An initial access broker (IAB) is a criminal who breaks into a company's network and sells the entry point — VPN credentials, remote desktop access, admin panels — rather than attacking further themselves. The buyers are usually ransomware crews who prefer to buy a ready-made way in. IABs are why the criminal economy runs like an industry, and why one stolen employee login can end as a company-wide ransomware incident.
- An IAB sells entry, not attacks: credentials, RDP, admin panels
- Ransomware crews are the main buyers
- Specialisation made ransomware scale like an industry
- It's the supply side of ransomware-as-a-service
- The defence is the first link: patching, MFA, monitoring
The biggest shift in cybercrime isn't a new kind of attack — it's a new division of labour. Modern intrusions are assembled from specialists, and the one that matters most, and is least understood, sells the way in.
What an IAB sells
An initial access broker (IAB) breaks into an organisation's network and then, instead of attacking further, sells the entry: VPN credentials, remote desktop access, compromised admin panels, or working employee logins. Listings are priced by how lucrative the target looks. The broker sells the first step of an attack, cleanly separated from the attack itself.
Why this specialisation exists
Breaking in and cashing out are different skills, and separating them makes both more efficient. A talented intruder may have no interest in running a ransomware operation; a ransomware crew may be slow at breaking in. The IAB market lets each do what it's best at — which is a major reason ransomware scaled.
The supply chain
| Role | What they do | What they sell |
|---|---|---|
| Stealer / phisher | Harvest credentials | Raw logins |
| Initial access broker | Confirm and package entry | Working network access |
| Ransomware affiliate | Break out, steal, encrypt | The ransom |
| Ransomware operator | Provide malware & leak site | A cut of every haul |
A stealer log or phish produces a credential; the IAB turns it into confirmed access and lists it; a ransomware affiliate buys it and attacks. This is “ransomware-as-a-service,” and the IAB is its supply side.
Where to break the chain
Every stage after initial access is harder to stop than the first. The highest-value defences deny the broker their product: prompt patching, phishing-resistant multi-factor authentication on every remote-access point, and monitoring for intrusions. Break the first link and the rest of the chain has nothing to buy.
Frequently asked questions
What is an initial access broker?
A criminal who breaks into an organisation's network and sells the entry point — VPN credentials, remote desktop access, admin panels — rather than attacking further. The buyers are usually ransomware crews who prefer a ready-made way in.
How do initial access brokers get in?
Through the same routes as most intrusions: phished credentials, unpatched systems, or logins harvested from stealer-log malware. They confirm the access works and package it for sale, often described by the victim's sector and revenue.
Why are initial access brokers important?
Because they let cybercrime specialise. Breaking in and running extortion are different skills; the IAB market lets each party do what it's best at, which is a major reason ransomware scaled.
What is ransomware-as-a-service?
A model where ransomware operators provide the malware and leak-site infrastructure as a service, and affiliates carry out attacks for a share of the ransom. Initial access brokers supply the entry points, making the whole chain an efficient market.
How do you defend against initial access brokers?
Deny them their product: patch internet-facing systems promptly, put phishing-resistant multi-factor authentication on every remote-access point, maintain strict credential hygiene, and monitor for intrusions. Breaking the first link leaves the chain nothing to buy.