Stronger Security Drives Ransomware Groups to Recruit From Within

Malicious Insiders Are Becoming a Growing Threat to Corporate Security

A disturbing trend is emerging in the world of cybersecurity: malicious insiders are increasingly helping ransomware groups gain access to corporate networks, resulting in devastating financial losses and reputational damage. According to recent research, insider threats are on the rise, with 56% of incidents attributed to negligent insiders who fall victim to phishing attacks or lose company devices. However, it’s the malicious insiders with elevated privileges who pose the greatest threat, costing organizations an average of $4.9 million per event.

The annual cost of insider threats has hit a staggering $19.5 million per organization in 2026, according to SentinelOne. While negligent insiders remain more common, the growing threat from malicious actors makes it essential for companies to address both types of threats. Disgruntled employees have historically accounted for many malicious inside threat scenarios, with some even selling their access to corporate data and network points on the Dark Web.

The recruitment trends observed across the Dark Web in July indicate that over 75% of unique threat actor posts came from insiders advertising their access to malicious third parties. This highly motivated threat landscape has disgruntled employees seeking out buyers for corporate data and network points, making it a challenging problem for companies to tackle. A case study by Huntress found that some ransomware groups are even bribing telecom employees to facilitate SIM swapping attacks against targeted users.

Justin Miller, a retired senior special agent with the US Secret Service, worked a case where a main IT director deployed malware after being fired, highlighting the need for companies to take insider threats seriously. “You don’t want to piss off the guy who’s in charge of your network,” Miller warns. “There’s always an insider who gets upset about things.” Companies must assume that they sit lower on the high-value target list and review their defenses accordingly.

Jamie Levy, senior director of adversary tactics at Huntress, emphasizes that even if companies think they have the best possible defenses, the vulnerability could be someone on the inside working with the ransomware actors. “We see a lot of that stuff too, where there’s a plant or the ransomware actors are like: ‘Hey, we’ll pay you to give us access’,” Levy explains.

To mitigate this growing threat, companies must take a proactive approach to insider threats. This includes implementing robust security protocols, conducting regular training and awareness programs for employees, and monitoring network activity for suspicious behavior. Additionally, companies should review their policies and procedures to prevent disgruntled employees from causing harm. By taking these steps, organizations can reduce the risk of insider threats and protect themselves against the devastating financial losses that come with them.

Practical takeaway: Companies should prioritize insider threat mitigation by implementing robust security protocols, conducting regular training and awareness programs for employees, and monitoring network activity for suspicious behavior. This will help reduce the risk of insider threats and prevent the devastating financial losses that come with them.


Source: Dark Reading — 2026-09-01