Last updated 1 month ago
Cifas, a United Kingdom-based fraud prevention service, reported that 13% of employees surveyed admitted to selling their corporate login credentials to a former colleague. The survey highlights a significant insider threat within the workforce, with one in eight workers engaging in credential sales. The exact number of affected organizations or individuals was not disclosed.
The attack vector is insider threat, as employees voluntarily sold their credentials. The compromised data type is corporate login credentials, which could enable unauthorized access to company systems and data. No specific threat actor or technical exploitation method was identified.
No post-incident developments were reported in the article.
Insider threat: employees selling corporate credentials to former colleagues
This survey underscores the need for organizations to implement robust insider threat detection programs, including user behavior analytics and access monitoring. The prevalence of credential sales suggests that security awareness training should emphasize the risks of credential sharing and the consequences of selling access. Additionally, enforcing least-privilege access and requiring multi-factor authentication can mitigate the impact of compromised credentials.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector