Get a free audit

Field Notes / Threat Intelligence

A Working Login to Your Network Sells for $700. Here Is What the Buyer Does Next.

Verizon put a median price on stolen corporate access in 2026: about $700 for a user account, $1,300 for an administrator. Its own analysts admitted they had expected more. Here is how that market prices your company, what happens in the twenty-two seconds after access changes hands, and the three intervals that decide whether any of it reaches you.

Author
Red Team Partners
Read
12 MIN READ
Filed
28 Aug 2026
An abstract wall of database records, the shape of the billions of stolen credentials now circulating on criminal markets.

01 The price list

our independent bodies of research now price this market, and they broadly agree once you read them carefully. Verizon's $700 and $1,300 medians sit alongside KELA's quarterly tracking of network access listings, which put the median asking price at $400 in the first quarter of 2022, $300 in the second, and $400 again in the first quarter of 2023 KELA 2022–2023 . ENISA, the European Union's cyber security agency, reported that most access sold by brokers went for under EUR 2,800 ENISA Threat Landscape 2025 .

What is being soldTypical priceMeasured by
Standard user account$700 medianVerizon DBIR, 2026
Administrator account$1,300 medianVerizon DBIR, 2026
Full network access listing$300 to $400 medianKELA, 2022 to 2023
Most broker-sold accessUnder EUR 2,800ENISA, 2025
58% of all listings in 2024Under $1,000Check Point / Cyberint

Be careful with averages here, because the market is built to produce misleading ones. Flare studied 72 auctions on a single forum in 2023 and calculated an average price of $4,699 with outliers included, and $1,328 with them removed Flare 2023 . Rapid7 reported an average base price of $113,275 across the second half of 2025, a rise it described as roughly 4,055 per cent, while stating in the same research that nearly 40 per cent of listings sold for between $500 and $1,000 Rapid7 Labs 2026 . Both figures are real. One trophy listing for a multinational drags the mean into six figures while the ordinary company on the same forum still goes for the price of a laptop.

02 Where the logins come from

Almost none of these credentials are guessed. Most are harvested in bulk by infostealer malware, which does one job: land on a machine, copy every saved password, session cookie and authentication token out of the browser, and send them onward. The user usually installs it themselves, attached to a cracked application or a file that arrived looking useful.

Flashpoint recorded 11.1 million infected machines across a year, producing more than 3.3 billion stolen credentials, session cookies and cloud tokens in circulation on criminal markets Flashpoint 2026 . That is a commercial vendor counting its own collection, and you should read the absolute number with that in mind. The direction it points matches what government assessors find independently.

Check Point's listing analysis adds a detail that should worry anyone relying on default tooling. Across the machines advertised for sale, more than 40 per cent carried only Windows Defender, rising to 53 per cent in 2024 Check Point / Cyberint . The broker is not selling you a story about a sophisticated adversary. They are selling a laptop that nobody was really watching.

03 Twenty-two seconds

Here is the number that changes how you should think about response time. Mandiant measured the interval between one attacker gaining access and handing that access to whoever would use it next. In 2022 the median was more than eight hours. In 2025 it was twenty-two seconds Mandiant M-Trends 2026 .

The reason is mundane. Brokers now pre-stage the buyer's tooling during the initial break-in, so the handover is prepared before it happens. The transaction you imagine, with a listing, a negotiation and a wait, has been compressed into an automated pass.

KELA measured the commercial side of the same trend and found that the average time for an access listing to sell was 1.75 days KELA 2022–2023 . Two days from advertisement to owner. Twenty-two seconds from owner to operator. Against that, Mandiant put the global median dwell time in 2025 at 14 days, up from 11 the year before.

THE INTERVAL An administrator reading a threat detection alert in a server room, hours or days after the access was already sold.
Twenty-two seconds on their side. A median of fourteen days on yours. Everything that matters happens in the gap.

04 The warning you already have

The useful part of all this is that the trail arrives early, and it arrives in public. Verizon matched ransomware victims against credential-leak data for its 2026 report. Among victims that had any prior exposure, half had a credential or infostealer event within 95 days of being publicly named as a ransomware victim. Twenty-seven per cent had no such event in the preceding year at all Verizon DBIR 2026 .

Read that alongside Mandiant's finding that prior compromise was the leading initial infection vector in ransomware operations at 30 per cent, double the 15 per cent recorded in 2024 Mandiant M-Trends 2026 . In a large share of cases, the credentials had surfaced somewhere before the extortion note did. Somebody could have seen them.

Two further findings explain why nobody did. CISA's own red teams, running 143 assessments against real organisations, found that abusing valid accounts accounted for 41 per cent of successful initial access attempts in FY23 CISA FY23 RVA . Sophos, working from 661 incident response cases, attributed 67.32 per cent of root causes to compromised identity and found multi-factor authentication missing in 59 per cent of them Sophos 2026 . A valid login on an account with no second factor defeats a security programme without touching any part of it.

05 What to fix this quarter

Three intervals decide your exposure, and all three can be measured before anything happens to you. Put a number on each one this quarter, including the cases where the answer is embarrassing, and measure again in ninety days.

Measure exposure to discovery: how long between one of your credentials appearing in a dump or on a market and somebody inside your organisation knowing. Measure discovery to revocation: how long between knowing and the account being disabled, the password rotated and the session invalidated. Then measure revocation to assurance: how long before you can state, with evidence, that the same credential is not still working somewhere it was reused.

Most organisations cannot currently answer any of the three. That is the finding, and it is a better starting point than it sounds, because each one is a number you can move. Twenty-two seconds is what the other side has already achieved. The fourteen days are yours to change.

References

Sources

  1. Verizon. 2026 Data Breach Investigations Report. Figure 50, advertised prices for stolen accounts (n=453 admin, n=1,008 user). verizon.com
  2. KELA. Ransomware Victims and Network Access Sales, quarterly research reports, 2022 to 2023. kelacyber.com
  3. Check Point / Cyberint. Initial Access Brokers Report, covering 2023 and 2024 listing data. e.cyberint.com
  4. Flare. Initial Access Brokers, Russian Hacking Forums and the Underground Corporate Access Economy. 16 August 2023. flare.io
  5. Rapid7 Labs. Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing. 31 March 2026. rapid7.com
  6. Google Cloud / Mandiant. M-Trends 2026, drawn from over 500,000 hours of incident response in 2025. cloud.google.com
  7. CISA. FY23 Risk and Vulnerability Assessments Analysis, covering 143 assessments. Published September 2024. cisa.gov
  8. Sophos. Active Adversary Report 2026, covering 661 cases from November 2024 to October 2025. sophos.com
  9. Flashpoint. Identity Is the New Attack Surface. 10 June 2026. flashpoint.io
  10. ENISA. Threat Landscape 2025, reporting period July 2024 to June 2025. enisa.europa.eu