Ransomware crews and data-theft groups have added a line item to the budget: your employees. Posts on criminal forums openly offer a cut of the payout to insiders who will hand over access, run a command, or approve an MFA prompt. Why phish your way in when you can pay someone who already holds the keys.
This breaks the model most defenses assume. There is no stolen credential, no brute-forced password, no external intrusion to detect. The login is the employee's. The MFA approval is real. Every authentication control confirms exactly what the attacker wants confirmed, that an authorized user is doing authorized things.
Authorized Doesn't Mean Expected
A recruited insider still has to act, and the actions serve someone else's goal. Access jumps to systems outside their role, data gets pulled at volumes their job never required, activity lands at hours that do not fit their history. The authorization is legitimate. The behavior is foreign to the person.
Baseline the Person, Catch the Deviation
The recruited insider already belongs here: real employee, real history, real access, now pointed at someone else's goal. That is what separates this from a planted operative. No authentication control speaks to that distinction. Behavior does. Abnormal's Insider Threat protection is built around exactly this gap.
You cannot reset a password an attacker never stole. You can notice when a trusted account starts working for someone else.
See the latest from Abnormal's product and engineering teams.

