Ransomware's New Affiliate: Your Employee

In July 2025, a BBC cybersecurity correspondent named Joe Tidy got a message on Signal. A person calling himself "Syn" offered Tidy 15 percent of a future ransom payment in exchange for help getting into BBC systems. When Tidy hedged, Syn raised the offer to 25 percent. When that didn't work either, the same crew ran an MFA-fatigue attack on Tidy's accounts. Tidy reported the contact to BBC InfoSec and was disconnected from internal systems as a precaution. The attackers were affiliated with Medusa, a ransomware group that has hit more than 300 organizations since 2021.
That's the part of ransomware most business owners haven't priced into their risk model yet. The crew on the other end isn't only trying to phish you, scan your perimeter, or buy stolen credentials from a forum. They're also DMing your employees on Signal, LinkedIn, and Telegram, offering them a cut of the ransom in exchange for VPN credentials, RDP access, or a clean walk-in through Citrix.
This is not a fringe tactic. It is now a standard part of the ransomware playbook, and it has been for several years.
The Tesla Case Set the Template
In summer 2020, a 27-year-old Russian national named Egor Kriuchkov flew into the United States, drove to Sparks, Nevada, and spent weeks befriending a Russian-speaking employee at Tesla's Gigafactory. The pitch came over a series of meetings. Install custom malware on Tesla's internal network. Help exfiltrate data. Then Kriuchkov's group would extort Tesla for a multimillion-dollar ransom in exchange for not publishing the stolen files.
The initial offer was 500,000 dollars. When the employee hesitated, the offer doubled to one million.
The employee reported the approach to Tesla. Tesla called the FBI. The bureau worked the employee as a cooperator and recorded the follow-up meetings. Kriuchkov was arrested August 22, 2020 in Los Angeles trying to leave the country. He pleaded guilty in March 2021, was sentenced to time served (about ten months), ordered to pay $14,824.88 in restitution to Tesla for investigation costs, and was deported to Russia. Security researchers attributed the operation to Evil Corp, the Russian crew running the WastedLocker ransomware family at the time.
Two things matter about that case. The first is the offer size. A million dollars to one mid-level employee is a smaller line item to a ransomware crew than the average hourly billing rate of an incident response firm. From their side it is a cheap, surgical purchase. The second is the outcome. The plot died because the employee had a reporting channel and used it. That is not luck. That is a control. We'll come back to it.
Lapsus$ Industrialized the Pitch
By March 2022 the recruitment moved out of one-on-one meetings and onto Telegram. The crew known as Lapsus$ posted a public ad reading, in part: "We recruit employees/insider at the following: any company providing telecommunications (Telefonica, ATT, and any other similar)... large software/gaming corporations (Microsoft, Apple, EA, IBM and other similar)... Callcenter/BPM (Atento, Teleperformance, Konecta, Alorica, Genpact, Teletech, Concentrix and any other similar)... Server hosts (OVH, Locaweb, hostgator and any other similar). TO NOTE: WE ARE NOT LOOKING FOR DATA, WE ARE LOOKING FOR THE EMPLOYEE TO PROVIDE US A VPN OR CITRIX TO THE NETWORK, or some anydesk."
That is a public price list. It tells you exactly what the crew wants (a working remote connection) and how broad their target set is (every major telco, every gaming studio, every call-center BPO, every hosting provider). The Cyber Safety Review Board, a federal panel chaired in part by DHS, later confirmed that Lapsus$ was paying as much as 20,000 dollars a week for ongoing access to SIM-management portals inside telecom carriers. The same group ended up inside NVIDIA, Samsung, Microsoft (where they pulled source code from Bing and Cortana), and Okta. The Okta breach in particular came through a support contractor at a BPO called Sitel, which is exactly the kind of vendor every business in the Lapsus$ recruitment list employed.
The UK eventually arrested seven Lapsus$ members in 2022, all between 16 and 21 years old. The age matters less than the math. A teenager with a Telegram account and twenty thousand dollars a week could buy his way into companies that had spent tens of millions on perimeter security.
LockBit Just Put the Pitch in the Wallpaper
Lapsus$ recruited in the open. LockBit went further. Starting with LockBit 2.0 in August 2021, the desktop wallpaper that appeared on every encrypted Windows machine carried this message: "Would you like to earn millions of dollars? Our company acquire access to networks of various companies, as well as insider information that can help you steal the most valuable data of any company. You can provide us accounting data for the access to any company, for example, login and password to RDP, VPN, corporate email, etc. Open our letter at your email. Launch the provided virus on any computer in your company... Companies pay us the foreclosure for the decryption of files and prevention of data leak."
Think about who reads that wallpaper. Every IT person at the victim company. Every contractor. Every system administrator working overtime to restore from backup. The recruitment pitch was embedded in the ransom note itself, so the people most positioned to help the attacker on a future job were also the people most likely to see the ad. A joint CISA and FBI advisory (AA23-165A) confirmed LockBit's affiliate-recruitment model as the reason its TTPs varied so widely. It was less a single criminal organization than a franchise, and the franchise was always hiring.
When the Vendor Is the Insider
In May 2025, Coinbase disclosed a breach that didn't come through an exploit or a phishing email. It came through bribed customer-support agents at TaskUs, a business process outsourcing firm in Indore, India. According to court documents and reporting from BleepingComputer and Fortune, attackers paid TaskUs agents roughly 200 dollars per record to photograph Coinbase customer information off their screens. One agent recruited supervisors and team leaders to scale the operation, turning a single corrupt employee into a coordinated conspiracy that captured customer data on approximately 200 records per day.
About 70,000 Coinbase customers were affected. The attackers then demanded a 20-million-dollar ransom. Coinbase refused and announced a 20-million-dollar reward fund for information leading to arrests. The company's SEC filing estimated remediation and customer-reimbursement costs at $180 million to $400 million. TaskUs shut down its Coinbase operations in Indore in January 2025, affecting 226 employees.
For a small or mid-sized business, the lesson is uncomfortable. Most SMBs don't run their own call centers or customer-support floors. They outsource them. They outsource IT, accounting, payroll, fraud detection, and incident response. Every one of those vendors has employees with access to your customer data, your network, or both. The Coinbase case is what happens when the criminal economy figures out that the easiest way into a Fortune 500 company isn't to attack the company itself. It is to attack the lowest-paid worker at the company that supports it.
The Security Industry Has Its Own Inside Job
The most recent and most uncomfortable case landed in October 2025. The DOJ indicted three men: Ryan Goldberg, 40, an incident response manager at the cybersecurity firm Sygnia; Kevin Martin, 36, a ransomware negotiator at DigitalMint; and Angelo Martino, 41, also a ransomware negotiator at DigitalMint. Between April and December 2023, the three operated as ALPHV/BlackCat ransomware affiliates on the side. They hit five US companies. A Florida medical company. A Maryland pharmaceutical company. A California doctor's office. A Virginia drone company. A California engineering firm. The Florida medical company paid roughly 1.2 million dollars. Twenty percent of that went to the ALPHV core operators. The rest went to the three men.
Goldberg and Martin pleaded guilty in December 2025. Martino pleaded guilty separately. Sentencing is scheduled for April 30, 2026. Maximum exposure is 20 years on the extortion conspiracy charge.
Read that paragraph again. The defendants' day jobs were responding to ransomware attacks and negotiating with ransomware crews on behalf of victim companies. The criminal access wasn't a side project that bumped up against their professional lives. It was their professional lives, weaponized. The same skills, the same victim-side intelligence, the same comfort with the negotiation script. When the trusted incident-response vendor or negotiation firm walks in the door of your breach, you are extending privileged access to people whose firms might or might not have done a deep background check on every employee. Three of them already turned out to be ALPHV affiliates.
Four Doors, Not One
The Tesla, Lapsus$, LockBit, Coinbase, and ALPHV cases all end in the same place: an attacker with employee-equivalent access to a target network. But how the attacker got there varies in ways that matter for how you defend.
There is the recruited insider, who took money to help. Tesla, Lapsus$, LockBit, Medusa, Coinbase, ALPHV all live here. The control that stops this is making sure employees have somewhere to report a recruitment attempt and a reason to trust that reporting it won't cost them their job.
There is the manipulated insider, who got tricked. The crew Microsoft tracks as Octo Tempest (also called Scattered Spider) builds its entire business model on voice-phishing IT help desks. They call in pretending to be an employee who lost their phone. The help desk resets the password, re-enrolls MFA, and the attacker is in. CISA and FBI published a joint advisory (AA23-320A) documenting Octo Tempest's hits across telecom, retail, hospitality, gaming, insurance, airlines, MSPs, manufacturing, legal, technology, and financial services.
There is the coerced insider, who got threatened. The same Octo Tempest crew has been documented sending employees pictures of their home address, their spouse, and threats of physical violence to extort credentials. Microsoft published screenshots of the texts in its October 2023 writeup.
There is the impersonated insider, where the attacker simply poses as the employee to a third party (the help desk, the bank, the vendor) and gets the same outcome without ever touching the employee at all.
Each of these requires a different defense. Recruitment fails when employees have a reporting channel. Manipulation fails when help desks verify out-of-band before resetting credentials. Coercion fails when employees know to immediately disclose threats to security or law enforcement. Impersonation fails when third parties refuse to trust caller identity alone.
What the Numbers Say
A few data points worth sitting with:
- The 2025 Verizon Data Breach Investigations Report found ransomware present in 44 percent of breaches it analyzed, up 37 percent year over year. For organizations without mature security programs, ransomware was present in 88 percent of breaches.
- The same report found third-party involvement in breaches doubled from 15 percent to 30 percent in a single year.
- The 2025 Ponemon "Cost of Insider Risks" report (sponsored by DTEX) put the average annualized cost of insider risk at 17.4 million dollars per organization, with a mean containment time of 81 days. Malicious insider incidents averaged 3.7 million dollars each.
- The FBI's 2024 Internet Crime Report logged 3,156 ransomware complaints (up 9 percent year over year) and called ransomware "the most pervasive threat to critical infrastructure" in 2024.
- Coveware's Q3 2025 report noted the ransom payment rate dropped to a historic low of 23 percent, while specifically calling out that "traditional RaaS groups are now actively recruiting insiders" as the next wave of pressure.
The downstream signal is clear. Pure-perimeter attacks are getting less profitable. Insider-assisted attacks are getting more attention.
What Small and Mid-Sized Businesses Should Actually Do
CISA published an Insider Threat Mitigation Guide that is free, public, and scaled for organizations smaller than the Fortune 1000. The full document is 80 pages. The version that fits on one page for a 50 to 200 person company looks like this:
-
Make standing remote access scarce. The recruitment ads from Lapsus$ and LockBit asked for VPN, Citrix, RDP, and AnyDesk credentials specifically. Every employee who has standing access to those tools and doesn't need it represents inventory the attacker can buy. Audit who has remote access, why they have it, and whether it can be just-in-time instead of always-on.
-
Write down the reporting channel for recruitment attempts. Pick a person. Publish their name, email, and phone number on the intranet next to "if anyone offers you money for system access, contact this person." Tesla worked because the employee knew who to call. Most SMBs have never had this conversation with their staff.
-
Promise non-retaliation in writing. An employee who reports a recruitment attempt should not lose their job, their bonus, or their assignment over it. Say so on paper. The recruiter is offering them a million dollars. You are asking them to walk away from that. You are also asking them to admit they were approached. Give them a reason to do it.
-
Verify out-of-band before resetting credentials or MFA. When an "employee" calls the help desk saying they lost their phone, the help desk should not be able to reset MFA without a second-factor verification through a known channel (manager callback, in-person, video confirmation). Phishing-resistant MFA (FIDO2 hardware keys, smart cards) for admin accounts. This is the single highest-value control against Octo Tempest.
-
Audit your vendors. Anyone with a login into your environment counts. Your MSP. Your accountant. Your CRM consultant. Your IR retainer. Your call-center vendor. Ask each one for a SOC 2 report or equivalent, an employee-vetting policy, and an access log into your systems. The ALPHV indictment and the Coinbase breach both came through trusted vendor staff.
-
Tighten offboarding. Same-day account disable, MFA token revocation, mobile device wipe, removal from VPN groups. The Conti chat logs leaked in 2022 showed how aggressively the Russian-speaking criminal economy buys access from former employees. Stale accounts are inventory.
-
Run the recruitment scenario in a tabletop. Most SMBs phish-test their staff. Almost none roleplay the LinkedIn DM offering 50 thousand dollars for VPN credentials. Add it to the annual exercise. The conversation alone is worth the hour.
None of these are expensive. None of them require new vendors or new software. All of them are documentable, which is the part that matters when a regulator, an insurer, or a customer asks what controls you have in place.
Back to Tesla
Egor Kriuchkov flew to Nevada with a million dollars and a custom malware payload. The plot collapsed because one employee made one phone call to one manager who knew to call the FBI. The control that stopped him was not a firewall. It was a workforce that knew what to do if a stranger offered money for system access, and a culture that meant the employee believed reporting it would be received well.
That is a control you can build this quarter. It costs almost nothing. And it is the only control that actually works against an attacker who has decided your easiest way in is already on your payroll.
If you want help thinking through how to harden the insider-threat side of your operation, that is the kind of conversation Sentinel Vault is built for. The recruitment pitches are out there. The Telegram ads are still running. The question is whether your team knows what to do when one shows up in their inbox.
References
- BleepingComputer, "Ransomware gang sought BBC reporter's help in hacking media giant," July 2025. https://www.bleepingcomputer.com/news/security/ransomware-gang-sought-bbc-reporters-help-in-hacking-media-giant/
- Trend Micro, "Russian Who Tried to Hack Tesla Pleads Guilty," April 2021. https://www.trendmicro.com/en_us/research/21/d/russian-who-tried-to-hack-tesla-pleads-guilty.html
- The Record (Recorded Future News), "Russian who tried to hack Tesla last summer pleads guilty." https://therecord.media/russian-who-tried-to-hack-tesla-last-summer-pleads-guilty
- Krebs on Security, "A Closer Look at the LAPSUS$ Data Extortion Group," March 23, 2022. https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/
- Microsoft Threat Intelligence, "DEV-0537 criminal actor targeting organizations for data exfiltration and destruction," March 22, 2022. https://www.microsoft.com/en-us/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
- DHS Cyber Safety Review Board, "Review of the Attacks Associated with Lapsus$ and Related Threat Groups," July 24, 2023. https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus$_508c.pdf
- BleepingComputer, "LockBit ransomware recruiting insiders to breach corporate networks," August 2021. https://www.bleepingcomputer.com/news/security/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks/
- CISA/FBI Joint Cybersecurity Advisory AA23-165A, "Understanding Ransomware Threat Actors: LockBit," June 14, 2023. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a
- BleepingComputer, "Coinbase breach tied to bribed TaskUs support agents in India," June 3, 2025. https://www.bleepingcomputer.com/news/security/coinbase-breach-tied-to-bribed-taskus-support-agents-in-india/
- Fortune, "Inside the $400 million Coinbase breach," May 29, 2025. https://fortune.com/crypto/2025/05/29/coinbase-hack-the-community-taskus-bpos-teenagers/
- The Record, "Ransomware responders' guilty plea using ALPHV/BlackCat in US attacks," December 2025. https://therecord.media/ransomware-responders-guilty-plea-using-alphv-blackcat-us-attacks
- DOJ press release, "Florida man working as ransomware negotiator pleads guilty to conspiracy to deploy ransomware." https://www.justice.gov/opa/pr/florida-man-working-ransomware-negotiator-pleads-guilty-conspiracy-deploy-ransomware-and
- Microsoft Threat Intelligence, "Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction," October 25, 2023. https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/
- CISA/FBI Joint Cybersecurity Advisory AA23-320A, "Scattered Spider," November 16, 2023 (updated July 29, 2025). https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
- Verizon, "2025 Data Breach Investigations Report." https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf
- Ponemon Institute / DTEX, "2025 Cost of Insider Risks Global Report." https://ponemon.dtexsystems.com/
- FBI Internet Crime Complaint Center, "2024 Internet Crime Report." https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
- Coveware, "Insider threats loom while ransom payment rates plummet," October 24, 2025. https://www.coveware.com/blog/2025/10/24/insider-threats-loom-while-ransom-payment-rates-plummet
- CISA, "Insider Threat Mitigation Guide," November 2020. https://www.cisa.gov/resources-tools/resources/insider-threat-mitigation-guide
- Krebs on Security, "Conti Ransomware Group Diaries, Part I: Evasion," March 2022. https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/

