Attack outcomes
Initial access broker
Also called: IAB
An initial access broker is a criminal who breaks into organizations and sells that access, such as working VPN or remote desktop credentials, to other attackers. Ransomware groups and data thieves buy it so they can skip the work of getting in. The broker's product is often a valid identity, not malware.
How it works
Brokers collect access through stolen credentials, password spraying, phishing and exploited remote access services, then confirm the login works and advertise it on criminal forums by company size and sector. A buyer pays and receives the credentials, and the ransomware attack that follows can come weeks later from a different group.
A real example
The FBI, CISA and MS-ISAC's Medusa ransomware advisory said Medusa actors typically recruit initial access brokers in cybercriminal forums and marketplaces to obtain initial access to potential victims.
Source: #StopRansomware: Medusa Ransomware (AA25-071A) — Cybersecurity and Infrastructure Security Agency (CISA), 2025-03-12
How to stop it
Require MFA on every VPN and remote access login, disable unused remote access accounts, and watch for valid logins from unexpected locations or infrastructure.
Related terms
Sources
- #StopRansomware: Medusa Ransomware (AA25-071A) — Cybersecurity and Infrastructure Security Agency (CISA), 2025-03-12
Last reviewed Oct 2, 2026