Cookie Consent by Free Privacy Policy Generator

Criminals recruiting insiders to bypass security controls

Research from Intel 471 reported by Help Net Security shows that cybercriminals are actively recruiting employees at specific organisations to provide insider access and services. The report highlights that legitimate employee access allows criminals to circumvent security controls that would be difficult or impossible to overcome from outside the organisation. Routine actions such as information lookups, account resets, password changes, transaction approvals, shipment modifications and data exports are being sold as services to criminal customers. Criminals are targeting employees at financial institutions, logistics companies, telecommunications providers, technology firms, healthcare organisations and government agencies, offering payment in exchange for access or specific actions performed using legitimate credentials and system access.

Why this matters for UK organisations

Insider threats are often harder to detect than external attacks because when an employee with legitimate access performs an action using their own credentials, it may appear entirely normal to monitoring systems, access logs and security controls. For UK businesses, this represents a shift in how organisations need to think about risk. It is no longer enough to focus solely on keeping attackers out through firewalls, endpoint protection and email filtering; organisations also need to understand who has access to what, whether that access is appropriate and proportionate, whether access is being used in expected ways, and whether unusual patterns of behaviour are being detected, investigated and reviewed. The recruitment of insiders is not a new phenomenon, but the scale and organisation of the market for insider services has grown significantly, driven by the difficulty criminals face in bypassing modern security controls from the outside. Criminals are now treating insider recruitment as a systematic business model rather than an opportunistic tactic.

What to review

For UK businesses, this is a reminder to review whether access controls, segregation of duties, monitoring and alerting are designed to detect misuse by legitimate users, not just external attackers. It is worth considering whether high-risk actions such as account changes, privilege escalations, transaction approvals, bulk data exports or changes to security settings are subject to dual authorisation, logging, review and alerting. Organisations should also consider whether HR, security, legal and senior leadership teams have a shared understanding of how insider risk is identified, investigated and managed, and whether there are clear processes for responding to concerns about employee behaviour, financial pressure, grievances or unusual access patterns. This is not about creating a culture of suspicion, but about ensuring that the controls, monitoring and governance structures are in place to detect and respond to misuse when it happens, regardless of whether it comes from inside or outside the organisation.

Source: Help Net Security

News and blog posts
Today's stories highlight three persistent challenges facing UK organisations:...
The US Cybersecurity and Infrastructure Security Agency has added a critical...
A critical vulnerability in Cisco Catalyst SD-WAN Manager is being actively...
Research from Intel 471 reported by Help Net Security shows that cybercriminals...