When people picture a cyberattack, they usually imagine a single dramatic moment: a phishing email clicked, ransomware exploding across the network, a demand for payment appearing on screen.
The reality is often slower, quieter, and more businesslike than that. Increasingly, the criminal who breaks into your systems isn't the one who attacks you. They break in, establish a quiet foothold, and then sell that access to someone else — often a ransomware gang — who does the real damage weeks or months later.
The people who specialise in this are called Initial Access Brokers, and they've become one of the most important and least understood links in the modern-day cybercrime chain. Here's what they are, how they operate, and what it means for your business.
An Initial Access Broker (IAB) is a cybercriminal whose entire job is to gain access to networks and then sell that access to others.
They're the middlemen of the cybercrime economy. An IAB breaks into a company's systems, quietly establishes a way back in, and then advertises that access for sale on dark web forums and marketplaces — often with a helpful "product listing" describing the victim: the company's size, industry, revenue and the level of access on offer.
A ransomware group browses, buys, and walks straight in through a door that's already been propped open.
Think of them as the people who pick your locks and sell the keys — without ever robbing the house themselves.
This "access-as-a-service" model has quietly transformed cybercrime, and not in your favour. Here's why.
It makes attacks faster and more frequent. Ransomware gangs used to do everything themselves — find a target, break in, establish a foothold, escalate, and only then deploy their attack. That took weeks or months of skilled effort. By simply buying ready-made access, they skip all of that and get straight to the damage. More attacks, launched faster, by more people.
It lowers the skill barrier. An attacker no longer needs to be capable of breaching a network to run a ransomware campaign; they just need to be able to buy access. That widens the pool of people who can hurt your business.
The break-in and the attack are separated in time. This is the part that catches businesses out. An IAB might compromise your network today and sell that access three months later. By the time the ransomware hits, the original break-in is long past, which means a quiet intrusion you never noticed can turn into a crisis much later, and is inevitably much harder to trace.
IABs rely on the usual suspects that account for the majority of cybersecurity breaches. The most common weaknesses include:
The good news here is that all of these can be defended against with relative ease, as the risks are well understood and the methods to combat them are achievable for most organisations with the right tooling and practices. With IABs, businesses aren't facing any entirely new infiltration methods; therefore, this underscores the importance of patching regularly, keeping credentials secure, and investing time and resources in user awareness training to combat the latest phishing and social engineering techniques.
There's a comforting myth that this is a big-company problem. It isn't, and it's important that both smaller and medium-sized enterprises (SMEs) realise this before it's too late.
For years, cybercriminals focused on large corporations. But the access-as-a-service model has drastically changed the landscape.
When breaking in is cheap and can be sold on for profit, every business becomes a viable target. Smaller organisations, which often have leaner security and stretched or non-existent in-house IT, are frequently the easier door to open.
To an IAB scanning for exposed RDP (Remote Desktop Protocol) or reused passwords, a 60-person midlands manufacturer is just as lucrative as a multinational corporation — sometimes more so, because the defences are thinner.
If your business sits in the supply chain of larger customers, you're doubly exposed: you may be targeted not just for your own data but also as a stepping stone to a bigger fish.
The reassuring part is that, because IABs rely on common, well-understood weaknesses, the defences are the same fundamentals that protect against most cyber threats. Do these well, and you close the doors they rely on.
Check out our cybersecurity services pages for more information on how you can defend your business against prevalent threats such as IABs and cybercriminals. Or if you're looking for a managed service provider (MSP) who will protect you from these malicious brokers, check out what we have to offer on our Fully Managed IT Support pages.
Initial Access Brokers are a reminder that cybercrime has become an organised, specialised industry — one where breaking into your business and profiting from it can be two entirely separate transactions. It sounds unsettling, and the trend is real. But the defences aren't exotic: strong authentication, controlled remote access, prompt patching, and continuous monitoring close the doors IABs depend on.
The businesses most at risk aren't the ones with the most valuable data — they're the ones with the easiest doors to open. Making sure yours aren't is exactly the kind of quiet, proactive work that stops a problem you'd never otherwise have seen coming.
You can't defend against a door you don't know is open. At Netitude, we help businesses across Somerset, Bristol, and the Southwest close the gaps that attackers rely on — from MFA and patching to continuous monitoring and response. Book a meeting with our Managing Director, or book in a Net9 audit to see where you stand against threats such as IABs.
What is an Initial Access Broker? An Initial Access Broker (IAB) is a cybercriminal who specialises in breaking into organisations' networks and then selling that access to other criminals — most often ransomware groups — rather than carrying out the attack themselves.
How do Initial Access Brokers get into networks? Most commonly through stolen credentials, poorly secured remote access (such as exposed RDP or VPNs without MFA), unpatched software vulnerabilities, and phishing. These are everyday weaknesses rather than sophisticated techniques.
Why are IABs a threat to small businesses? The "access-as-a-service" model makes every business a viable target, not just large corporations. SMEs often have leaner security and limited in-house IT, making them easier to breach — and if they supply larger customers, they can be targeted as a stepping stone.
How can I protect my business from Initial Access Brokers? Focus on the fundamentals: enforce multi-factor authentication everywhere, secure or disable exposed remote access, patch promptly, monitor continuously to catch quiet intrusions early, train staff to spot phishing attempts, and maintain an incident response plan.
What's the link between IABs and ransomware? IABs supply the "way in" that ransomware gangs need. By buying ready-made access, ransomware operators skip the hardest part of an attack and move straight to deploying their payload, which makes attacks faster and more frequent.