Initial-Access Brokers & the Access Economy
An initial-access broker (IAB) is a specialist who breaks into a network, verifies and packages the access (admin rights, VPN credentials, RDP, a foothold on a domain controller), and lists it for sale on a criminal forum — supplying the front door a ransomware affiliate uses before encrypting anything. The IAB is the wholesale tier of the attack supply chain, and in H2 2025 it professionalized and moved up-market: Rapid7's threat research found the average alleged revenue of victim organizations whose access was being sold had climbed to $3.24B, while the average advertised base price for an access listing jumped to ~$113,000 — roughly a 40× increase over 2024. The access economy is where the #1 intrusion vector — stolen credentials — is manufactured, priced, and distributed, which is a central reason identity security is among the most acquisitive segments in the market.
The two layers of the access economy
The access economy is a two-tier funnel that converts raw stolen data into a turnkey intrusion:
The bulk layer is the infostealer / stealer-log market — high-volume, low-price, commodity. Infostealer malware (Lumma, RedLine, Vidar, Raccoon, StealC) harvests everything a browser stores: saved passwords, session cookies, autofill, crypto wallets. The output ("logs") sells for $5–$50 per log (~$10 average per infected machine) in automated dark-web shops, while the malware itself is rented as a service for $100–$200/month (StealC, for example, ~$200/month or ~$800 for six months). This is the raw material — billions of stolen credentials, with industry trackers citing on the order of 15B+ exposed credentials circulating.
The wholesale layer is the IAB — low-volume, high-price, curated. The broker takes raw access (often sourced from the bulk layer, or from exploiting an edge device), validates it, establishes how valuable the victim is, and resells a verified, ready-to-use foothold. This is the value-add step: a buyer pays a premium for access that is confirmed to work, to a named target, at a known privilege level. The H2-2025 data shows brokers concentrating on government (~14% of listings), retail, and IT, and clustering on newer forums — RAMP and DarkForums together carried ~81% of observed access threads after older marketplaces were disrupted.
Why the access economy matters more than any single attack
The IAB layer is the structural reason ransomware survives takedowns and a central reason identity is among the most active M&A categories. Four implications:
- It decouples intrusion skill from monetization. A ransomware affiliate no longer needs to know how to break in — only how to buy access and deploy a payload. This is the same labor-specialization that made RaaS resilient: the access supply is a distinct, liquid market that persists regardless of which extortion brand is up or down.
- It makes credentials the product. When the wholesale price of "a working login to a $3B-revenue company" is six figures, the defensive value of preventing credential theft and abuse is enormous — and quantifiable. That is the demand curve under IAM, PAM, MFA, ITDR, and machine-identity.
- Automation is now visible on the supply side of this market, and it lowers the cost of the access rather than raising its price. Google's Threat Intelligence Group, in its AI Threat Tracker edition of Sep 8 2026, documents the financially motivated actor UNC6780 (TeamPCP) using an AI coding chatbot, a prompt and agent instructions to plan, build and execute a mass credential-harvesting campaign in less than six hours, as part of a run of large-scale open-source supply-chain compromises against PyPI, npm and Docker Hub beginning March 2026. The structurally relevant detail is not the speed but the handoff: in one Mandiant engagement the actor established initial access and passed it to a separate actor, who issued the ransom demand under LAPSUS branding. The broker did not monetise the intrusion itself. Two consequences follow. The wholesale price of access should be expected to fall, not rise, because the scarce input being automated is the intrusion labour the broker supplies — which cuts against reading a six-figure premium listing as the market's central price. And the supply channel shifts from phished employees to build pipelines, which moves the defensive spend that answers it from endpoint and email toward artifact provenance and dependency integrity (03f, 20a). (GTIG, Sep 8 2026)
- It moves up-market. The H2-2025 shift to higher-revenue victims and premium pricing means brokers are doing more reconnaissance and selectivity — the criminal market maturing toward "enterprise sales." Premium access implies premium targets, which implies the defensive spend follows the same up-market curve.
The landscape: markets, malware, and the disruption pattern
| Layer | Representative names (2025–26) | Note |
|---|---|---|
| Infostealer families | Lumma, RedLine, Vidar, Raccoon, StealC, Atomic (macOS) | Sold as MaaS; periodic LE takedowns (e.g., the 2025 disruptions) reshuffle market share |
| Log marketplaces | Automated dark-web shops + Telegram channels | Commoditized; volume-driven; cheap entry |
| Access forums | RAMP, DarkForums (≈81% of H2-25 threads), Exploit, XSS | Migrated here after older forums seized; access "auctions" |
| Historical takedowns | Genesis Market (seized Apr 2023), various RaaS infra | Each seizure displaces — but does not destroy — the supply |
The disruption pattern matters for the bear case: law enforcement has repeatedly seized marketplaces (Genesis Market in April 2023 being the landmark) and disrupted infostealer infrastructure — and each time the supply migrates to new forums rather than disappearing. The access economy is a hydra, which is precisely why the durable defensive answer is to make the stolen credential worthless (phishing-resistant MFA, session-binding, identity threat detection) rather than to rely on suppressing supply.
What the buy side offers for access
The prices above are drawn from advertised listings. A second, differently sourced figure appears in the joint FBI, CISA and HHS advisory on the Medusa ransomware operation, revised on August 18, 2026, which describes the arrangement from the buyer's side: Medusa developers recruit initial-access brokers on criminal forums and marketplaces and offer payments of between $100 and $1,000,000 per access, together with the opportunity to work exclusively for the operation. The advisory adds that most brokers appear willing to work for several ransomware variants at the same time.
The two figures measure different things and are not directly comparable. The advertised base price is what a broker asks for a single listing; the advisory's range is the full span one buyer will pay across every grade of access it purchases, from a low-value foothold to a privileged position inside a large organisation. What the second figure adds is independence of method — it derives from investigation of a buyer rather than from listings a seller writes and controls, which is the objection the bear case below raises against listing-derived pricing.
The non-exclusivity finding bears on the structure of the layer rather than its pricing. An operation able to offer seven-figure payments and a standing exclusivity arrangement has not converted the access supply into a captive channel. Brokers remain shared suppliers across competing extortion brands, which is the mechanism behind the disruption pattern described above: when one brand is seized or closes, the access it had been buying is already being sold to others, and affiliates move without an interruption in supply. The durable asset in the model is the supply layer, not the brand (Ransomware-as-a-Service).
Falsifiable bear case
The "access economy guarantees an identity-security supercycle" thesis has real counter-arguments. (1) Phishing-resistant auth could collapse the value of stolen credentials. If passkeys/FIDO2 and continuous session validation reach scale, a stolen password becomes far less useful — compressing both the criminal market and the legacy MFA/credential-monitoring vendors built around the password problem. The winners would be a narrower set (passwordless, ITDR) than the broad identity complex. (2) Platform bundling absorbs the category. Microsoft Entra, Okta, and the platform vendors increasingly ship identity-threat detection and credential monitoring as features, capping standalone pure-plays. (3) The data is noisy. "Average victim revenue $3.24B" and "$113k base price" come from advertised listings, which are self-reported and gameable; the true clearing prices may differ. The Medusa advisory supplies an independently sourced cross-check from the buyer's side but not a clearing price, so the objection is narrowed rather than answered. None of these kills the thesis — credentials will be stolen and sold for years — but each reshapes which identity vendors capture the value.
/ angle
→ The access economy is the proof behind the identity-M&A wave. When the wholesale market prices "a working corporate login" in the six figures, the strategic logic of Palo Alto–CyberArk and the broader identity consolidation (Identity) is no longer abstract — it is the defensive answer to a priced criminal product. That makes ITDR, machine-identity (20b), and credential-/dark-web-intelligence vendors a coherent buy-side targeting cluster.
→ Infostealer + browser theft → browser-security thesis. Logs are harvested from the browser, which is why enterprise browser and browser-extension security (the CrowdStrike–SGNL/Seraphic, Palo Alto–Talon, Zscaler–SquareX lineage on 11) sits directly downstream of this market.
Sources: CISA/FBI/HHS — #StopRansomware: Medusa Ransomware (AA25-071A, updated Aug 18, 2026) · Rapid7 — IABs shift to high-value targets & premium pricing (H2 2025) · DeepStrike — Dark Web Data Pricing 2025 · DeepStrike — Stealer Log Statistics 2025 · Flare — Infostealer Malware · DeepStrike — Dark Web Statistics 2025
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.