Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is an initial-access broker?

An initial-access broker obtains a foothold and sells or transfers it to another operator. The person who creates access may not conduct the later ransomware, fraud or theft.

Separate acquisition, sale and use

Establish who obtained the access, method, privilege, persistence and time; what listing or communication offered; payment or transfer; and which account or session later used it. Credentials, remote access, cloud sessions or web shells may be sold, sometimes to several buyers.

Marketplace descriptions and screenshots show what was claimed, not what access actually existed. Confirm the advertised target and privilege using victim and provider records.

Test continuity after transfer

Access can expire, be revoked or change before purchase. Compare sale time with later authentication and activity to show whether the buyer used the offered foothold.

Matching method alone does not prove one continuous actor. Attribute broker, buyer and later operator from their own communication, financial, account and technical evidence.

Key takeaway

Reconstruct initial access as creation, claimed sale and later use, attributing the broker and downstream operator as separate roles.

Reference: CIM-247Cyber Incidents & Offender Methods