Hackers Recruit Insiders With Cash and Referrals

IT Pro Security · High sophistication
Last updated August 7, 2026

A TrendAI (Trend Micro) report describes a structured underground market where criminals recruit employees to provide access, approve transactions, and bypass controls, often via Telegram and hacking forums. The article gives concrete examples (e.g., paying a FedEx employee $1,000/day to update tracking systems, paying for SIM swaps, or removing social media bans), which can be turned into realistic insider-recruitment awareness simulations.

How the recruitment scheme works

A TrendAI (Trend Micro) report describes a structured underground market operating largely on Telegram and hacking forums, where criminals recruit employees willing to sell access, approve fraudulent transactions, or bypass internal controls. The market includes brokers, escrow services, and recruitment posts that connect insiders with buyers ranging from scammers to ransomware groups. Recruitment runs in both directions: insiders advertise their access for sale, and criminals also actively solicit employees at target companies.

What insiders are paid to do

The report lists specific examples of paid insider actions across several industries:

  • Uploading falsified tracking information into shipping systems, with one buyer reportedly offering $1,000 per day for a FedEx employee capable of doing this
  • Performing SIM swaps at telecom companies to defeat SMS-based multi-factor authentication and gain access to email or bank accounts
  • Removing account bans or safelisting suspicious ads on social media platforms, with prices for ban removal reportedly ranging from $1,000 to $7,000
  • Approving fraudulent refunds or transfers, generating shipping labels, or falsifying delivery confirmations

Offers to insiders include fixed payments, profit-sharing agreements, and referral bonuses for bringing in additional insiders.

Why this approach succeeds

This type of recruitment does not rely on exploiting a technical vulnerability. Instead, it targets employees who already have legitimate access to internal systems, approval workflows, or moderation tools. Because the requested actions, such as approving a transfer or updating a tracking record, can resemble routine job tasks, they may not immediately stand out as suspicious to the insider or to observers, especially when payment is framed as a simple side gig.

What to watch for

Defenders and employees should be alert to:

  • Unsolicited approaches on messaging apps like Telegram offering payment for internal actions
  • Offers of unusually high pay, profit-sharing, or referral bonuses tied to job-related access
  • Requests to bypass verification steps, approval workflows, or moderation policies
  • Unusual workflow exceptions, such as excessive account recoveries or oddly timed manual approvals

Building resistance

TrendAI recommends treating workflow exceptions as security events worth reviewing, and reducing single-person authority by requiring dual approval for high-risk transactions such as transfers, account recoveries, and moderation overrides. The report also recommends that fraud and cybersecurity teams share information and coordinate, since these schemes blend policy abuse with technical compromise and can otherwise slip between the cracks. Preparing staff across shipping, telecom, finance, and trust and safety roles to recognize and report recruitment attempts is a key part of reducing this exposure.

Key findings

  • TrendAI describes a “highly structured underground economy” for recruiting corporate insiders, using Telegram and hacking forums.
  • The market includes “brokers, escrow services, and recruitment posts,” connecting employees willing to sell access/data with criminals including scammers and ransomware groups.
  • Recruitment can be two-way: insiders advertise access, and criminals actively solicit employees at target companies.
  • Offers include fixed payments, profit-sharing, and even “referral bonus[es].”
  • Examples include paying insiders to remove social media bans, approve fraudulent refunds, perform SIM swaps to defeat SMS-based MFA, approve transfers, generate shipping labels, or falsify delivery confirmations.
  • One example quote: “$1,000 per day for a FedEx employee capable of uploading tracking information into internal systems.”
  • TrendAI recommends monitoring workflow exceptions as security events and reducing single-person authority via dual approvals.

Who’s being targeted

  • Commonly targeted roles: All employees, Trust & Safety / Content Moderation, Ad Operations, Telecom Customer Service and Provisioning, Finance (approvals/transfers), Shipping & Logistics Operations, Fraud team, Security team, HR (insider risk awareness).
  • Affected industries: Social media / online platforms, Online review platforms, Telecommunications, Financial services, Shipping and logistics, Government / public sector platforms (credential access referenced).
  • Attack channels: telegram.
  • Impersonated: Underground “buyer” claiming to represent a fraud operation, Criminal recruiter offering payment for telecom account actions, Third-party advertiser/agency (actually a criminal) seeking ‘trust & safety’ help.

Red flags to watch for

  • Offer of unusually high pay for a simple internal task
  • Request to use internal systems for non-business purposes (tracking updates/falsified confirmations)
  • Mentions of referral bonuses/escrow typical of illicit marketplaces
  • Request to perform account actions that bypass normal verification steps
  • Pressure to treat security controls/approvals as a formality
  • Payment offered for actions outside job duties
  • Payment tied to internal moderation or enforcement actions
  • Requests that explicitly undermine platform policy (safelisting dodgy ads, removing bans)
  • Unusual pricing per action suggests illicit activity
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How are criminals recruiting corporate insiders?

According to a TrendAI report, criminals use Telegram and hacking forums to run a structured underground economy with brokers, escrow services, and recruitment posts that connect insiders to buyers, including scammers and ransomware groups.

What kinds of payments do insiders receive?

Offers include fixed payments, profit-sharing agreements, and referral bonuses, with one example describing $1,000 per day offered for a FedEx employee capable of uploading tracking information into internal systems.

Which industries and roles are being targeted?

Targeted roles span shipping and logistics, telecommunications customer service, financial approvals, and social media trust and safety teams, since these roles can bypass verification, approvals, or moderation controls.

How can organizations reduce this risk?

TrendAI recommends monitoring workflow exceptions as security events, requiring dual approval for high-risk transactions, and having fraud and security teams share information so these schemes do not slip between the cracks.

Read the video transcript

You’re scrolling Telegram and see this: “FedEx insider needed to upload tracking info, $1,000 per day. Referral bonus.” That’s not a side gig. That’s a crime. TrendAI found a whole underground economy doing this on Telegram and forums, brokers, escrow, even profit‑sharing. They pay insiders to fake delivery confirmations, approve bogus refunds, or do SIM swaps to break SMS MFA. Here’s the trick: it sounds like easy money for a tiny favor, one manual override, one ‘harmless’ approval, one SIM swap. But those workflow exceptions are exactly how scammers and ransomware groups get in. If anyone ever offers cash, profit‑share, or a ‘referral bonus’ to bend our systems, treat it as an attack, screenshot it and report it to Security immediately.

Similar attacks

Fake IT Support Calls in Teams Lead to Ransomware

Fake IT Support Calls in Teams Lead to Ransomware

Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions. After gaining access, the attackers ran commands to download malware and in several cases deployed Chaos ransomware within hours. The…

July 29, 2026
Deepfake OnlyFans Catfish Scam Hits Fans

Deepfake OnlyFans Catfish Scam Hits Fans

Scammers are using AI deepfakes to impersonate real OnlyFans creators on social media and trick fans into paying for “live chats” or exclusive interactions. Victims are funneled from TikTok to private messages (e.g., Snapchat) and then pressured to send money via Cash App, after which the scam…

August 7, 2026
Poipet Scam Ring Used ChatGPT for Romance & Fines

Poipet Scam Ring Used ChatGPT for Romance & Fines

OpenAI says it disrupted a Cambodia-based scam network operating from Poipet that used ChatGPT to scale romance, investment, gambling, and law-enforcement impersonation scams. The group used messaging apps to build trust, then pressured victims to pay deposits, activation fees, or fake fines,…

August 5, 2026
OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on…

August 3, 2026
AiTM Phishing Now #1 Break-In Method for Law Firms

AiTM Phishing Now #1 Break-In Method for Law Firms

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and…

July 31, 2026
Fake IT Support Hits Teams to Drop Ransomware

Fake IT Support Hits Teams to Drop Ransomware

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked into starting remote-control sessions (Quick Assist or RemSupp), after which the attackers used PowerShell to maintain access and, in some…

July 30, 2026