Cybrsecurity firm Rapid7, has released its 2025 Access Brokers Report, a new research analysis of illicit underground marketplaces where cyber-criminals buy and sell access to corporate networks.
Drawing on six months of threat intelligence from dark web forums Exploit, XSS, and BreachForums, the report uncovers new insights into how initial access to compromised businesses is being sold – often for less than $1,000 – and the steps defenders can take to disrupt the process in its earliest stages.
Rapid7’s threat intelligence researchers analysed hundreds of posts by Initial Access Brokers (IABs) offering access to compromised networks across a range of industries and regions. Their findings paint a stark picture: “initial” access doesn’t necessarily equate to minimal; in many cases, this access represents a deep compromise.
“This report shows that initial access brokers aren’t intent upon finding a single way into an organisation’s network and then quickly exiting – they’re making attempts to explore the networks they’ve infiltrated. And they’re often succeeding,” said Raj Samani, SVP and chief scientist at Rapid7.
“In doing so, the IAB can offer buyers admin privileges, multiple access types, or both. By the time a threat actor logs in using the access and privileged credentials bought from a broker, a lot of the heavy lifting has already been done for them. Therefore, it’s not about if you’re exposed, but whether you can respond before the intrusion escalates.”
The report found that the vast majority of access broker sales (94%) included not just a specific access vector but also a level of privilege.
In nearly 10% of cases, these sales were bundled with multiple initial access vectors and/or privileges. The average sale price was just over $2,700, with almost 40% of offerings falling between $500 and $1,000.
VPN, Domain User, and RDP access were identified as the most common types sold – the same weak points frequently observed in Rapid7’s incident response investigations.
The Access Brokers Report arrives as security teams grapple with alert fatigue, limited resources, and evolving attacker tradecraft. Rapid7 states that there’s a growing body of evidence to support the idea that exposure management and threat detection must be operationalised together, not handled in isolation.
Recommended reading
- UK Gov Cyber Breaches Survey 2024 | Key Stats and Data
- Report: Cyber Breaches Are Tanking Share Prices
- Cyber-crime Costs to Hit $1.2tn in 2025, New Report Warns
In addition to in-depth forum analysis, the report outlines concrete steps organisations can take to harden defenses and reduce attacker dwell time:
- Enforce MFA — especially on VPN, RDP, and user accounts that access critical infrastructure.
- Invest in threat-informed detection and response — including unified platforms that correlate access signals with suspicious activity.
- Run regular red team exercises to identify exposure paths like abandoned accounts, default credentials, and externally accessible RDP services.
This research reinforces Rapid7’s position that threat detection and exposure management must be fast, unified, and context-rich. According to the firm, operationalising threat intelligence, asset context, and automation isn’t just a best practice – it’s a requirement.
Initial Access Brokers and the forums they use have long been analysed by threat intelligence teams. While law enforcement activity and takedowns continue, access brokers remain a persistent threat to organisations around the world.





