Intel 471: Criminals recruit insiders at FedEx and UPS

Intel 471: Criminals recruit insiders at FedEx and UPS

Cybercriminals are actively trying to recruit employees inside target organizations, because staff with legitimate access can bypass security controls that are hard to defeat from the outside. This is according to Intel 471's new report, Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services.

The threat intelligence firm found that routine tasks such as looking up information, resetting accounts, approving transactions or changing shipments are being packaged and sold as services to criminal customers.

Recruitment dominates the sample

Intel 471 analyzed 85 records. Recruitment was the largest category, with 45 records. Another 15 involved claims of insider capability, 11 of them claims of insider access. Twelve records advertised services allegedly enabled by employee privileges. The rest covered access and data offerings, a recruitment guide and a complaint.

Threat actors looked for employees who could pull restricted information, manipulate accounts, help with subscriber identity module (SIM) swaps, interfere with shipments, enable fraud or support intrusion and extortion.

Some actors sold services based on claimed employee privileges. Others, acting as buyers or operational partners, wanted those capabilities for larger criminal schemes. Criminal forums, messaging platforms and other marketplaces served as meeting points for recruitment, advertising, referrals and negotiation.

Brokers, referrals and planted job applicants

Recruiters used several methods to find insiders: public solicitations, targeted approaches, referrals, brokers and partnership offers. Referrals and brokers let criminals outsource the search for suitable staff. In other cases, self-proclaimed insiders offered their own access or cooperation. Some recruiters relied on deception or built relationships with prospects over time.

Intel 471 described two broad models. In deliberate employment schemes, actors looked for willing participants who would apply for jobs at targeted organizations and abuse their privileges once hired. Other efforts focused on existing employees whose roles already gave them control over valuable information, systems or business processes.

Payment models varied. Advertisements mentioned per-action payments, one-time sales of access or data, referral and recruitment fees, revenue sharing and ongoing arrangements. Money could go to the insider, to a facilitator, or be split among several participants based on their roles.

To manage trust, actors used or proposed escrow, staged payments, verification requirements and other transaction controls.

Shipping, tech and telecom in focus

Transportation was the most frequently referenced industry, appearing in 19 leads. Technology followed with 17 and telecommunications with 15. Another 26 leads were cross-sector or could not be confidently tied to one industry. Because a single lead could mention several industries, the figures overlap. Intel 471 notes they describe the sample and do not measure how common insider threats are in each sector.

In transportation, criminals wanted insiders who could locate, hold or reroute shipments and change related records. In telecommunications, they sought help with SIM swaps, subscriber lookups and account resets to support account compromise and fraud. Technology cases centered on internal user data, account administration, content moderation and privileged enterprise access.

FedEx and UPS were each named in nine leads, the highest count for any organization. Instagram appeared in four. DoorDash, Facebook, Meta, Verizon and eBay each appeared three times. AT&T, Apple, LinkedIn, PayPal, Santander, T-Mobile and UAB Urbo Bankas were each mentioned twice.

Our take

The report suggests that insider access is being treated less as a rare opportunity and more as a product, with brokers, referral fees, escrow and pricing models that look much like the rest of the underground economy. For defenders, the problem is that the abused actions, such as a password reset or a shipment change, are normal parts of someone's job and may not trigger any alerts.

The telecom findings fit with ongoing concern about telecom security, where SIM swaps remain a gateway to account takeover. The sample is small, so it does not show how widespread the problem is. Still, it is worth watching whether organizations in the named sectors tighten oversight of high-risk employee actions and screening of new hires, given that some schemes reportedly plant applicants from the start.