Initial Access Broker
An Initial Access Broker is a type of cybercriminal who breaks into an organization's networks or systems and then sells that unauthorized access to other attackers rather than carrying out the full attack themselves. Buyers, such as ransomware groups, use this ready-made access to launch their own attacks more quickly. In this way, IABs act as a specialized supplier within the broader cybercrime economy.
An Initial Access Broker (IAB) is a threat actor specializing in obtaining unauthorized access to victim organizations' networks, systems, or infrastructure and monetizing that access by selling it to other cybercriminals, commonly including ransomware-as-a-service (RaaS) operators and data-theft actors. By separating the intrusion phase from downstream exploitation, IABs function as intermediaries in the cybercrime supply chain, providing pre-established access as a reusable building block that streamlines subsequent attacks. Reporting in the evidence indicates a shift by some IABs toward higher-value targets with correspondingly premium pricing, though this entry does not address specific pricing figures or volumes.
Why it matters
Initial Access Brokers matter because they lower the barrier to entry for damaging attacks. By specializing in the intrusion phase and selling ready-made access, IABs allow downstream actors such as ransomware-as-a-service operators and data-theft groups to move faster and skip the technical work of breaking in. This division of labor within the cybercrime supply chain means that a single compromise can be resold and weaponized by multiple, more capable attackers, increasing the likelihood that an initial foothold escalates into a full ransomware or extortion event.
For cyber insurance and resilience professionals, the IAB model reshapes how loss events unfold. An organization may be compromised well before any visible damage occurs, with the actual attack arriving only after access changes hands. This latency complicates incident timelines, forensic attribution, and questions about when a breach or occurrence began, which can be material to notice requirements, retentions, and coverage triggers depending on the specific policy wording. Reporting in the evidence also indicates that some IABs are shifting toward higher-value targets with premium pricing, suggesting that larger or more sensitive organizations may face more deliberate, resale-driven targeting.
Crucially, the existence of IABs underscores that insurance transfers financial consequences but does not reduce the likelihood of intrusion. Reducing exposure to IAB activity depends on risk mitigation and resilience measures rather than risk transfer alone. Whether losses stemming from an IAB-enabled attack are covered will depend on the applicable policy terms, endorsements, exclusions, and conditions, and cannot be assumed.
Who it's relevant to
Inside IAB
Common questions
Answers to the questions practitioners most commonly ask about IAB.
