Skip to content

News with true faith

Economy

Cybercriminals Offer Workers $25,000 to Betray Companies

Organized cybercrime groups are recruiting corporate employees with signing bonuses of up to $25,000 to bypass security defenses from within.

Cybercriminals Offer Workers $25,000 to Betray Companies

Organized cybercrime groups are actively recruiting corporate employees with privileged system access to facilitate insider attacks, offering signing bonuses of up to $25,000, according to new research published by TrendAI, the enterprise business unit of cybersecurity firm Trend Micro.

The investigation warns that cybercriminals have discovered it is often more effective and profitable to purchase employee loyalty than to breach corporate network perimeters directly. Rather than breaking through security defenses, criminal groups are targeting staff who already hold legitimate credentials within targeted organizations.

La Región de Murcia es la CCAA en donde más crece la ciberdelincuencia en 2022 respecto a 2019, con un aumento del 163%
File photo of a worker in front of her computer Unsplash - Marek Levak La Razón

The practice of recruiting corporate staff has rapidly professionalized across subterranean cybercrime forums. Attackers are using structured incentives to lure staff into betraying their employers, treating access rights as commercial assets.

Financial Incentives for Corporate Insiders

To attract workers capable of manipulating critical operations, cybercriminals are offering signing bonuses alongside performance incentives. In addition to upfront payments of up to $25,000, recruitment schemes feature referral rewards for introducing colleagues with similar access levels, profit sharing agreements on stolen funds, and third party escrow services to guarantee transactions between hackers and internal accomplices.

An escrow service functions as an independent intermediary that holds funds until specific contractual conditions are satisfied. Cybercrime networks use these services to reassure insider recruits that their promised payouts will be delivered once an attack is facilitated.

David Sancho, a senior threat researcher at TrendAI, said that organizations have spent years focusing attention on perimeter protection. Sancho noted that cybercriminals themselves are demonstrating that the most efficient route into a company does not always involve breaking defenses, but convincing someone who already works inside. He added that the industry is witnessing the professionalization of an illicit market that converts corporate trust into a tradeable commodity.

Targeted Positions and High Risk Sectors

According to the TrendAI study, the most vulnerable element in corporate defense is no longer a misconfigured server, but an employee possessing legitimate access to internal systems. Advanced technical expertise is not required for recruits, as attackers prioritize strategic access over computer skills.

Cybercrime groups are actively searching for managers authorized to approve payments, personnel with access to account recovery systems, shipping operators who can alter delivery statuses, and workers empowered to validate transactions that an external attacker could not easily execute. Criminal groups also target employees who can modify internal processes, access confidential data, or grant direct network entries.

Sancho highlighted that the primary objective for cybercriminals has shifted from merely infiltrating corporate networks to directly controlling critical business processes from the inside.

The report identifies several key sectors targeted by recruitment campaigns, including financial institutions, telecommunications providers, digital platforms, logistics providers, government agencies, healthcare organizations, and major retail chains. Tactics vary by industry, ranging from fraudulent SIM card swaps and tracking system manipulation to unauthorized refund approvals, access to patient medical records, and the sale of ready to use privileged credentials.

In telecommunications, SIM card swapping occurs when criminal actors convince service providers to transfer a target's mobile number onto a new subscriber identity module card, allowing attackers to intercept two factor authentication codes and breach secure accounts.

Rethinking Corporate Cybersecurity Strategy

The emergence of organized insider recruitment forces businesses to re-evaluate traditional security frameworks. Corporate cybersecurity has historically relied on perimeter defenses such as firewalls, antivirus software, and multi factor authentication built on the assumption that external threats pose the primary danger.

The study emphasizes that insider risk can no longer be viewed strictly as a technical glitch or an isolated human resources concern. Instead, insider collaboration represents an enterprise risk that directly threatens the core operational trust of an organization.

Sancho stated that companies must complement traditional cybersecurity measures with tighter controls over critical internal processes. He concluded that organizations must implement targeted awareness programs to inform employees that they are actively being targeted by criminal recruitment campaigns.

Related

Leave a comment

Your email address will not be published. Required fields are marked *