Dark-Web
What Is an Initial Access Broker?
An initial access broker obtains footholds in victim networks, verifies them, and resells them to whoever intends to monetise the intrusion. The role exists because specialisation pays: the people who harvest credentials at scale are not the people who deploy ransomware, and neither wants the other's job. For a defender the significance is temporal. Access now changes hands at a median of 22 seconds according to Mandiant's 2026 figures, and sells within one to three days of listing. A credential exposure is not a latent risk sitting quietly in a dump — it is an actively marketed asset with a short shelf life.
A market built on specialisation
An initial access broker is an intermediary. They acquire a working foothold in an organisation's network, establish what it is worth by confirming what it reaches, and sell it to someone else. They do not deploy ransomware, exfiltrate data for extortion, or commit fraud with the access they obtain. They sell it and move on.
The role exists for the same reason roles exist in any market: specialisation is more profitable than vertical integration. Harvesting credentials at scale through commodity malware is a volume business requiring distribution skill. Running a ransomware operation is a negotiation and logistics business requiring different skills entirely. The broker sits between them, converting undifferentiated bulk credential data into qualified, priced, ready-to-use access.
This is now well enough established to appear in incident response taxonomy. Mandiant's M-Trends 2026 records "prior compromise" — access acquired from another actor — as the initial infection vector in 30% of ransomware-related intrusions in 2025, a figure the report describes as having nearly doubled year on year. Observed hand-offs between actors appeared in 9% of investigations, up from 4% in 2022.
Europol frames its 2025 assessment around the same structure, describing a cybercrime economy built on access — to systems, to identity, and to data — with stolen data as the feedstock.
The population is concentrated rather than diffuse. One study of Exploit-forum listings found 31 unique broker identities behind all posts, with the top seven producing over 55% of them. These are persistent, reputationally-invested vendors, not opportunists.
What is actually sold
Listings follow a consistent taxonomy across every dataset from 2023 onward: the access mechanism, the privilege level, and qualifiers describing the victim.
Access mechanism. RDP and VPN consistently account for roughly 40–60% of listings. One 2025 sample across five forums recorded RDP at 21.2%, VPN at 12.8% and RDWeb at 11.2%; another put VPN at 23.5% and RDP at 16.7%. Citrix, SSH, web shells and appliance-specific access — Fortinet access is named explicitly in some datasets — make up smaller named categories. VPN access is frequently advertised with working credentials and no multi-factor authentication.
Privilege level. Contrary to intuition, most access sold is not administrative. Over 70% of listings in one 2025 study paired access with user-level rather than admin privileges. Domain user access was the single most common category at 42.9% in another sample, against 32.1% domain admin.
That matters defensively. The buyer is not purchasing a finished intrusion. They are purchasing a starting position, and expecting to escalate.
Victim qualifiers. Country, sector, revenue, host count, endpoint count, and — notably — which endpoint protection product is deployed. The last of these tells you what the buyer is pricing: not whether the organisation has security controls, but which ones they will need to work around.
What it costs
The central tendency is low and has been consistently low. Median prices sit around USD 500 to 1,500, with roughly 40% of listings in the USD 500–1,000 band and around 65% under USD 2,000 in one 2023 sample. A 2024 study found the average falling to around USD 1,295, with high-value listings representing only about 9% of supply.
Reported averages should be treated with care. Several widely-repeated five-figure "average price" claims are means computed over asking prices on listings including extreme outliers, and at least one is contradicted by the same report's own distribution data. Where a headline price figure is not accompanied by a median, it is probably not telling you what it appears to.
The practical reading is uncomfortable. Access to a mid-sized organisation's network frequently costs less than a mid-range laptop. The economics do not require the attacker to be selective.
How fast it moves
This is the part that should change how an exposure finding is handled.
Access sells within one to three days of being listed. Once sold, Mandiant's 2026 data records the median time from initial access to hand-off between actors at 22 seconds, down from over eight hours in 2022 — a collapse that indicates the handover is now largely automated rather than negotiated.
The interval from listing to the victim appearing on a ransomware leak site has been reported at 23 to 36 days. That figure comes from five traced cases from 2021 and has not been independently replicated, so it should be treated as indicative rather than established. It is nonetheless the best available evidence for that leg.
Dwell time frames the rest. Mandiant's global median was 14 days in 2025. Sophos, working a caseload where 84% of organisations had fewer than 1,000 employees, recorded a median of 3 days across 661 cases. For mid-market organisations, the window between intrusion and impact is measured in days.
A detail worth knowing: 88.1% of ransomware deployments in the Sophos dataset occurred outside business hours, with 37.1% falling between 11pm and 3am. Response capability that exists only during the working day is response capability that exists for the minority of the relevant time.
Where the credentials originate
There is no published dataset decomposing what proportion of broker-acquired access originates from infostealer logs versus exploitation versus phishing. Claims to the contrary should be checked against their methodology.
What exists is incident response data on victim root cause, and it diverges by caseload in a way that is informative rather than contradictory.
Mandiant's M-Trends 2026 puts exploitation first at 32%, the leading vector for the sixth consecutive year, with voice phishing second at 11%. Its clients skew large enterprise.
Sophos's 2026 Active Adversary Report, covering 661 cases where 84% of victims had under 1,000 employees and 56% had 250 or fewer, puts identity-related root causes at 67.3% in aggregate — compromised credentials alone at 42.1%, brute force at 15.6%, phishing at 6.4% — against exploited vulnerabilities at 16.0%.
Both are accurate descriptions of different populations. For a mid-sized European organisation the Sophos distribution is the one that applies, and it says that identity, not unpatched software, is the dominant route in.
The scale of the feedstock is visible elsewhere. Flare's analysis of 18.7 million stealer logs in 2025 found 2.05 million exposing enterprise SSO or identity provider credentials — roughly 11%, rising to 16% of infections by late 2025. The infected machine is frequently not a managed corporate asset at all.
Why your incident report will not mention this
Post-breach reporting classifies initial access by the observable entry event into the victim's network. A valid credential used against a VPN concentrator is recorded as "valid accounts" or "compromised credentials." That is accurate, and it is not the whole story.
The original infostealer infection usually occurred outside the victim's estate — a personal laptop, a contractor's machine, a family computer where someone once checked work email. It sits outside the investigation's scope and outside its time window. It is structurally invisible to the engagement.
Dwell time makes this concrete. It is measured from the adversary's entry into the environment. Any period during which the credential sat in a log, was aggregated into a list, was advertised on a forum, and was purchased is definitionally excluded from the reported figure. The 14-day median describes the last leg of a considerably longer journey.
Mandiant's "prior compromise" category is the closest the industry has come to naming this gap, and its growth to 30% of ransomware intrusions suggests the gap is widening.
Where the trade happens
The market runs on Russian-language reputation forums — Exploit and XSS, and until early 2026 RAMP — alongside the English-language breach forum lineage and Telegram, which now carries the overwhelming majority of stealer log distribution.
A dense sequence of law enforcement actions has reshaped the landscape since mid-2025. XSS's administrator was arrested in Kyiv in July 2025, prompting a community split. BreachForums was seized again in October 2025. RAMP, the principal ransomware affiliate recruitment venue, was seized in January 2026. LeakBase's clearnet domain followed in March 2026.
The effect has been fragmentation rather than reduction. Successor forums appeared within weeks in each case, several reaching hundreds of thousands of registered accounts within months. What has degraded is trust between participants — one prominent actor issued a signed statement in March 2026 disavowing all current forums bearing a well-known brand as fraudulent. Supply has not measurably fallen.
What this means for response timing
The existence of this intermediation layer converts a credential exposure from a latent risk into a time-bounded, actively marketed asset. That changes the arithmetic of response.
Access sells within one to three days of listing. Hand-off to the operator is effectively instantaneous. Mid-market dwell time is three days. Set against that, a thirty-day remediation SLA of the kind commonly applied to patching is not a response — it is a formality completed after the event.
The defensible guidance is hours, not days.
Four things follow.
Revoke sessions before rotating credentials. Stolen session cookies survive a password reset on most platforms, and they bypass multi-factor authentication because the authentication has already completed. Revocation is a separate action and it should come first.
Assume the source device is outside your control. The infection that produced the credential probably happened on a machine you cannot inventory or inspect. Internal telemetry will not show it, which means the first available signal is external — the credential appearing in stealer log data.
Do not wait for attribution. Whether the credential came from infostealer malware or from a combolist does not change the remediation. Rotate, revoke, clean the host.
Plan for out-of-hours. Nearly nine in ten ransomware deployments in the mid-market dataset landed outside business hours. Whatever your response capability is, it needs to work at 2am.
Common questions
How is an initial access broker different from a ransomware group?
They are different businesses. A broker obtains and validates access, then sells it. A ransomware affiliate buys access and monetises it through encryption or extortion. Neither performs the other's role, and the separation is now visible in incident response data — Mandiant tracks "prior compromise," meaning access acquired from another actor, as its own initial infection vector category, reaching 30% of ransomware-related intrusions in 2025.
What does network access cost?
Less than most people expect. Across 2023 to 2025 samples the central tendency sits around USD 500 to 1,500, with roughly 40% of listings priced between USD 500 and 1,000. Widely-quoted five-figure averages are driven by a handful of outlier listings and by asking prices rather than sale prices; treat them sceptically. Price rises with victim revenue, privilege level and sector.
Where does the access come from?
There is no published dataset decomposing broker acquisition methods by percentage, and any figure claiming otherwise should be checked. What exists is incident response data on how victims were breached, and it splits by caseload. Mandiant, whose clients skew enterprise, puts exploitation first at 32%. Sophos, whose 2026 caseload was 84% organisations under 1,000 employees, puts identity-related causes at 67.3% with compromised credentials alone at 42.1%. For a mid-sized organisation the Sophos distribution is the relevant one.
How long between a credential leaking and a ransomware incident?
The evidence is uneven. Access sells within one to three days of listing. The interval from listing to the victim appearing on a leak site has been reported at 23 to 36 days, but that rests on five traced cases from 2021 and has not been replicated. What is better evidenced is the hand-off itself: Mandiant's median time from initial access to hand-off fell from over eight hours in 2022 to 22 seconds in 2025.
Does multi-factor authentication make this irrelevant?
It raises the cost of a stolen password considerably, and it should be deployed. It does not address stolen session material. Flare reported 1.17 million stealer logs in 2025 containing active session cookies capable of bypassing MFA, because a session cookie represents an authentication that has already completed.
Have law enforcement takedowns reduced the supply of access?
They have fragmented the marketplace without measurably reducing supply. XSS's administrator was arrested in July 2025, BreachForums was seized again in October 2025, RAMP was seized in January 2026 and LeakBase in March 2026. Successor forums appeared within weeks in each case. Trust between participants has degraded; volume has not.
Check your own exposure
Enter a work email and SphereTI checks it against known breaches and stealer logs, then shows you which credentials have been exposed. Free, and it never asks for your password.
Get your free report