and SaaS tenancy. Microsoft 365 tenants, single sign-on credentials, SaaS administrator accounts, and console credentials for AWS, Azure, and Google Cloud.
  • Session tokens and cookies. Stolen session material resumes an existing authenticated session, sidesteps MFA (opens in new tab), and keeps working after a password reset.
  • Web shells and admin panels. Persistent backdoors on compromised servers that double as staging points for the buyer's lateral movement.
  • Exploitable perimeter appliances. Brokers weaponize edge CVEs within hours of disclosure. CVE-2025-0282 in Ivanti Connect Secure gave unauthenticated attackers remote code execution, and one broker weaponized CitrixBleed 2 (opens in new tab), the Citrix NetScaler memory-disclosure flaw (CVE-2025-5777) that leaks session tokens.

How to defend against initial access brokers

Defending against brokers means removing the inventory they collect and detecting the credentials once buyers acquire them. The controls that do the most work:

  • Deploy phishing-resistant MFA. Phishing-resistant MFA such as FIDO/WebAuthn or PKI-based methods resists phishing and is not susceptible to push bombing or SIM swap attacks. Where that is not yet possible, number matching blunts MFA fatigue.
  • Harden the help desk. Attackers convince IT support staff to reset MFA tokens (opens in new tab) and passwords for accounts they do not own. Verifying identity out of band before any reset or MFA enrollment closes that path.
  • Shrink the exposed perimeter. Do not expose RDP to the internet, and scan internet-facing devices regularly; external attack surface management tools find unmanaged exposure (opens in new tab) before brokers do.
  • Monitor for exposed credentials. Credential monitoring services that watch the dark web for compromised credentials show an organization that brokers have listed its access before an affiliate buys it.
  • Build identity anomaly detection. Brokers create new domain accounts (opens in new tab) to hold access for buyers. Alert on unfamiliar geographies and ASNs, first-time device enrollment, new OAuth consents, and log-ins that succeed only after repeated failures.
  • Segment the network. Segmentation controls traffic flows (opens in new tab) between subnetworks so purchased credentials do not translate into enterprise-wide encryption.

How Doppel helps

Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM). It targets the lookalike domains, spoofed login pages, fake profiles, and vishing pretexts that feed the logs brokers later sell as access.

Access brokers register and stage this infrastructure in public before contacting an employee. The Doppel Threat Graph correlates signals across domains, social, paid ads, telco, app stores, and the dark web into campaign-level views. Our agentic AI then prioritizes and executes takedowns across registrars, hosts, social platforms, and ad networks. We dismantle that infrastructure as we find it, and each campaign we take apart sharpens detection for the next one.

The same detections feed HRM. A live vishing or credential-harvesting campaign converts into a multi-channel simulation for the employees and help desk agents brokers target most, which is how organizations become too costly to attack. Request a demo for a working view of the broker infrastructure attackers have already staged against your brand.

Frequently asked questions about initial access brokers

What is an initial access broker?

An initial access broker is a cybercriminal who specializes in getting into corporate networks and selling that access to other criminals. Brokers acquire footholds through stolen credentials, exposed remote desktop and virtual private network (VPN) services, unpatched internet-facing appliances, and social engineering, then verify the access works before listing it. Listings typically describe the victim by industry, revenue, employee count, and privilege level instead of naming the company. Buyers include ransomware affiliates, extortion crews, data theft teams, and nation-state actors.

What is an initial access broker in cybersecurity?

In cybersecurity, the term names a specialized role in the criminal supply chain that sits between credential theft and attack execution. The broker establishes and validates a foothold during the first stage of an intrusion, then hands everything after that to a paying buyer. This division of labor is why ransomware groups can move from purchase to encryption in a matter of days: the broker has already completed the reconnaissance and break-in. Some brokers work to standing requirements from specific ransomware groups, while others auction confirmed access to any buyer on forums and Telegram channels.

Initial access broker vs ransomware affiliate: what is the difference?

The two roles occupy different points in the same operation. An initial access broker breaks in, tests the access, and sells it, then walks away without encrypting files or negotiating a ransom. A ransomware affiliate buys or receives that access, escalates privileges, moves laterally, steals data, deploys the payload, and runs the extortion. A third role, the ransomware operator or developer, builds and maintains the tooling the affiliate uses. The ransomware-as-a-service economy runs on three distinct roles (opens in new tab), though single groups sometimes play more than one.

What is an example of an initial access broker attack?

In November 2025, Russian national Aleksei Volkov pleaded guilty to charges including trafficking in access information and conspiracy to commit computer fraud, admitting that he broke into corporate networks and sold the access to ransomware crews, including the operators of Yanluowang. A court sentenced him to 81 months (opens in new tab) in March 2026, and he had taken a cut of the ransoms his buyers collected from large US companies. A more common pattern looks quieter: an infostealer harvests VPN credentials from an employee laptop, a broker validates and resells the foothold, and weeks later an affiliate uses that same account to deploy ransomware.

Last updated: September 23, 2026