Are employees to blame for rise in insider access threats? This new study claims so
Flashpoint found ~34 insider threat posts daily on dark web between July 2025–26 July 2026 saw 12,653 posts, with 75% from insiders selling access themselves Report warns insiders are now the weakest link, urging external monitoring of illicit forums Every month, hundreds of people try to sell access to their employer’s IT infrastructure on the dark web.
Some do it for the money.
Others do it because they’re angry with their company for whatever reason.
As a result, malicious insiders are growing into one of the biggest, most dangerous threats for modern businesses, experts have warned.
This is according to cybersecurity professionals Flashpoint which published its latest monthly analysis of insider threat recruitment, illicit access advertising, and threat actor activity targeting enterprise environments.
Employees selling, hackers buying As per the report, between July 2025 and July 2026, there were an average of 34 unique posts on the dark web, every day, which can be classified as “insider threat posts”.
That is roughly a thousand unique posts every month.
In July this year alone, Flashpoint analysts identified a total of 12,653 insider posts, including both threat actors attempting to recruit insiders in target organizations, and insiders advertising their services.
Of these communications, 1,132 were unique posts.
“As perimeter security, EDR coverage, and other security tools mature, threat actors are finding it faster—and cheaper—to target the human element and simply buy an insider’s credentials or pay an employee to open the front door,” Flashpoint said.
“In a threat landscape where identity is becoming the primary attack surface, monitoring illicit marketplaces and recruitment efforts is critical.” Perhaps the best example is the 2025 Coinbase attack, when hackers bribed overseas customer support employees to provide access to customer data.
Coinbase said at the time that the insiders abused legitimate system access, causing a cyber-incident that ended up costing the company around $360 million .
Over the course of the year, the biggest targets were organizations in three industries: telecommunications, retail, and finance.
However, July 2026 findings “noticeably deviate from this trend”, Flashpoint said, finding that more than half (58.6%) of all posts affect other industries.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.