Insider threats surge as employees sell corporate access on dark web, Flashpoint finds
A Flashpoint report reveals over 12,000 insider threat posts on the dark web in July 2026, with 75% from insiders selling access, highlighting employees as the weakest link.
In July 2026 alone, Flashpoint identified 12,653 insider threat posts, of which 1,132 were unique. More than 75% of these unique posts came from insiders advertising their own access for sale, indicating a highly motivated internal threat landscape where disgruntled employees actively seek buyers for corporate data and network entry points.
Over the year, the biggest targets were organizations in telecommunications, retail, and finance. However, July 2026 findings noticeably deviate from this trend, with more than half (58.6%) of all posts affecting other industries. Flashpoint noted this could be a way for threat actors to find an alternative entry point into target networks, essentially preparing for supply-chain attacks.
Flashpoint cited the 2025 Coinbase attack as a prime example. Hackers bribed overseas customer support employees to provide access to customer data, causing a cyber-incident that cost the company around $360 million.
The report explains that as perimeter security, EDR coverage, and other security tools mature, threat actors find it faster and cheaper to target the human element and simply buy an insider's credentials or pay an employee to open the front door. Insider threats are inherently difficult to detect using internal security controls alone because the malicious activity relies on valid credentials and legitimate access privileges. Relying solely on internal logs means security teams often only detect an insider threat after data exfiltration or system sabotage has already occurred.
To combat this, Flashpoint advises organizations to monitor deep and dark web forums, invite-only threat communities, and encrypted chat platforms to spot when someone is trying to buy or sell access to their IT infrastructure. They should also keep an eye on infostealer activity, compromised corporate credentials, and active session tokens, and deploy third-party cybersecurity intelligence that equips teams with adversary TTPs.