Defenses Get Harder, So Attackers Change Targets
As organizations harden their perimeters with MFA, EDR, and improved network segmentation, ransomware-as-a-service groups are increasingly turning to a defense that firewalls and VPNs cannot stop: people with legitimate access. Security researchers report a growing pattern of insider-assisted ransomware attacks, where affiliates recruit employees, contractors, or trusted partners to hand over the keys instead of breaking in themselves.
How the Recruitment Works
According to Tim Rawlins, senior adviser and director of security at NCC Group, ransomware-as-a-service operators are treating employees and contractors as gateways into targeted organizations. Recruitment typically happens through:
- Dark web forums advertising payment for insider access or credentials
- Encrypted messaging platforms like Telegram used to approach targeted employees directly
- Direct offers to disgruntled or financially motivated staff, promising a cut of ransom proceeds in exchange for network access or help disabling security controls
The appeal for attackers is straightforward: instead of spending time and resources probing for a vulnerability or crafting a convincing phishing lure, they can walk straight through the front door with help from someone already inside.
Scale Is Hard to Measure, but the Trend Is Real
Researchers caution that the true scale of insider-assisted ransomware is difficult to pin down due to limited visibility into how initial access is actually obtained in many breaches. Rawlins notes that while insider-assisted attacks are real, they are not yet the dominant initial access route — but the trend is accelerating as traditional intrusion methods become harder to execute against well-defended networks.
Satnam Narang, a security researcher cited in the coverage, points out that the arrangement isn't without risk for the criminals themselves: a targeted employee could report the approach to their employer or law enforcement instead of cooperating. In one documented case, a targeted employee played along with an attacker's outreach specifically to gather intelligence, later revealing that the threat actor's pitch was to "secretly sell the keys to my corporation's kingdom in exchange for a hefty pay day."
Why This Matters for Defenders
Not every breach begins with a zero-day exploit or a sophisticated phishing campaign. Some start with an employee who simply decides to help attackers in. This shifts part of the risk calculus for security teams:
| Traditional Focus | Insider-Threat Consideration |
|---|---|
| Patch management, perimeter hardening | Employee monitoring, access reviews |
| Phishing-resistant MFA | Background checks, financial-stress indicators |
| EDR and network segmentation | Least-privilege access, separation of duties |
| Vulnerability scanning | Whistleblower and reporting channels |
Recommended Actions
- Strengthen insider threat programs — combine HR, legal, and security functions to identify and respond to recruitment attempts.
- Enforce least-privilege access so no single employee can single-handedly enable a full compromise.
- Monitor for anomalous access patterns, particularly privileged account use outside normal behavior baselines.
- Provide clear, confidential reporting channels for employees who are approached by criminal actors, removing the fear of retaliation for reporting contact.
- Review offboarding and credential rotation processes to reduce the window of opportunity for departing or disgruntled staff.
Broader Context
This reporting aligns with similar findings from Check Point Research and Recorded Future, both of which have tracked increased criminal recruitment of insiders across banking, telecom, and technology sectors in 2026. As ransomware groups face tougher technical defenses, the human element — already the most common root cause across breach reports — is becoming an explicit, targeted recruitment channel rather than an incidental weakness.