Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market.
That contradiction defines the identity threat economy entering 2026: billions of stolen credentials have made basic logins disposable, while verified footholds into large enterprises are being marketed as premium assets for ransomware, extortion and espionage operations.
Initial access brokers, or IABs, sell an established route into a victim environment rather than conduct the full intrusion themselves.
Yet the direction is materially significant: brokers increasingly advertised access to organizations with average claimed revenue of $3.242 billion, compared with $2.232 billion a year earlier.
The mainstream market remains inexpensive. Rapid7’s earlier 2025 dataset found nearly 40% of known-price listings between $500 and $1,000, while more than 70% included some degree of privilege.
Domain-user, local-administrator and domain-administrator access converts a simple credential compromise into a potential lateral-movement and ransomware staging point.
In the later dataset, Government accounted for 14.2% of observed offerings, followed by Retail at 13.1% and IT at 10.8%.
For defenders, those listings are not merely criminal advertisements; they are imperfect but useful demand signals for access paths, data sets and sectors attackers believe can be monetized.
Supply is eroding the value of ordinary identity data. KELA says it identified 2.86 billion compromised credentials in 2025, with business cloud and authentication services representing more than 30% of exposed data.
Infostealer malware collects saved passwords, browser data, authentication cookies and wallet artifacts in volume, then turns them into searchable logs.
Rapid7 Researchers said that, examination of five major underground forums found that the average base price for initial-access-broker listings rose from $2,726 in 2024 to $113,275 in the second half of 2025, a 4,055% increase.
Dark Web Corporate Access
A username-password pair is therefore weak evidence of identity, particularly when it is reused, exposed through a managed endpoint, or paired with a session artifact.
Session theft is especially important because it can sidestep the authentication ceremony altogether. A stolen cookie or token may allow an attacker to replay an already authenticated browser session without entering a password or responding to an MFA challenge.
The risk depends on application design, token lifetime, revocation controls and device or channel binding.
Organizations should treat anomalous token reuse, impossible travel after session establishment, new device fingerprints and sudden privilege changes as high-confidence signals worth correlating in their identity telemetry.
Market disruption also shapes the numbers. Rapid7 observed DarkForums and RAMP accounted for 81% of IAB sales threads in H2 2025, while activity fell on older venues including XSS and Exploit.
Law-enforcement pressure and forum migration can concentrate listings temporarily, inflate advertised prices and push transactions into private channels.
Pricing intelligence should therefore be trended with forum health, source coverage and observed sales evidence, rather than presented as a single deterministic risk metric.
Security teams should continuously hunt for exposed workforce and third-party credentials, enforce phishing-resistant MFA, reduce session duration, bind sessions where feasible, revoke tokens promptly after risk events, and test externally exposed VPN, remote-access, SaaS and administrative paths.
Dark-web price movements cannot predict an intrusion, but they can identify where adversaries are investing. In a credential-saturated market, resilient identity controls not passwords determine whether a stolen record becomes a corporate breach.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model. -> Register Now
Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market.
That contradiction defines the identity threat economy entering 2026: billions of stolen credentials have made basic logins disposable, while verified footholds into large enterprises are being marketed as premium assets for ransomware, extortion and espionage operations.
Initial access brokers, or IABs, sell an established route into a victim environment rather than conduct the full intrusion themselves.
Yet the direction is materially significant: brokers increasingly advertised access to organizations with average claimed revenue of $3.242 billion, compared with $2.232 billion a year earlier.
The mainstream market remains inexpensive. Rapid7’s earlier 2025 dataset found nearly 40% of known-price listings between $500 and $1,000, while more than 70% included some degree of privilege.
Domain-user, local-administrator and domain-administrator access converts a simple credential compromise into a potential lateral-movement and ransomware staging point.
In the later dataset, Government accounted for 14.2% of observed offerings, followed by Retail at 13.1% and IT at 10.8%.
For defenders, those listings are not merely criminal advertisements; they are imperfect but useful demand signals for access paths, data sets and sectors attackers believe can be monetized.
Supply is eroding the value of ordinary identity data. KELA says it identified 2.86 billion compromised credentials in 2025, with business cloud and authentication services representing more than 30% of exposed data.
Infostealer malware collects saved passwords, browser data, authentication cookies and wallet artifacts in volume, then turns them into searchable logs.
Rapid7 Researchers said that, examination of five major underground forums found that the average base price for initial-access-broker listings rose from $2,726 in 2024 to $113,275 in the second half of 2025, a 4,055% increase.
Dark Web Corporate Access
A username-password pair is therefore weak evidence of identity, particularly when it is reused, exposed through a managed endpoint, or paired with a session artifact.
Session theft is especially important because it can sidestep the authentication ceremony altogether. A stolen cookie or token may allow an attacker to replay an already authenticated browser session without entering a password or responding to an MFA challenge.
The risk depends on application design, token lifetime, revocation controls and device or channel binding.
Organizations should treat anomalous token reuse, impossible travel after session establishment, new device fingerprints and sudden privilege changes as high-confidence signals worth correlating in their identity telemetry.
Market disruption also shapes the numbers. Rapid7 observed DarkForums and RAMP accounted for 81% of IAB sales threads in H2 2025, while activity fell on older venues including XSS and Exploit.
Law-enforcement pressure and forum migration can concentrate listings temporarily, inflate advertised prices and push transactions into private channels.
Pricing intelligence should therefore be trended with forum health, source coverage and observed sales evidence, rather than presented as a single deterministic risk metric.
Security teams should continuously hunt for exposed workforce and third-party credentials, enforce phishing-resistant MFA, reduce session duration, bind sessions where feasible, revoke tokens promptly after risk events, and test externally exposed VPN, remote-access, SaaS and administrative paths.
Dark-web price movements cannot predict an intrusion, but they can identify where adversaries are investing. In a credential-saturated market, resilient identity controls not passwords determine whether a stolen record becomes a corporate breach.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model. -> Register Now
Click Here For The Original Source.
