1 in 8 employees have sold company logins or know someone who has
UK anti-fraud non-profit Cifas just published research that should bother anyone who runs a business, or buys from one: One in eight workers at large enterprises have either sold their company login credentials or know someone who did.
The internet is awash with compromised credentials that employees use to access company systems. Threat intelligence company KELA tracked nearly 2.9 billion compromised credentials globally in 2025. Most of these come from phishing attacks and infostealers. But thanks to employees wanting to make a quick buck, cyber criminals can just make people an offer.
The insiders nobodyβs watching
Cifas interviewed 2,000 employees of companies with at least 1,000 staff. Of these, 13% admitted to selling their corporate access credentials in the last 12 months, or knowing someone who did. Amazingly, as the report says, the sellers did so βoften under the belief itβs harmless.β
Newsflash: Selling your account credentials isnβt harmless. Criminals want them so they can take over the account and do nefarious things with it. Account takeovers in the US surged 6% to over 78,000 last year, according to Verizon.
Many hijacked accounts are personal ones for services ranging from social media to online streaming sites, and of course bank accounts. But many others are accounts for business systems like Microsoft 365, Salesforce, and other platforms that hold sensitive company data. Those secrets are valuable commodities for criminals who can then trade them on the open market.
Your boss is more likely to sell than you
Ideally, this is where a common technique called βleast-privilege accessβ should come in.
The idea is that a corporate online account should only have access to what it needs. So Jim in the canteen should have access to the food ordering system, but not to the entire customer database. That way, even if Jimβs account gets compromised, the worst the attackers could do is deprive you of sausages tomorrow.
The problem is that, according to the report, higher-ups are even more comfortable selling their account credentials than low-level employees. Thirty-two percent of senior managers find it justifiable, along with 36% of directors, 43% of C-suite executives, and, stunningly, four in five business owners. Their roles mean that even with least-privilege access, their accounts can still open routes to sensitive system functions and data.
This isnβt just a UK problem
The Cifas research is UK-specific, but thatβs likely not where it ends. Weβve seen employees at several companies selling access to either company accounts or records. For example, cryptocurrency company Coinbase revealed last year that employees at a Bangladesh-based outsourcing company sold customer records to hackers.
Compromised credentials are widespread. Our own research found that in a single 30-day window, 111 Fortune 500 companies had employee credentials leaked. Long-term, 363 of those firms (thatβs 73%) have lost control of at least one employee credential.
Employees selling their access credentials isnβt just bad for the companies that employ them. Itβs also bad for customers.
When a directorβs password goes up for sale, a customer file might not be far behind, although it likely wonβt be the director selling it. Malwarebytes found that 91% of Fortune 500 companies have had their customersβ credentials leaked, and hijacked accounts are a great way to get at them.
So insider risk isnβt just a corporate issue. Itβs also a consumer one. That makes us less likely to hand over our personal information to large enterprises without questioning why they need it.
Your name, address, and phone number areΒ probably alreadyΒ for sale.Β Β
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.Β