A recent report from cybersecurity firm Flashpoint highlights a worrying increase in insider threats, driven by employees selling access to corporate IT systems on the dark web. Between July 2025 and July 2026, insider threat posts averaged 34 daily, signaling a growing risk from within organizations.

  • Over 12,000 insider threat posts identified in July 2026 alone
  • Employees account for 75% of posts advertising illicit access
  • Telecommunications, retail, and finance are historically top targeted sectors

What happened

Cybersecurity specialists at Flashpoint published monthly data revealing that each day between July 2025 and July 2026 included an average of 34 distinct dark web postings related to insider threats. These posts featured both criminal attempts to recruit insiders and insiders advertising unauthorized access to their employers' systems.

In just one month, July 2026, analysts documented over 12,600 such posts, with insiders responsible for approximately 75% of unique posts offering illicit credentials or access. This insider activity demonstrates high motivation among employees to monetize or weaponize their legitimate access, often driven by monetary gain or dissatisfaction with their company.

Why it matters

The findings underscore a significant shift in attack tactics as cybercriminals increasingly exploit trusted insiders instead of attacking hardened cybersecurity defenses. While advanced perimeter and endpoint security systems continue to improve, employees remain a vulnerable entry point, rendering traditional detection methods less effective.

Because insider threats rely on valid credentials and authorized access, organizations often discover malicious activity only after damage such as data theft or sabotage has occurred. These challenges highlight the urgent need for enterprises to rethink defense strategies that go beyond technical barriers and include monitoring of external marketplaces where insider access is bought and sold.

What to watch next

Companies should prioritize enhancing threat intelligence capabilities focusing on dark web surveillance, encrypted communication platforms, and invite-only cybercriminal forums to identify early signs of insider recruitment and access sales. This proactive stance can help identify compromised insiders before major breaches unfold.

Industries that have been frequent targets, notably telecommunications, retail, and finance, need to remain vigilant, although recent data shows that over half of insider threat posts now involve a broader range of sectors. Monitoring supply chain vulnerabilities connected to insider access will also be critical as attackers seek alternative entry points into enterprise networks.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings