Court documents unsealed this week revealed that a systems administrator at a managed services provider sold privileged access to client corporate networks through darknet initial-access brokers.
The insider provided VPN credentials and remote-management tokens for at least nine companies, receiving cryptocurrency payments routed through mixers. Buyers included ransomware affiliates who later attacked two of the firms.
The scheme unraveled when undercover investigators purchased access to a honeypot network and traced the seller through payment flows and login forensics.
Prosecutors are seeking enhanced penalties, noting the defendant abused a position of exceptional trust. The case has renewed calls for stricter monitoring of privileged accounts at service providers.
