How Initial Access Brokers Sell Corporate Network Access | Sinon Security
Initial access brokers auction VPN, RDP and domain admin access to ransomware crews. See how IAB listings work, what they cost in 2026, and how to detect exposure early.

Most ransomware attacks no longer begin with a ransomware operator. They begin with a middleman who broke in weeks earlier, verified the access, priced it, and sold it to the highest bidder. These middlemen are initial access brokers, and understanding how they package and sell corporate network access is one of the highest-leverage things a security team can do in 2026.
What an initial access broker actually sells
An initial access broker (IAB) is a specialist. They do not deploy ransomware, exfiltrate data, or run extortion negotiations. They compromise organisations, establish a reliable foothold, and resell that foothold on underground forums to ransomware affiliates and data-theft crews who prefer to buy their entry point rather than earn it.
The product on offer is usually one of a handful of access types:
Corporate VPN accounts, often harvested from infostealer logs or unpatched VPN appliances.
Exposed or brute-forced RDP sessions on internet-facing hosts.
Domain administrator or Active Directory access, the premium tier.
Cloud and SaaS console credentials, including identity provider and SSO logins.
Web shells and command-and-control footholds on compromised servers.

Underlying stages derived from Rapid7, ZeroFox and Flare reporting, 2025–2026.
Anatomy of an access listing
IAB listings read like classified ads, and they are deliberately vague. Brokers rarely name the victim, because naming it invites law enforcement attention and lets threat intelligence teams warn the target. Instead, a listing profiles the company well enough for buyers to calculate expected ransom payout: country, industry vertical, annual revenue, employee or endpoint count, security stack in place, and the level of access obtained.
Pricing follows an auction convention borrowed from Russian-language forums. Sellers post three figures: a "start" opening bid, a "step" increment, and a "blitz" buy-it-now price that ends the auction immediately. High-value listings with domain admin rights and confirmed EDR evasion sell privately in Telegram channels rather than publicly, precisely because the buyer pool is small and the sellers are known.
Where the market operates and what it costs in 2026
Exploit and XSS remain the technically credible Russian-language venues, while RAMP has consolidated as a convergence point for ransomware affiliates and brokers. DarkForums emerged as the English-language on-ramp after repeated BreachForums takedowns, absorbing lower-tier credential and stealer-log resale.
Two data points define the current market. Rapid7 measured an average IAB listing price of roughly USD 2,700 across 2024, with about 71 percent of deals offering privileged access. Its H2 2025 update measured an average base price of approximately USD 113,275, a jump driven by forum reshuffling after the BreachForums collapse and the arrest of the XSS administrator. Volume moved the other way: ZeroFox observed roughly 370 network access listings in Q1 2026, down from around 620 in Q1 2025.
That combination matters. Fewer listings at far higher prices does not mean less ransomware. It means the trade has moved into private, vetted channels, and that brokers are curating for quality rather than volume. Chainalysis tracked at least USD 14 million in on-chain payments to initial access brokers across 2025, against roughly USD 820 million in total ransomware payments, which tells you how cheap the entry ticket remains relative to the payout.
How brokers get in, and why your perimeter did not stop them
The dominant vectors are unglamorous. Infostealer malware on an employee or contractor endpoint delivers valid credentials and, critically, live session cookies that replay past multi-factor authentication. Unpatched edge devices give brokers pre-authentication footholds. MFA fatigue and adversary-in-the-middle phishing kits handle the rest.
Verizon’s 2025 Data Breach Investigations Report found that 54 percent of ransomware victims had domain credentials present in infostealer logs before the incident. The perimeter was not breached in the traditional sense. Someone logged in.
Closing the window
The exploitable gap is time. Credentials typically move from theft to underground listing within about 48 hours, and ransomware affiliates have been observed weaponising purchased access within 48 hours of a listing going live. Organisations without dark web monitoring usually learn about the sale only after encryption begins, at which point the broker is long gone and the buyer already has persistence.
Practical controls that shrink that window:
Continuously monitor dark web forums, Telegram channels and stealer-log markets for your domains, VPN hostnames and executive identities.
Extend that monitoring to key suppliers and managed service providers, who are frequently the listed access.
Enforce phishing-resistant MFA and, just as importantly, revoke sessions on credential exposure — a password reset alone does not kill a stolen cookie.
Reduce internet-facing RDP to zero and patch VPN and edge appliances on an emergency cadence.
Alert on the behaviours that follow a purchase: impossible-travel logins, new MFA device enrolment, and privilege escalation outside change windows.
The takeaway
Initial access brokers have turned intrusion into a wholesale commodity, and they operate on a clock your incident response team never sees. Visibility into that marketplace converts an unavoidable surprise into a manageable, dated warning.
Sinon Security provides continuous dark web and initial access broker monitoring, so you find out your access is for sale while it is still a listing and not yet a ransom note. Talk to our team about an exposure assessment for your organisation and its supply chain.