A TrendAI (Trend Micro) report describes a structured underground market where criminals recruit employees to provide access, approve transactions, and bypass controls, often via Telegram and hacking forums. The article gives concrete examples (e.g., paying a FedEx employee $1,000/day to update tracking systems, paying for SIM swaps, or removing social media bans), which can be turned into realistic insider-recruitment awareness simulations.
How the recruitment scheme works
A TrendAI (Trend Micro) report describes a structured underground market operating largely on Telegram and hacking forums, where criminals recruit employees willing to sell access, approve fraudulent transactions, or bypass internal controls. The market includes brokers, escrow services, and recruitment posts that connect insiders with buyers ranging from scammers to ransomware groups. Recruitment runs in both directions: insiders advertise their access for sale, and criminals also actively solicit employees at target companies.
What insiders are paid to do
The report lists specific examples of paid insider actions across several industries:
- Uploading falsified tracking information into shipping systems, with one buyer reportedly offering $1,000 per day for a FedEx employee capable of doing this
- Performing SIM swaps at telecom companies to defeat SMS-based multi-factor authentication and gain access to email or bank accounts
- Removing account bans or safelisting suspicious ads on social media platforms, with prices for ban removal reportedly ranging from $1,000 to $7,000
- Approving fraudulent refunds or transfers, generating shipping labels, or falsifying delivery confirmations
Offers to insiders include fixed payments, profit-sharing agreements, and referral bonuses for bringing in additional insiders.
Why this approach succeeds
This type of recruitment does not rely on exploiting a technical vulnerability. Instead, it targets employees who already have legitimate access to internal systems, approval workflows, or moderation tools. Because the requested actions, such as approving a transfer or updating a tracking record, can resemble routine job tasks, they may not immediately stand out as suspicious to the insider or to observers, especially when payment is framed as a simple side gig.
What to watch for
Defenders and employees should be alert to:
- Unsolicited approaches on messaging apps like Telegram offering payment for internal actions
- Offers of unusually high pay, profit-sharing, or referral bonuses tied to job-related access
- Requests to bypass verification steps, approval workflows, or moderation policies
- Unusual workflow exceptions, such as excessive account recoveries or oddly timed manual approvals
Building resistance
TrendAI recommends treating workflow exceptions as security events worth reviewing, and reducing single-person authority by requiring dual approval for high-risk transactions such as transfers, account recoveries, and moderation overrides. The report also recommends that fraud and cybersecurity teams share information and coordinate, since these schemes blend policy abuse with technical compromise and can otherwise slip between the cracks. Preparing staff across shipping, telecom, finance, and trust and safety roles to recognize and report recruitment attempts is a key part of reducing this exposure.
Key findings
- TrendAI describes a “highly structured underground economy” for recruiting corporate insiders, using Telegram and hacking forums.
- The market includes “brokers, escrow services, and recruitment posts,” connecting employees willing to sell access/data with criminals including scammers and ransomware groups.
- Recruitment can be two-way: insiders advertise access, and criminals actively solicit employees at target companies.
- Offers include fixed payments, profit-sharing, and even “referral bonus[es].”
- Examples include paying insiders to remove social media bans, approve fraudulent refunds, perform SIM swaps to defeat SMS-based MFA, approve transfers, generate shipping labels, or falsify delivery confirmations.
- One example quote: “$1,000 per day for a FedEx employee capable of uploading tracking information into internal systems.”
- TrendAI recommends monitoring workflow exceptions as security events and reducing single-person authority via dual approvals.
Who’s being targeted
- Commonly targeted roles: All employees, Trust & Safety / Content Moderation, Ad Operations, Telecom Customer Service and Provisioning, Finance (approvals/transfers), Shipping & Logistics Operations, Fraud team, Security team, HR (insider risk awareness).
- Affected industries: Social media / online platforms, Online review platforms, Telecommunications, Financial services, Shipping and logistics, Government / public sector platforms (credential access referenced).
- Attack channels: telegram.
- Impersonated: Underground “buyer” claiming to represent a fraud operation, Criminal recruiter offering payment for telecom account actions, Third-party advertiser/agency (actually a criminal) seeking ‘trust & safety’ help.
Red flags to watch for
- Offer of unusually high pay for a simple internal task
- Request to use internal systems for non-business purposes (tracking updates/falsified confirmations)
- Mentions of referral bonuses/escrow typical of illicit marketplaces
- Request to perform account actions that bypass normal verification steps
- Pressure to treat security controls/approvals as a formality
- Payment offered for actions outside job duties
- Payment tied to internal moderation or enforcement actions
- Requests that explicitly undermine platform policy (safelisting dodgy ads, removing bans)
- Unusual pricing per action suggests illicit activity
Frequently asked questions
How are criminals recruiting corporate insiders?
According to a TrendAI report, criminals use Telegram and hacking forums to run a structured underground economy with brokers, escrow services, and recruitment posts that connect insiders to buyers, including scammers and ransomware groups.
What kinds of payments do insiders receive?
Offers include fixed payments, profit-sharing agreements, and referral bonuses, with one example describing $1,000 per day offered for a FedEx employee capable of uploading tracking information into internal systems.
Which industries and roles are being targeted?
Targeted roles span shipping and logistics, telecommunications customer service, financial approvals, and social media trust and safety teams, since these roles can bypass verification, approvals, or moderation controls.
How can organizations reduce this risk?
TrendAI recommends monitoring workflow exceptions as security events, requiring dual approval for high-risk transactions, and having fraud and security teams share information so these schemes do not slip between the cracks.
Read the video transcript
You’re scrolling Telegram and see this: “FedEx insider needed to upload tracking info, $1,000 per day. Referral bonus.” That’s not a side gig. That’s a crime. TrendAI found a whole underground economy doing this on Telegram and forums, brokers, escrow, even profit‑sharing. They pay insiders to fake delivery confirmations, approve bogus refunds, or do SIM swaps to break SMS MFA. Here’s the trick: it sounds like easy money for a tiny favor, one manual override, one ‘harmless’ approval, one SIM swap. But those workflow exceptions are exactly how scammers and ransomware groups get in. If anyone ever offers cash, profit‑share, or a ‘referral bonus’ to bend our systems, treat it as an attack, screenshot it and report it to Security immediately.