Back to blog
Threat Intelligence Aug 31, 2026

Your Network Was Already On Sale

We analyzed 28,634 ransomware victims and the forum listings that supply their attackers. Access into a $3B company sold for $10,000. A hospital went for $240. The market is public, priced, and in our data controlled by a handful of sellers, and defenders are watching the wrong end of it.

Walless Al Essa Adem El Adeb
Your Network Was Already On Sale
Share Article: Copied!

By the VULONE threat intelligence team

We analyzed 28,634 ransomware victims and the forum listings that supply their attackers. The access market is public, it is priced, and in our data it sits in a surprisingly small number of hands.

A VULONE listing card for the access broker el84, offering VPN logins into an .il telecom for $500, surrounded by other access listings priced from $240 to $2,500. One listing among thousands. el84 offered VPN access into an Israeli telecom for $500. The buyer needs a client and a password. The rest is labor.

Every incident report tells the same story. Attackers breached a perimeter, moved laterally, encrypted the crown jewels, and then a name appeared on a leak site. The timeline always starts with the intrusion.

But in a meaningful share of intrusions, the attacker did not guess a password or burn a fresh zero-day. They had help. Access that was advertised, often weeks earlier, on cybercrime forums, and bought by someone who put it to work. The industry calls it initial access. The forums just call it a listing.

When we work through the forums we monitor as part of day-to-day threat tracking, we keep running into that upstream stage, the part that never makes it into incident reports. The listing. Someone offering access into a hospital. A bank. A defense contractor. Sometimes a government. Priced in dollars, with guarantees, in plain sight.

The market that feeds ransomware is not hidden. It is public. And it is largely invisible to the teams responsible for defending the networks being sold.

Here is what we found.

A market that works like a market

The first thing that strikes you is how professional it all is. These are not basement posts. They read like a sales channel.

Consider what one seller, using the handle el84, offered:

"[SELL] VPN Logins of telecommunication .il CORP. i'm selling logins for a private Virtual Private Network in an .il enterprise. initial price: $500 USD. External VPN, you can access with a client. more info only in contact."

Five hundred dollars for a foothold into a telecom operator. The buyer just needs a VPN client and a password, and then the real work begins.

The el84 profile inside VULONE, showing 143 recovered posts, 252 private messages, a riseup.net email, and the SELL thread for the .il telecom VPN. The el84 profile as we hold it: recovered posts, private messages, registration and last-known IPs, and the thread itself. This is the difference between watching the leak site and watching the seller.

Another seller, boxi, was running what amounts to a wholesale operation:

"I have access to thousands of VNC and SSH boxes. They mainly comprise of Linux and Windows but I also have Android, Apple and other, more obscure OS's, such as BSD, Home Assistants, PfSense firewalls and others. I also have VNC boxes that are connected to SCADA systems in factories, power plants etc. I am more than happy to send any genuine buyer a free sample first as I am a new seller."

Read that again. Access into SCADA systems in power plants. With a free sample to prove the goods work. This is the supply side of ransomware, and it looks less like the dark web and more like industrial procurement.

The boxi profile in VULONE, with 65 recovered posts, 120 selectors, and the VNC + SSH thread advertising access to thousands of boxes including SCADA systems. boxi advertised access to thousands of VNC and SSH boxes, some wired into factory and power-plant SCADA, and offered a free sample to any genuine buyer.

Then there were the listings that priced the crown jewels. One broker, handle fokonishi, put it bluntly:

"USA, RDP, Energy, Revenue $800M."

The fokonishi profile, showing the USA RDP Energy $800M listing with domain controller counts, trusts, and a $2,500 price for trusted buyers. fokonishi did not just name a sector. The listing carried domain controller counts, domain trust counts, the installed AV, and a price. This is a reconnaissance report with an invoice attached.

Pwnstar offered something bigger:

"Multiple access to networks with over $1 Billion in revenue. Looking for pentesters and post exploit hackers for..."

Not "we will sell you access." "We have billion-dollar networks, and we are looking for operators." The listing is not the end of the transaction. It is the beginning of a partnership.

The pwnstar profile, advertising access to billion-dollar networks and recruiting pentesters, with a Telegram handle and a stealer-log dataset for sale. pwnstar ran the full stack: network access, a recruiting pitch for active-directory operators, a Telegram channel, and a stealer-log dataset on the side.

The price of a front door

We cataloged 99 access-for-sale listings in our monitored data, spanning 2021 through early 2024, and parsed 88 explicit prices from them. The distribution tells you almost everything about the economics.

The median was $240. Roughly a quarter of listings went for $100 or less. Top-tier corporate access ran $1,500 to $2,500. And the highest we recorded was $10,000 for a single network.

That $10,000 listing is worth dwelling on, because it is the most honest description of corporate security we have ever seen. The seller wrote, in plain Russian:

"Selling access to a very large company. Type of access: VPN (Pulse Secure). Revenue: $3B. Employees: 5,896. Price: $10,000. Geography: Colombia."

A three billion dollar company. 5,896 employees. One VPN credential. Ten thousand dollars. The price of the opening move, advertised like any commodity.

The sales pitch even named the exact appliances, Citrix, FortiGate, Cisco AnyConnect, M365, RDP, AnyDesk, Exchange, because when you are selling access, the product is the perimeter, and the perimeter has a brand.

Governments were on the menu

The most uncomfortable part of our analysis was what these listings targeted.

Across the forum activity we monitor, we documented access-for-sale posts referencing government and defense targets across more than a dozen countries, including the US, UK, Greece, New Zealand, Vietnam, and China. Of the 99 listings we cataloged, 11 explicitly named government or defense targets. A few examples, verbatim:

"[SELL] NZ Gov Webshell"

"[Sell] UK Gov WebShell"

"[SELL] Greece Government Access"

"Vietnam Government Internet Network Information Center -- Selling Access"

"Selling US Gov Financial Access"

"[RDP/SELL] USA, Defense industry, Engineering services."

"[SELLING] RDP // LA // INDIA DEFENSE AEROSPACE"

A defense-aerospace program. A government internet network center. Financial access inside a government. These are the kinds of organizations that hire firms like ours to protect them, and their access was on the shelf.

The sellers knew exactly what they were listing. One thread title read like a business-to-business catalog:

"[SELL-ПРОДАМ/-ACCESS/SELL] US,GB,FR,IN, etc. energy/government/financial/health/data providers"

Energy, government, financial, health, data providers. If your sector is on that list, and almost everyone's is, you were the product.

It was not just governments. Banks were offered outright:

"Selling Access To A Bank"

"[BANK] Selling AddisBank Full Access ADMIN"

Hospitals too:

"Selling [KR] hospital access admin ssh"

Airlines:

"[Sell] Webshell at Airline Enterprise"

This is not a collection of edge cases. It is the customer list.

What happens after the sale

This is the part that never makes the news, so it is worth spelling out. An access listing is rarely the end of the story. It is a recruitment ad.

Some buyers simply bought and deployed. But many listings did not end at "for sale." They ended at "let's work together." The same brokers who sold access were simultaneously advertising for operators:

"Looking for botnet for attacking corp networks. PM me your price and functionality."

One broker, w1nte4mute, ran a standing buy order, with a very particular geography:

"Looking for access to corp networks from countries: UA + NATO. Revenue from $3M+. Can buy your access or work as partners on %."

The w1nte4mute profile, with 34 recovered posts, a Tox ID, and a thread buying corporate access in UA and NATO countries above $3M revenue. w1nte4mute was not selling. This was a buy order. NATO countries, a revenue floor of three million dollars, and an offer to work on a percentage. Your network had a minimum order quantity.

Another team, grovergold, described the workflow outright:

"We take accesses to work on all topics. Geo: USA, CA, AU, EU. Full transparency of the process and honesty guaranteed. We give regular partners access to the panel. Rights don't matter, we work through complex networks. Any type of access, the main thing is there's an entry into the network."

The grovergold forum thread in Russian, recruiting partners across USA, CA, AU and EU, offering a panel to regular partners and paying on proof. grovergold recruited in the open. Access sellers here are not just middlemen. They sell the door, find the crew to use it, then take a cut on a percentage.

Notice what is happening. Access sellers are not only middlemen. Many are running recruitment. They sell the door, then find the crew to use it, then take a cut on a percentage. The transaction is not just goods changing hands. It is people being put to work.

And these operators are not strangers to each other. They are the same small crowd, selling to and recruiting one another across the same boards.

A VULONE view connecting the el84 and pwnstar profiles, showing one broker reaching into another's recruitment thread. el84 reaching into pwnstar's billion-dollar recruitment thread. The market is not a set of lone sellers. It is a network of the same operators, working with each other.

When the crew needs a weapon, that is on the market too. One seller, udp, was offering something more complete:

"Selling Light Locker source code, a non-resident dropper x86/x64 .exe that downloads a minimal Python distribution, unpacks and runs an encrypted script module."

The udp profile, advertising the source code of a ransomware locker called Light Locker, written in Delphi with multi-language support. A ransomware locker, source code included. Access for sale, operators for hire, and lockers for purchase. The inputs of a ransomware operation are all available in the same place.

Access for sale, operators for hire, lockers for purchase. The inputs of a ransomware operation are all available in the same place, often on the same board, often within the same week.

The numbers, in full

The victims. We cross-referenced our listing data against 28,634 documented ransomware victims tracked on public leak sites worldwide:

  • 6,467 victims in the current year alone
  • 135 active ransomware gangs, 132 countries affected
  • Top three sectors hit: Manufacturing (3,373), Technologies (1,687), Construction (1,560)
  • Healthcare (2,238) and finance (1,677 across banking, insurance, and fintech) feature prominently
  • USA leads: 11,726 victims, more than the next eight countries combined
The listings. From the forum activity we monitor:
  • 99 access-for-sale listings (2021 to 2024)
  • 88 explicit prices parsed. Median $240, roughly a quarter at $100 or less, top-tier access $1,500 to $2,500, peak $10,000
  • 13 countries and 15+ sectors referenced across listings
  • 11 listings explicitly named government or defense targets
The overlap, and what it does not claim. Before the number, the caveat, because it matters more than the number. This is not per-victim attribution. We are not saying these specific victims were bought through these specific listings. We are comparing two lists: the sectors ransomware actually hits, and the sectors the access market actively advertises. What we found is that they are largely the same list.

Of all victims with a known sector, 27.8% fall in sectors that RAMP brokers were actively advertising: healthcare (2,238 victims), finance (1,677), education (1,159), energy (977), government and defense (796), telecom (425), airlines (218), and casinos (44).

The targeting we see on leak sites is reflected on the forums first. Your sector may well have been on the menu before the first victim in your industry appeared on a leak site. The point is not the exact causal chain per victim. The point is that the access market runs ahead of the leak sites, and defenders are only watching one of the two.

The industry's entire incident-response model starts the clock after the breach. The listings start the clock earlier, and that earlier window is the one defenders never see.

A small club controls a big share

The last thing we expected to find was concentration this stark.

A market concentration view: 59 distinct sellers, with the top five accounting for roughly a third of all listings, and el84 and xss_0x2 flagged as continuous year-plus operators. Fifty-nine sellers in our monitored data. Five of them account for roughly a third of everything listed. The most prolific operated continuously for over a year.

Over the monitored period we identified 59 distinct sellers of access. In our data the concentration is stark. The top five brokers account for roughly one-third of all listings. The most prolific, handles like xss_0x2 and el84, operated continuously for over a year, posting across countries and sectors as if running a franchise.

Disrupting the access market, at least the slice of it we can see, is not a whack-a-mole problem. It is closer to a decapitation problem. A small, identifiable, persistent group of operators supplies a disproportionate share of what is listed for sale. In our threat-actor tracking, these are the profiles that matter most, because they sit where a meaningful share of attacks begins, not where they end.

The ransomware industry is not a mystery. In part, it is a listing.

Everything in this report comes from the same source the entire industry claims to monitor, the cybercrime ecosystem itself. The difference is what you are watching.

Most security teams watch leak sites. The aftermath. The name on the wall, days after the damage.

We also watch the listings. The access for sale, the buyer standing by, the locker for hire. It is a stage that comes before impact, and it is one of the few stages where defenders can still do something about it.

At VULONE, that is our model. We track 135 ransomware groups and index more than 1.7 million threat-actor profiles across 27 cybercrime forums, alongside 134,000 command-and-control servers and 33 million indicators, and we read the forums where the next attack is being assembled, looking for your sector, your region, your name.

Your sector may already be listed. The difference is whether anyone on your side is watching the listings, not just the leak sites.


VULONE is an enterprise threat-actor intelligence platform that tracks ransomware groups and high-impact threat actors across their full lifecycle, the forums they recruit on, the infrastructure they burn, the victims they claim.

This analysis is based on VULONE's continuous collection and monitoring of publicly accessible cybercrime forums, marketplaces, and threat-actor communications. Seller handles are self-declared aliases. Listings represent advertised offers, not verified completed transactions; where listings named a specific target, that attribution is the seller's own description. Sector figures reflect overlap between advertised sectors and publicly reported leak-site victims.