A survey rig measuring an entry port cuts a key that rests in a handover cradle between it and a separate buyer module, with an extraction press waiting further along.

Initial Access Broker (IAB)

An initial access broker, or IAB, is a criminal who breaks into organisations and sells that access to other attackers rather than using it. Ransomware crews are the main buyers. MITRE ATT&CK models the purchase as T1650 Acquire Access, under Resource Development, and states it cannot be easily mitigated by enterprise controls.

The term turns up in advisories, incident reviews and vendor reports, and it sounds like it should imply a new control to buy or a new alert to write. The interesting question is not what a broker is. It is whether there is anything here you can prevent, detect, or usefully budget for.

This page answers that first, because the answer determines everything else: what the framework actually models, why the transaction sits outside your visibility, what the circulating price figures really show once you check them, and where the defensive effort belongs instead.

A building with one measured door and a note plate carried off to a handover counter, while a separate hopper further along empties the same building.

Explain It Like I'm 10

Someone finds a way into a building. They do not steal anything. They write down which door works, how many rooms it opens, and how rich the company inside looks, then sell that information to whoever pays most. Weeks later, a different person walks in and empties the place. The one who found the way in and the one who did the damage are not the same person, and the second one never had to look for a door.

Initial Access Broker Quiz

Test your knowledge about Initial Access Broker - maybe you already know everything about it.

EasyQuestion 1 of 3

What does an initial access broker do?

A cradle holding a socket with its key seated and a delivery cartridge clipped alongside, beside a rack of three gauges reading differently.

What is actually being sold

A broker is not selling a technique. They are selling a working way into a specific organisation, described in the terms a buyer cares about.

MITRE's own description of the purchase says footholds "may take a variety of forms, such as access to planted backdoors (e.g., Web Shell) or established access via External Remote Services". In plain terms: a way in that persists, whether that is a shell on a web server or a legitimate remote-access route with credentials attached.

Two details in the framework's description matter more than the vector list the explainers on this term tend to publish.

  • What a buyer inherits is not always just a login. MITRE notes that "in some cases, access brokers will implant compromised systems with a 'load' that can be used to install additional malware for paying customers". The access can arrive pre-fitted with a delivery mechanism.
  • Your sector can make you worth more than your own data. Buying access to an organisation in "IT contracting, software development, or telecommunications" can open a path to that organisation's customers through a trusted relationship or a supply chain. If you serve other businesses, you are being priced on their behalf too.

Huntress, writing in July 2026, notes that listings "can include details like the victim's industry, country, revenue, and access type, all of which help shape the price". Read that from the defender's side rather than the market's: your revenue figure, your sector and the kind of remote access you expose are pricing inputs in a market you cannot see.

What makes one victim worth more than another

The framework is also explicit about this. Buying access lets an adversary "reduce the resources required to gain a foothold" and "focus their efforts on later stages of compromise", and buyers may prioritise "systems that have been determined to lack security monitoring or that have high privileges, or systems that belong to organizations in a particular sector". Your monitoring posture is not only a detection capability. It is a pricing input.

How the access was obtained in the first place is the subject of other pages. Phishing, credential theft, exposed remote services and identity attacks all feed this market, and each has its own detection story. This page is about what happens to the access afterwards.

An unwatched handover on open ground, and separately a raised plinth whose single intake tube carries the only instrument in the frame.

Can you detect an initial access broker?

Not the transaction. And the clearest statement of that comes from the framework itself.

ATT&CK models the buyer's side as T1650 Acquire Access, under Resource Development, on the PRE platform, which is where behaviour that happens outside the victim's estate is filed. The technique has no sub-techniques, and it was last modified on 24 October 2025.

Its mitigation is a single entry, `M1056 Pre-compromise`, and it reads: "This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls."

Its detection strategy, `DET0884`, carries one analytic, `AN2016`, and it says the same thing from the other direction: "Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."

Two things follow, and they are why this page exists.

First, there is nothing to catch at the moment your access changes hands. No log records the sale. The event that matters to the market happens on infrastructure you have no relationship with, between two parties who are not you.

Second, the framework is not shrugging. It names the stage where the effort belongs: initial access, the intrusion itself. That is a redirection, and it is more useful than the monitoring pitch most of the captured coverage ends on.

That also answers a purchasing question the field tends to leave hanging. A threat-intelligence subscription can tell you that something has been listed. It cannot make the transaction detectable, and it does not reduce the exposure that made the access sellable. Buy in that order.

In practice that means the detection work for this term is not new work. It is the intrusion detection you already run, valued differently: an alert at the access stage is worth more than its severity score suggests, because it may be the only moment anyone in your organisation is in a position to act.

There is also a briefing consequence worth having ready. If your organisation was compromised in one quarter and ransomware appeared in another, that is not necessarily a detection failure spanning months. It may be two different actors and a transaction in between.

Three identical dials reading differently above a rail of mostly short capsule columns with a few very tall ones tipping a balance beam.

How much does access actually sell for?

Three price claims circulate on the first page of results for this term, and they do not agree. Tracing them teaches more than any of the numbers.

Figure in circulation

Where it comes from

What year it describes

Collection basis

"Average $5,400, median $1,000"

Wikipedia, which ranks first on both major engines, written in the present tense

2020

Cited to a vendor post from 2 August 2021; the article's references were last retrieved in early 2024

"$500 to $2,000, occasionally over $10,000"

Cyberint, September 2024 - the source Google's AI Overview cites for pricing

2023 to 2024

One vendor's collection of listings; no sampling method published

"Average $3,066 falling to $1,295"

The same Cyberint dataset

2023, then 2024

As above

The third row is the one that matters, because it points the opposite way to the figure in wide circulation. Cyberint reports that the average listing price was "$3,066" in 2023 with a median of "$1,500", and that in 2024 "the average price has dropped significantly to $1,295, which is an approximately 60% decrease" - while brokers moved upmarket toward higher-revenue targets.

The most-quoted number for network access describes the market as it stood in 2020, and the page serving it ranks first on both major engines and writes it in the present tense.

Distribution before average, every time

The same source makes the statistical point itself, which is rarer than it should be. In 2023, "65% of listings ... were priced under $2,000, and 77% were under $3,000", and the report says plainly that "the higher average price is skewed by these high value listings". By 2024 "the vast majority of listings are now priced under $1,000", with high-value access down to 9% of what was available.

So the average was never describing a typical sale. It was describing a long tail. That is the transferable move here: when a market number appears in a report, ask for the distribution before you repeat the mean, and ask which year the collection covers.

One caveat belongs with all three rows. These are vendor collections from venues each vendor chose to watch. They describe what those collections saw, which is not the same as what the market did.

A key handed between two differently built modules at one end of a long rail, a calendar drum along the empty middle, and an extraction press working at the far end.

Why the attack arrives months after the break-in

The gap between the break-in and the ransomware is the part that confuses incident timelines, and a 2026 SOC account puts it plainly. Huntress describes the pattern: an intrusion in one year, a sale, and a different actor arriving months later, which means "it's really hard to definitively point to activity that initially stemmed from an IAB selling the access".

The same piece states the defensive consequence: "By the time follow-on activity appears, the original break-in may be weeks or months old, and the attacker in the environment may not be the one who first got in." And then the sentence that matters most for a SOC: "Even when attribution is murky, those first signs of compromise can still give defenders a chance to interrupt what comes next."

The triage consequence

That is one behavioural change, and it is the only one this page is really asking for. An unremarkable alert at the access stage - a brute-force attempt against exposed remote access, a credential used from an odd location - may not be the attack. It may be the inventory being taken. Triaging those alerts as low-value noise is how an organisation ends up reading about itself months later.

It also explains why dwell time on a ransomware incident is a strange thing to reason about: the clock may have started with someone who never intended to do anything but sell.

A central press with three supplier modules seated in its intake ports and a return manifold sending capsules back to each.

Who buys, and what a government advisory records

The demand side is documented, not inferred.

ATT&CK's procedure examples for T1650 include a named ransomware group that "has purchased user credentials and other sensitive data from Initial Access Brokers (IABs)".

More recent, and more specific: on 10 August 2026, CISA, the FBI, DC3, the NSA, the US Secret Service and the Republic of Korea's National Police Agency published a joint advisory recording that one ransomware operation "has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access". That advisory was nine days old when this page was written, and it does not appear on the first page of results for this term.

Specialisation with a payroll

The labour market behind it is documented too. The CIS Center for Internet Security, writing as the MS-ISAC threat intelligence team, records that one ransomware gang "hired 'Coders,' 'Testers,' 'Penetration Testers,' and other personnel", with departments given their own budgets. This is division of labour with a payroll, which is worth understanding precisely because it is unremarkable rather than impressive.

What the buyer does next belongs to another page: encryption, data theft, and pressure applied through a leak site. Worth one note here, though, because it changes what access is worth: extortion has been drifting away from encryption toward theft alone, which raises the value of quiet, durable access over noisy access.

Two handover rigs of identical design, one visibly aged and one factory fresh, both working at the same rate.

This is not new

The framework's own reference list for T1650 includes a report from October 2012, titled "Service Sells Access to Fortune 500 Firms", alongside 2022 research on access brokers and a Microsoft report describing ransomware as a service as a criminal gig economy.

The model is nearly fourteen years old. Any page that presents brokers as an emerging development is describing its own reading list rather than the threat.

A machine whose exposed rail is being retracted and its ports capped, with a two-stage latch closed over the one remaining opening.

What to actually do about initial access brokers

Start from the uncomfortable framing: the broker's product is your exposed edge and your credential hygiene, priced by somebody else. That is why the control list looks so unglamorous. There is no broker-specific control, because there is no broker-specific weakness - only yours, valued by a stranger.

CIS, writing for state, local, tribal and territorial organisations, sets out the work: reduce the attack surface, run vulnerability management with a patching cadence fast enough to close the flaws brokers exploit, harden remote access with credential lockout policies, use multi-factor authentication, apply access controls and least privilege, and test the result periodically.

Two additions are worth making explicit.

  • The credential path is half the market. Infostealer-harvested credentials are a standing input to broker inventories, so credential exposure monitoring and rotation are exposure work rather than broker-watching.
  • There is a free option that no vendor page mentions. The same CIS guidance points to CISA's Cyber Hygiene Services, which are available at no cost to SLTT organisations and will "proactively scan your networks, figure out where you're vulnerable". Note the eligibility scope before assuming it applies to you.

If a budget question follows from all this, the order is straightforward: buy exposure reduction before you buy visibility into a market you cannot influence.

An empty three-bay measurement rack beside a single sealed ledger drum whose narrow slit shows only part of the rail behind it.

What we do not know

There is no independent measure of this market. Every count of brokers, listings or prices located for this article is one organisation's collection from venues it chose to watch, with no external register and no verification step. The sibling problem, and the longer version of that argument, belongs to the leak-site side of this ecosystem.

Attribution to a broker is rarely provable after the fact, as the SOC account above makes clear, and nothing in the framework's detection guidance suggests otherwise. Incident reports that assert a broker origin are usually inferring one from timing and tradecraft.

And this page has a deliberate boundary: it names no marketplace, reproduces no listing, and explains no monitoring mechanics. Naming the venues would help the wrong readers and change nothing for the right ones.

A rotary drum with five sockets around its face, each holding a seated plug fed by its own short tube.

Frequently asked questions

Is an initial access broker the same as a ransomware group? No. A broker's product is the way in; a ransomware crew's product is the extortion. They are different roles in the same supply chain, and the relationship can be commercial - a government advisory records one ransomware operation recruiting brokers and paying them a share of proceeds.

Can threat intelligence tell me if my access is for sale? Sometimes it can tell you something has been listed. It cannot make the sale itself detectable, because the transaction happens outside your estate, and it does not reduce the exposure that made the access sellable in the first place. Treat it as a supplement to exposure work, never a substitute.

Why do price figures differ so much between reports? Different collections, different years and different definitions. One widely repeated figure describes 2020 and is published in the present tense; the dataset most often cited for pricing shows averages falling through 2024. Always check which year a figure describes before repeating it.

Does buying access mean the attacker is unskilled? It means they chose not to spend time on entry. The framework's own reasoning is that buying access lets an adversary "focus their efforts on later stages of compromise". Speed and specialisation are the point, and treating it as a skill question misreads the model.

If we find an old compromise, does that mean our access was sold? Not provably. The useful response is identical either way: work out what the access reached, assume it may have been shared or resold, and close the path rather than the incident.

Four stations on one bench: a retracting boom, a credential latch, a cradle lifting one small capsule under a lens, and a plate held against a reference block.

What to check this week

Four moves, in order, each drawn from the sources above.

  1. Inventory and shrink the internet-facing edge. Remote access services and web-facing applications are the product being sold; anything you retire cannot be listed.
  2. Close the credential path. Multi-factor authentication, lockout policies, and rotation when credentials appear in exposure data. Brokered access frequently starts with a working login.
  3. Re-triage early-stage intrusion alerts. Treat a small access-stage alert as potentially the opening move of an operation that will be finished by somebody else, weeks later.
  4. Check any market number before it reaches a slide. Which year does it describe, who collected it, and is it a mean hiding a long tail?

You cannot reach this market, negotiate with it, or take it down from your side. What you can do is make the thing it sells less worth buying, and make sure that when somebody does buy it, the first thing they touch sets something off.