Somewhere on a Telegram channel, there is a job advert your recruiters will never see.
It offers a fixed fee or a share of the profits. It uses brokers and escrow so both sides can trust the deal. Some even pay a referral bonus. The role is simple: keep doing your job, but occasionally do it for someone else.
This is the insider market, and in 2026 it has stopped being a fringe of the cybercrime economy. TrendAI’s researchers now describe it as one of the fastest-growing and least understood risks to enterprise security.
For HR and screening professionals, that shift matters more than it first appears. The insider market doesn’t target your systems. It targets your people, after you’ve hired them, in exactly the roles your hiring process fills every week.
The Job Board Nobody in HR Reads
Start with scale. Flashpoint, which monitors illicit forums and encrypted channels, identified 12,653 insider posts in July 2026, of which 1,132 were unique. Between July 2025 and July 2026, that works out to an average of 34 unique insider posts every day.
The more unsettling number is the direction of traffic. More than 75% of those unique posts came from insiders advertising their own access to third parties, not from criminals trying to recruit.
The popular picture of insider threat is a gang slowly grooming a vulnerable employee. The data describes something closer to a seller’s market, where the employee goes looking for the buyer.
The market is also spreading. Telecoms, retail and financial services have historically absorbed the most insider activity, but in July 2026, 58.6% of posts touched “other” industries, which Flashpoint reads as buyers probing supply chain partners, logistics hubs and specialist service providers for alternative ways in.
The infrastructure looks uncomfortably familiar. There are brokers, escrow services and recruitment posts, and insiders can take a fixed payment or a profit share. It has every feature of a labour market except one: the employer never finds out.
Why Buying Beats Breaking
The economics are straightforward. As perimeter security and endpoint detection mature, attackers are finding it faster and cheaper to simply buy an insider’s credentials or pay an employee to open the door.
An insider also brings something no external attacker can fake: legitimacy. They log in from the expected device, at the expected hour, into systems they’re supposed to use. Insider activity is hard to catch with internal controls precisely because it rides on valid credentials.
The clearest statement of this logic came from a victim. After Coinbase’s 2025 breach, its security leadership argued that attackers resorted to paying help desk workers because the rest of the security programme was strong. Bribery was what was left.
That is a compliment and a warning in the same breath. The better your technical defences, the more your people become the attack surface.
What the Buyers Are Actually Shopping For
If you picture the targeted insider as a systems administrator with root access, you’ll protect the wrong people.
TrendAI’s research found that buyers value decision-making power over raw privilege. They want employees who can authorise payments, restore accounts or bypass fraud checks, which are actions an outside attacker could never credibly imitate.
The price list reflects this. At social media companies, buyers want insiders who will safelist dodgy adverts, help with account takeovers or lift bans, with ban removals alone running $1,000 to $7,000. Review platforms are targeted for deleted complaints and approved fraudulent refunds. Telecom staff are targeted for SIM swaps that break SMS-based authentication.
Logistics has joined the list. One buyer offered $1,000 a day for a FedEx employee capable of uploading tracking data into internal systems. Listings stretch from a few hundred dollars for credentials to a government-linked platform up to premium offers for administrator control inside large enterprises.
Now look at those roles again: support agents, trust and safety reviewers, retail telecom staff, operations approvers.
These are high-volume, often entry or mid-level positions. They are filled quickly, frequently outsourced and, in most organisations, screened with a standard package rather than a considered one. They are the roles screening programmes process at scale, and the roles the insider market prices highest.
The Case That Put a Price on It
The Coinbase breach remains the defining case, because it shows the whole chain in one incident.
Starting in December 2024, attackers targeted Coinbase support agents working for the outsourcing firm TaskUs in Indore, reportedly offering bribes of up to $2,500 per person to copy data from their support tools. Around 70,000 customers were affected.
The bill was enormous. Coinbase’s SEC filing put preliminary remediation and reimbursement costs at $180 million to $400 million, and TaskUs stopped taking Coinbase calls at the Indore facility, with 226 workers let go.
The story has kept unfolding. A court filing reported in July 2026 identified a TaskUs employee as a key conspirator, alleging she sold stolen data at $200 per record. Earlier in 2026, Hyderabad police arrested a former Coinbase customer service agent believed to have been bribed.
Three lessons sit inside that case.
The access that mattered belonged to support agents, not engineers. The people involved were hired and managed under a vendor’s process, not the client’s. And the price of each betrayal was tiny next to the damage: a few thousand dollars in bribes against a nine-figure bill.
Why the Delivery Centre Is the Front Line
For employers in India and the Gulf, the Coinbase case carries a specific message.
India, the Philippines and increasingly the Gulf host the customer support, back-office and trust and safety operations of global brands. These are precisely the seats on the buyers’ price list: account recovery, customer data, transaction approvals. The attackers didn’t go after Coinbase’s engineers. They went to the support floor.
The Gulf has its own record here. In 2022, a Dubai criminal court sentenced a bank customer services employee to three years in prison for selling clients’ phone numbers, card and account details to a scammer.
The pattern holds across geographies. Pay is modest relative to the value of the access. Headcounts are large. Screening is often compressed to hit hiring targets.
None of this is an argument against offshore delivery, which runs some of the best-controlled operations in the world. It is an argument for screening delivery-centre roles by the value of the access they hold, not by salary band or location.
The Approach Is Now Part of the Attack
The Coinbase agents were recruited quietly. The other instructive case is one where the target talked.
In July 2025, BBC cyber correspondent Joe Tidy was contacted on Signal by someone claiming to represent the Medusa ransomware gang. The offer started at 15% of any ransom in exchange for access to BBC systems, then rose by another 10%, on the promise that the group could demand tens of millions.
When persuasion stalled, the gang flooded his phone with multi-factor authentication prompts, turning a negotiation into an intrusion. He reported the approach to the BBC’s security team, and the breach never happened.
Two details matter for employers.
First, the target was not a privileged administrator. He was a journalist whose login was simply a way in. Anyone with credentials is in scope.
Second, the approach was visible to the employee, and reporting it worked. That makes the approach itself a detection opportunity, and one that HR, not just security, is well placed to design around.
A Tolerance Problem, Not Just a Temptation Problem
It would be comforting to believe the insider market feeds only on desperate, underpaid junior staff. The attitudinal data says otherwise.
Cifas, the UK’s fraud prevention service, found that 13% of employees had sold company logins or knew someone who had in the past year, and 13% considered selling access justifiable. Tolerance rose with seniority: 32% of senior managers and 36% of directors called it justifiable, climbing to 43% among C-suite executives.
Mimecast’s research points the same way from the incident side. Malicious insider incidents now make up 42% of all insider events, level with negligence, and the share of organisations reporting rising malicious activity jumped from 35% in 2024 to 44% in 2026. It attributes the surge to financial pressure from layoffs and living costs, combined with cybercriminals industrialising recruitment.
The cost is not abstract. Ponemon’s 2026 study for DTEX put the average annual cost of insider risk at $19.5 million per organisation, with incidents taking 67 days on average to contain. Malicious incidents accounted for about $4.7 million of that total.
What a Background Check Can See, and What It Can’t
Here is where honesty matters, because screening firms are tempted to overclaim.
A pre-employment check answers a historical question: is this person who they say they are, with the history they claim? That question still matters enormously. Identity fraud, fabricated employment and undisclosed records remain real routes into sensitive roles, and a well-run check closes them.
But TrendAI makes the key point plainly. Workers rarely join a company intending to sell it out; they can be persuaded over time, as culture sours, finances tighten or dissatisfaction grows.
The person you verified was telling the truth. The problem arrives later, carried by an offer your process never sees.
That exposes three structural blind spots in most screening programmes.
The first is access drift. People are screened for the role they’re hired into, then promoted, transferred or granted new permissions without a fresh look. The support agent verified two years ago for a basic queue now sits in account recovery.
The second is the outsourced seat. Some of the most coveted access in a modern company sits with vendor staff screened to the vendor’s standard, on the vendor’s timelines, with the client rarely checking. Coinbase learned what that costs.
The third is silence. Most organisations have no clear, safe way for an employee to say, “Someone offered me money for my login.” Without one, the only people who know about the approach are the employee and the buyer.
None of these is solved by a better pre-hire check alone. All of them are, at least in part, screening and HR design problems.
Hiring Now Has a Second Recruiter
For decades, the hiring decision was treated as the moment of maximum risk. Get the right person through the door, and the job was done.
The insider market has changed that. Every employee with meaningful access now has, in effect, a second recruiter: one who never posts on LinkedIn, pays in crypto and offers remarkably flexible hours.
You can’t stop that recruiter from calling. What you can do is make your organisation an expensive, awkward place to buy from. Know which seats are worth buying. Verify the people in them when their access changes. Hold vendors to your standard. Make the approach something employees report rather than consider.
The companion playbook sets out how.







