Understanding the Complex World of Cybercrime: The Role of Access Brokers
In today’s digital landscape, news about significant data breaches or disruptive ransomware attacks often paints a picture of solo hackers or rogue groups orchestrating chaos. However, the reality is much more intricate. The cybercrime ecosystem operates through a network of specialists, including a lesser-known yet pivotal player: access brokers.
The Function of Access Brokers
Access brokers are hackers who specialize in infiltrating networks and selling that access to other criminals. While some hackers prefer to execute all tasks themselves, many leverage these brokers for a more focused approach. According to the 2025 Access Brokers Report by Rapid7, a small number of skilled individuals dominate this profitable market.
Key Players in the Access Broker Space
A striking example comes from the Russian-language hacking community, particularly the Exploit Forums. Here, just two brokers—known as “doZKey” and “sganarelle2”—account for over 65% of initial access offerings. In only six months, their activities outshined 11 other brokers active on the platform.
DoZKey, for instance, posted an offer in November 2024, advertising access to four corporations across the UK, Spain, and South Africa. Prices for such illicit access ranged from $400 to $1,000, along with details about the antivirus software present on each network. This level of transparency provides potential buyers with insights crucial for planning their next malicious steps.
Why Access Brokers Don’t Steal Data Themselves
A critical question arises from the operations of these access brokers: Why don’t they expand their efforts to exfiltrate data directly? The answer lies in a balance of risk and reward. Jeremy Makowski, a senior threat intelligence researcher at Rapid7, explains that access brokers are primarily motivated by financial gain but also prefer to minimize their risks.
Risk Management in Cybercrime
Access brokers focus on maintaining and selling network access obtained through various means, such as stolen credentials or compromised VPNs. By selling this access instead of carrying out data theft themselves, they sidestep heightened risks associated with detection by cybersecurity forces. This division of labor allows them to manage multiple accesses simultaneously while evading the intense scrutiny usually faced by active extortionists or ransomware attackers.
Think of them as wholesale operators in a cybercrime supply chain, preferring simpler, repeatable transactions over high-stakes illicit acts.
Actionable Intelligence from Access Brokers
Interestingly, while these brokers play a crucial role in cybercrime, they also serve as a valuable resource for network defenders. Brokering activities often include detailed listings about the sectors their victims belong to, employee counts, and annual revenues—information frequently gleaned from public sources like Crunchbase.
Monitoring Threats in Real-Time
According to Makowski, organizations can significantly benefit from monitoring underground forums for mentions of their business or sector. Even if a company isn’t specifically named, similarities in factors like technology and size can indicate potential risks. By understanding the nature of the access being sold—be it through RDP, VPN, or other means—cybersecurity teams can enhance their defenses accordingly.
If an organization suspects it is being targeted, immediate action is essential.
Steps to Mitigate Risks
Upon confirmation of such threats, the first course of action should involve verification with internal cybersecurity teams and trusted threat intelligence partners. Following this, containment measures must be swiftly implemented.
Implementing Containment Strategies
Recommended steps include securing or disabling compromised entry points, enforcing multifactor authentication, and resetting any exposed credentials. A thorough review of related suspicious activities should follow, along with patching or disabling vulnerable services. Involving incident response specialists can further aid in a comprehensive investigation.
Conclusion: Access Brokers as Bellwethers
While access brokers undeniably pose significant risks to organizations, they also provide crucial insights into emerging threats. By vigilantly monitoring their activities, businesses can potentially avert greater dangers on the horizon, acting as a proactive response mechanism against an increasingly sophisticated cybercrime landscape.


