メインコンテンツにスキップ
Join Us at our First In-Person User Conference.Register for our Dallas event today

2026年8月26日

When Someone Buys Your Employee, Not Your Password

Attackers are recruiting the people who already have access, and no credential control stops a login that is genuinely authorized

Ransomware crews and data-theft groups have added a line item to the budget: your employees. Posts on criminal forums openly offer a cut of the payout to insiders who will hand over access, run a command, or approve an MFA prompt. Why phish your way in when you can pay someone who already holds the keys.

This breaks the model most defenses assume. There is no stolen credential, no brute-forced password, no external intrusion to detect. The login is the employee's. The MFA approval is real. Every authentication control confirms exactly what the attacker wants confirmed, that an authorized user is doing authorized things.

Authorized Doesn't Mean Expected

A recruited insider still has to act, and the actions serve someone else's goal. Access jumps to systems outside their role, data gets pulled at volumes their job never required, activity lands at hours that do not fit their history. The authorization is legitimate. The behavior is foreign to the person.

Baseline the Person, Catch the Deviation

The recruited insider already belongs here: real employee, real history, real access, now pointed at someone else's goal. That is what separates this from a planted operative. No authentication control speaks to that distinction. Behavior does. Abnormal's Insider Threat protection is built around exactly this gap.

You cannot reset a password an attacker never stole. You can notice when a trusted account starts working for someone else.

See the latest from Abnormal's product and engineering teams.

進化し続けるメールの脅威から守る

行動分析AIが、従来の防御をすり抜ける攻撃をどのように検知するかをご覧ください。