

The division of labour in the ransomware ecosystem has become sophisticated enough that the organisation responsible for compromising a target and the organisation that deploys ransomware on that target are often entirely different entities. Initial access brokers, a category of dark web market participants that emerged prominently around 2020 and has grown significantly since, occupy the compromise layer of this supply chain. They specialise in gaining initial access to corporate networks, usually through credential theft, exploitation of vulnerable internet-facing services, or phishing, and then selling that access to other threat actors rather than using it themselves. The buyers are typically ransomware operators, who apply the purchased access to deploy their ransomware, conduct further reconnaissance, and execute the extortion campaign that generates their revenue.
The existence of the IAB layer in the ransomware supply chain has several significant implications for how defenders think about threat intelligence and incident response. First, the compromise event and the ransomware deployment event are often separated by days to weeks, because the IAB sells the access and the ransomware operator then needs time to prepare the campaign. This separation means that early detection of the initial compromise, before the IAB has sold the access or before the ransomware operator has expanded their foothold, can prevent a ransomware incident entirely. Second, the IAB's listings on criminal forums reveal which organisations are currently compromised and for sale, giving defenders the ability to detect that their own organisation is listed and respond before the ransomware operator acts.
IAB listings on dark web forums and markets describe the access being sold in standardised terms that reflect what ransomware operators need to make a purchasing decision. Typical listing components include: the access type (RDP, VPN, web shell, domain admin, etc.), the victim's revenue and industry sector, the geography of the victim, the number of devices visible from the access point, the current privilege level of the access, and the asking price.
Pricing varies significantly based on these factors. RDP access to a small company with 50 employees might sell for a few hundred dollars. Domain administrator access to a multinational company with thousands of employees and high annual revenue can sell for tens of thousands of dollars. The pricing reflects the potential ransomware payout that the buyer can extract from the victim: a buyer who pays $10,000 for access to a large company expects to demand and receive a ransom of hundreds of thousands to millions of dollars, making the acquisition price a small fraction of the expected return.
Researchers at KELA and Flashpoint who systematically collect IAB listings have documented that healthcare, finance, and manufacturing are consistently among the most frequently listed sectors, reflecting both their high ransomware payout potential and the prevalence of exploitable vulnerabilities in their internet-facing infrastructure. Geographic distribution of IAB listings shows strong concentration in North America and Europe, where ransomware groups have historically achieved the highest ransom payments, though listings from other regions have grown in proportion as groups have expanded their targeting globally.
IAB access acquisition methods map directly onto the most common enterprise security gaps. Remote Desktop Protocol exposed on the internet, either directly or through poorly configured VPN gateways, is the most documented access vector for IABs. Credential guessing against RDP, using credential lists from infostealer logs and previous breaches, requires no software vulnerability and succeeds when the target organisation has not enforced MFA or account lockout policies on its remote access infrastructure. A vulnerable RDP endpoint discovered through Shodan scanning can be compromised in minutes.
VPN and remote access appliance vulnerabilities are the second major IAB access category. The critical vulnerabilities disclosed in major VPN products from Pulse Secure, Citrix, Fortinet, and Ivanti in 2023, 2024, and 2025 each generated significant IAB activity as brokers scanned for and compromised organisations running unpatched versions. The combination of a public proof-of-concept exploit and a large installed base of vulnerable appliances consistently produces a wave of IAB access listings in the weeks following disclosure, representing the speed at which brokers move from vulnerability announcement to active exploitation.
Phishing for credentials and session tokens feeds the IAB market indirectly through the infostealer log ecosystem. IABs who purchase infostealer logs can extract credentials for VPN, remote desktop, and corporate applications from those logs and use them to authenticate to target networks without any additional exploitation. This creates a second-order connection between the infostealer market and the ransomware supply chain: an employee whose credentials are stolen by an infostealer may have their organisation listed on an IAB market within days, and the organisation may face a ransomware deployment weeks later. Monitoring your credential exposure in infostealer logs is therefore also a leading indicator for ransomware risk through the IAB channel.
The operational value of monitoring IAB forums is the potential to detect that your organisation has been listed for sale before the ransomware operator has purchased and used the access. This detection window, measured in days to weeks in typical cases, is the most valuable pre-ransomware indicator available. It occurs before the ransomware is deployed, before internal monitoring may have detected the initial compromise, and before any public disclosure has occurred. Responding to an IAB listing detection means immediately identifying and revoking the access vector being sold, resetting credentials associated with that access, and reviewing recent network activity for lateral movement or data exfiltration activity that may have occurred during the broker's assessment period.
Systematic monitoring of IAB forums requires the same dark web intelligence capabilities as monitoring ransomware leak sites: access to the forums where listings appear, automated collection of listing data, and alerting mechanisms tied to the monitored organisation's identifiers. Security vendors that maintain continuous monitoring of IAB forums can provide near-real-time alerts when a listing matching an organisation's profile appears. Dark web monitoring that specifically covers IAB activity gives security teams the pre-ransomware detection capability that no internal tool can provide.
The timeline between IAB listing and ransomware deployment reveals an important defensive window. Research from security firms that track IAB transactions shows that the average time between when an IAB lists access and when a ransomware operator deploys an attack using that access ranges from a few days to several weeks, with the median closer to two weeks in documented cases. This is not a narrow window: two weeks of advance warning, starting from when you detect your organisation in an IAB listing, is ample time to execute a focused incident response that revokes the compromised access and investigates the initial compromise.
The challenge is that detecting your own organisation in an IAB listing requires active monitoring of the specific forums and markets where IABs operate, many of which require accounts, vouching by existing members, or cryptocurrency payments to access. Most organisations cannot maintain this monitoring directly. Security vendors and threat intelligence platforms that maintain continuous monitoring of IAB forums provide this capability as a service, alerting their clients when listings matching their profile appear. The investment in this monitoring is justified by the potential cost of a ransomware incident that it can prevent.
The defensive response to the initial access broker market requires addressing both the initial compromise that produces the access being sold and the window between that compromise and its use. On the prevention side, the initial access methods that IABs most commonly sell, primarily compromised VPN credentials, Remote Desktop Protocol access, and exploit-based entry through unpatched internet-facing services, are addressable through known security controls: MFA on remote access services, regular credential rotation, and rapid patching of known-exploited vulnerabilities. The challenge is the consistency of application, particularly in large organisations with complex infrastructure or in organisations that have acquired new business units with legacy systems that are difficult to patch quickly.
Detection of IAB activity targeting your organisation requires monitoring the forums and marketplaces where access listings appear. An IAB posting that lists access to a specific organisation by name, or that describes the access in enough detail to identify the target, gives that organisation a window to revoke the listed access before a buyer deploys ransomware. This window is typically short, hours to days, because IAB postings attract buyer attention quickly. But even a short window is actionable: emergency access reviews for external-facing services, rotation of credentials for remote access systems, and enhanced monitoring of authentication events can all be triggered by an IAB intelligence alert about your organisation.
Dark web monitoring that covers IAB forums and includes automated alerting on mentions of your organisation's domain, company name, or key identifiers is the detection layer that makes this pre-ransomware window actionable. Without this monitoring, organisations typically discover they were listed as an IAB target only after the ransomware has been deployed, at which point the actionable intelligence comes too late. Continuous dark web monitoring covering IAB marketplaces is what converts an IAB listing from a precursor to a confirmed incident into a detectable early warning that enables pre-ransomware response.
VPN credential access is consistently the most common type of access offered by IABs, reflecting both the prevalence of VPN as a remote access technology and the effectiveness of credential stuffing, phishing, and vulnerability exploitation against VPN products. Remote Desktop Protocol access and web shell access to compromised web servers are the next most common categories. Access to domain administrator accounts, while less common, commands the highest prices and is most directly usable for rapid ransomware deployment without requiring additional lateral movement.
Sophisticated ransomware groups typically evaluate IAB listings based on several criteria: the size of the target organisation (determined from public information or from what the IAB discloses about revenue or employee count), the specificity of the access (domain admin access is more valuable than a standard user VPN credential), the security products visible in the environment (an EDR that the ransomware payload can evade makes the access more valuable), and the reputation of the IAB seller. High-value access listings are often contested through auction-style formats or sold through private negotiations rather than public forum posts.
Yes, through dark web monitoring that covers the forums and marketplaces where IABs operate. When an IAB listing references your organisation by name, describes access to your specific systems, or includes enough details to identify you as the target, that listing is detectable by monitoring services that include IAB forum coverage. The challenge is speed: IAB listings attract buyer attention quickly, and the window between listing and purchase can be hours for high-quality access. Automated monitoring with rapid alerting is necessary to make this intelligence actionable before a purchase is made and ransomware deployment begins.
While credential-based initial access (through stolen VPN credentials, phishing for access, or credential stuffing) represents the largest category of IAB offerings, vulnerability exploitation is a significant secondary source of the accesses that IABs sell. The relationship between newly published vulnerabilities and IAB activity is direct and fast: when a critical vulnerability affecting a widely deployed internet-facing system is published, exploitation activity, including activity specifically aimed at acquiring access for later sale through IAB channels, typically begins within hours to days of publication. The exploit code may be incorporated into automated scanning tools that identify vulnerable instances at scale, with the resulting access catalogued and eventually sold through IAB channels.
The specific vulnerabilities that drive the most IAB activity tend to be those affecting systems that are directly internet-facing and that provide meaningful access without requiring additional lateral movement. VPN gateway vulnerabilities are consistently the highest-value category because a compromised VPN gateway provides authenticated access to the internal network, making the access immediately useful for a ransomware operator without requiring additional exploitation steps. Web application vulnerabilities that lead to server compromise, vulnerabilities in remote code execution on email servers, and vulnerabilities in remote management systems like RMM tools used by managed service providers are other high-value IAB acquisition categories.
Rapid patching of known-exploited vulnerabilities is one of the most direct mitigations for IAB-sourced initial access, because it reduces the window during which automated exploitation and access collection can succeed. CISA's Known Exploited Vulnerabilities (KEV) catalogue, which lists vulnerabilities that have been documented in active exploitation, provides a prioritised list that gives defenders clarity on which patches are most urgent from an active threat perspective rather than just a theoretical severity perspective. Organisations that use the KEV catalogue to prioritise their patching programme, applying KEV-listed patches within 24-48 hours of identification, materially reduce their exposure to IAB-acquired access compared to organisations that follow quarterly patching cycles.
The pricing dynamics in IAB markets reflect the economics of the ransomware ecosystem. Access prices are set by the intersection of the buyer's perceived value (how much ransomware revenue the access might enable) and the seller's acquisition cost (how difficult it was to obtain the access and how many competing sellers have similar offerings). Prices have been documented to correlate with factors including the target organisation's revenue (larger organisations command higher prices because they can afford larger ransoms), the specificity of the access (domain admin commands a premium over standard user access), and current market supply (when a widely deployed vulnerability is actively exploited, the market may be flooded with similar accesses, depressing prices for that access type).
The timing dynamics are important for defenders. IAB listings for high-value access can be transacted quickly once they appear, sometimes within hours for listings that match active buyer demand. A listing that appears on a Friday afternoon may result in a ransomware deployment by the following Monday, leaving a very short window for defenders who become aware of the listing to respond. This urgency is why the monitoring and alerting architecture for IAB intelligence needs to be capable of real-time alerting rather than daily digests: an alert that arrives 18 hours after a listing appears may come after the access has already been sold and used.
The most effective prevention against IAB access from credential compromise is systematic credential hygiene across the complete inventory of external-facing services. Credential hygiene for IAB prevention specifically means: rotating all credentials for external-facing services (VPN, RDP, web application login) on a schedule that ensures any credential captured in a breach dataset that is sold into IAB channels has been changed before the buyer attempts to use it; ensuring MFA is required for all external-facing services without exception; and monitoring for credential appearances in breach datasets through dark web monitoring services so that exposed credentials can be identified and rotated proactively rather than reactively.
The rotation schedule question is one that many organisations struggle with because the tradeoffs between security and operational friction are real. Frequent credential rotation reduces the window during which an exposed credential remains valid, but it also creates operational burden for users and support teams. The pragmatic resolution for most organisations is risk-stratified rotation: higher-frequency rotation for credentials used on high-value external-facing systems (VPN administrator credentials, for example) and standard-frequency rotation for general user credentials, supplemented by immediate rotation when monitoring detects a credential appearing in a new breach dataset. This approach concentrates the rotation overhead where the risk is highest rather than applying uniform overhead across all credentials regardless of their risk profile.
Monitoring for employee credential appearances in breach datasets is the intelligence input that makes targeted rotation practical. Without monitoring, organisations either rotate all credentials frequently (high overhead) or rotate infrequently (high risk exposure window). With monitoring, they can rotate specifically when a credential is identified as exposed, which concentrates the action on the cases where rotation is most urgent. The monitoring needs to include not just current employee email addresses but also historical ones from domains used before rebranding and from acquired organisations, because attackers who purchase breach datasets do not filter for only currently active email addresses.
The long-term strategic implication of the initial access broker market for enterprise security posture is that organisations can no longer rely on perimeter security alone to prevent ransomware attacks. When access to internal networks is commercially available to any ransomware group willing to pay the market price, the perimeter is not the last line of defence: it is a layer that reduces the frequency of successful intrusions but cannot prevent them entirely. The security controls that limit the impact of a successful initial access purchase, specifically strong network segmentation that limits lateral movement, endpoint detection that identifies post-compromise activity, and backup strategies that enable recovery without ransom payment, are as important as the perimeter controls that aim to prevent initial access in the first place.
The dark web intelligence described in this article, ransomware leak site monitoring, initial access broker tracking, and criminal forum surveillance, is valuable precisely because it is external to your perimeter and operates on a timeline that precedes most attacks. An organisation listed on a ransomware leak site has already been compromised; the value of monitoring is detecting that listing before the public announcement and before the data is downloaded by third parties. An organisation whose credentials appear in an IAB listing has a window to revoke those accesses before the buyer deploys ransomware.
Defendis monitors ransomware leak sites, initial access broker forums, and criminal marketplaces continuously, with alerts targeted to your organisation's identifiers, domains, IP ranges, employee data, and brand name. Intelligence surfaces in time to act, not after the fact.
Book a demo to see how Defendis monitors ransomware groups and IAB activity for your sector.