A cybercriminal specialized in reselling pre-obtained access to corporate networks, upstream of the final attack.
An Initial Access Broker is a specialized link in the attack chain that focuses on a single stage, namely obtaining access to corporate networks, which it then resells on underground forums to other actors, notably ransomware affiliates. The access sold may take the form of valid credentials, remote-desktop access, an exploitable vulnerability or an already active session. This specialization directly illustrates the division of labor within the cybercriminal economy, where intrusion and monetization have become two distinct trades. For cyber underwriting, the existence of an access market shifts part of the risk analysis toward the insured's authentication hygiene, the exposure of its remote services and the speed at which it patches vulnerabilities. One methodological difficulty should be noted, however: access may be resold several months before it is exploited, creating a time lag between initial compromise and reported loss, and complicating the dating of the triggering event under an insurance contract.
A broker advertises administrator access to a European industrial company for a few thousand dollars on a forum; a ransomware affiliate buys it, then deploys encryption several weeks later.
courtier en accès initial, vendeur d'accès