The Business of Cyber Security

Initial-Access Brokers & the Access Economy

An initial-access broker (IAB) is a specialist who breaks into a network, verifies and packages the access (admin rights, VPN credentials, RDP, a foothold on a domain controller), and lists it for sale on a criminal forum — supplying the front door a ransomware affiliate uses before encrypting anything. The IAB is the wholesale tier of the attack supply chain, and in H2 2025 it professionalized and moved up-market: Rapid7's threat research found the average alleged revenue of victim organizations whose access was being sold had climbed to $3.24B, while the average advertised base price for an access listing jumped to ~$113,000 — roughly a 40× increase over 2024. The access economy is where the #1 intrusion vector — stolen credentials — is manufactured, priced, and distributed, which is a central reason identity security is among the most acquisitive segments in the market.

The two layers of the access economy

The access economy is a two-tier funnel that converts raw stolen data into a turnkey intrusion:

The bulk layer is the infostealer / stealer-log market — high-volume, low-price, commodity. Infostealer malware (Lumma, RedLine, Vidar, Raccoon, StealC) harvests everything a browser stores: saved passwords, session cookies, autofill, crypto wallets. The output ("logs") sells for $5–$50 per log (~$10 average per infected machine) in automated dark-web shops, while the malware itself is rented as a service for $100–$200/month (StealC, for example, ~$200/month or ~$800 for six months). This is the raw material — billions of stolen credentials, with industry trackers citing on the order of 15B+ exposed credentials circulating.

The wholesale layer is the IAB — low-volume, high-price, curated. The broker takes raw access (often sourced from the bulk layer, or from exploiting an edge device), validates it, establishes how valuable the victim is, and resells a verified, ready-to-use foothold. This is the value-add step: a buyer pays a premium for access that is confirmed to work, to a named target, at a known privilege level. The H2-2025 data shows brokers concentrating on government (~14% of listings), retail, and IT, and clustering on newer forums — RAMP and DarkForums together carried ~81% of observed access threads after older marketplaces were disrupted.

The access economy: commodity logs are refined into premium, verified access Price rises ~10,000× from a single stealer log to a curated network foothold BULK LAYER · infostealer logs Lumma · RedLine · Vidar · Raccoon · StealC harvest browser creds, cookies, wallets $5–$50 / log WHOLESALE LAYER · IABs validate + package verified access named target · known privilege level ~$113k avg base price refine ↑ BUYERS · ransomware affiliates · APTs · fraud crews skip the break-in — buy a working front door Most-targeted sectors (H2 2025): government ~14%, retail, IT · RAMP + DarkForums ≈ 81% of access threads. Source: Rapid7 (H2 2025); Flare; DeepStrike; vendor stealer-log trackers. Exhibit: The Business of Cyber Security.
The funnel turns the #1 intrusion vector — stolen credentials — into a priced, traded commodity. The premium step is *verification*: buyers pay ~$113k for access confirmed to work, vs ~$10 for an unverified log. See [15a](15a-ransomware-as-a-service.md) for who buys.

Why the access economy matters more than any single attack

The IAB layer is the structural reason ransomware survives takedowns and a central reason identity is among the most active M&A categories. Three implications:

  1. It decouples intrusion skill from monetization. A ransomware affiliate no longer needs to know how to break in — only how to buy access and deploy a payload. This is the same labor-specialization that made RaaS resilient: the access supply is a distinct, liquid market that persists regardless of which extortion brand is up or down.
  2. It makes credentials the product. When the wholesale price of "a working login to a $3B-revenue company" is six figures, the defensive value of preventing credential theft and abuse is enormous — and quantifiable. That is the demand curve under IAM, PAM, MFA, ITDR, and machine-identity.
  3. It moves up-market. The H2-2025 shift to higher-revenue victims and premium pricing means brokers are doing more reconnaissance and selectivity — the criminal market maturing toward "enterprise sales." Premium access implies premium targets, which implies the defensive spend follows the same up-market curve.

The landscape: markets, malware, and the disruption pattern

Layer Representative names (2025–26) Note
Infostealer families Lumma, RedLine, Vidar, Raccoon, StealC, Atomic (macOS) Sold as MaaS; periodic LE takedowns (e.g., the 2025 disruptions) reshuffle market share
Log marketplaces Automated dark-web shops + Telegram channels Commoditized; volume-driven; cheap entry
Access forums RAMP, DarkForums (≈81% of H2-25 threads), Exploit, XSS Migrated here after older forums seized; access "auctions"
Historical takedowns Genesis Market (seized Apr 2023), various RaaS infra Each seizure displaces — but does not destroy — the supply

The disruption pattern matters for the bear case: law enforcement has repeatedly seized marketplaces (Genesis Market in April 2023 being the landmark) and disrupted infostealer infrastructure — and each time the supply migrates to new forums rather than disappearing. The access economy is a hydra, which is precisely why the durable defensive answer is to make the stolen credential worthless (phishing-resistant MFA, session-binding, identity threat detection) rather than to rely on suppressing supply.

Falsifiable bear case

The "access economy guarantees an identity-security supercycle" thesis has real counter-arguments. (1) Phishing-resistant auth could collapse the value of stolen credentials. If passkeys/FIDO2 and continuous session validation reach scale, a stolen password becomes far less useful — compressing both the criminal market and the legacy MFA/credential-monitoring vendors built around the password problem. The winners would be a narrower set (passwordless, ITDR) than the broad identity complex. (2) Platform bundling absorbs the category. Microsoft Entra, Okta, and the platform vendors increasingly ship identity-threat detection and credential monitoring as features, capping standalone pure-plays. (3) The data is noisy. "Average victim revenue $3.24B" and "$113k base price" come from advertised listings, which are self-reported and gameable; the true clearing prices may differ. None of these kills the thesis — credentials will be stolen and sold for years — but each reshapes which identity vendors capture the value.

/ angle

The access economy is the proof behind the identity-M&A wave. When the wholesale market prices "a working corporate login" in the six figures, the strategic logic of Palo Alto–CyberArk and the broader identity consolidation (Identity) is no longer abstract — it is the defensive answer to a priced criminal product. That makes ITDR, machine-identity (20b), and credential-/dark-web-intelligence vendors a coherent buy-side targeting cluster.

Infostealer + browser theft → browser-security thesis. Logs are harvested from the browser, which is why enterprise browser and browser-extension security (the CrowdStrike–SGNL/Seraphic, Palo Alto–Talon, Zscaler–SquareX lineage on 11) sits directly downstream of this market.


Sources: Rapid7 — IABs shift to high-value targets & premium pricing (H2 2025) · DeepStrike — Dark Web Data Pricing 2025 · DeepStrike — Stealer Log Statistics 2025 · Flare — Infostealer Malware · DeepStrike — Dark Web Statistics 2025


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.