skip to content

An access broker listed your VPN account for sale weeks before the extortion - how were you chosen?

level: seniorimportance: should knowfreq 44%

answer

  1. selected twice, by two different parties
  2. sellability first, margin second
  3. you were inventory, not a target
  4. the listing outlives the foothold
  5. make the access unsellable, not just closed

basics

~20 s

You were selected twice by two different parties: a broker picked you because your access was sellable, then a buyer picked your listing because the price fitted their margin. Neither selection was about you specifically.

solid answer

~50 s

When entry is purchased, victim selection is split from the intrusion. The broker's selection criterion is sellability - a credential or exposed service that works, in an organisation whose revenue and sector make the listing worth something. The affiliate's criterion is margin: they buy from available inventory at a price their expected payout supports. So "why us" has an economic answer, not a strategic one: you were inventory. Two practical consequences. First, the entry route tells you about the broker's stock, not about the crew's capability - a sophisticated operation can begin with a purchased password, and a clumsy one can begin the same way. Second, the exposure predates the extortion by weeks or months, and the same access may have been sold to more than one buyer, so removing the encryptor's foothold does not retire the listing.

go deeper

for a junior

Know that a way in can be bought as a separate product, so the party that broke in and the party that extorted may be different, and neither necessarily picked you for who you are.

for a middle

Explain the two selection filters - the broker's sellability and the buyer's margin - and why that makes the entry route a statement about available inventory rather than about the operator.

for a senior

Show the operational consequences: date the exposure from the harvest, treat the listing as possibly multi-sold and still live, and judge capability only from the phase the affiliate actually performed.

for a principal

Own the argument that spend belongs on making access unsellable - phishing-resistant authentication, no single-factor reachable remote access, suppliers held to the same bar - because that subtracts the supply layer the whole market depends on.

## Two selections, neither of them about you When an extortion begins with purchased access, at least two independent parties made a selection before anyone had an opinion about your organisation. **Selection one - the broker.** The broker is not hunting a target; they are building inventory. They collect access at scale through whatever is cheap and repeatable, and they keep what works. Their filter is *sellability*: does this credential still authenticate, does it reach something useful, and can I describe the victim in a way that supports a price? Listings are typically priced on the victim's revenue, country and sector, because those predict what the eventual buyer can extract. **Selection two - the affiliate.** The affiliate is shopping. They have a rented platform, a revenue split to satisfy and a cost of time. They buy from what is listed at a price their expected payout supports. A larger victim justifies a higher price and more patience; a smaller one has to be cheap and fast to be worth the same week of work. The brand whose encryptor eventually runs made no selection at all. ## What this changes about the questions people ask after an extortion **"Were we targeted?"** In the ordinary case, not in the sense the question means. You were sellable, then you were affordable. That is a real answer, and it is more useful than a story about being singled out, because it tells you what to remove: the property that made you listable. **"What does the entry route say about how good they were?"** Almost nothing. Purchased access decouples entry difficulty from operator skill in both directions. A very capable operation can start with a password someone else harvested; an inept one can start with the same thing. Judge capability from what happened *after* entry, not from how entry occurred. **"Is it over now that we have removed their foothold?"** Removing what the affiliate used does not retire the broker's product. Access can be listed for months, can be sold more than once, and is often more than one credential from the same harvest. The property that made the access sellable - a reusable password, an internet-reachable remote service with no phishing-resistant second factor, a supplier's account into your estate - is what has to change, not just the single account that was used. ## The timeline that catches people out The economically important date is not the day the encryptor ran; it is the day the access became sellable. That is often weeks or months earlier, and it may predate the affiliate's involvement entirely. So the window in which the estate was exposed is bounded by the harvest, not by the extortion. It also means the same harvest may have supplied several listings against your organisation - or against your suppliers, which is how third-party access becomes your problem. ## The control-class reading Because the market has to *list* access before it can be bought, the controls that bite hardest are the ones that stop access from being sellable at all: - **Phishing-resistant authentication** (FIDO2/WebAuthn) makes a harvested password worthless as a listing, because possession of the secret is no longer sufficient to authenticate. - **No internet-reachable single-factor remote access** removes the most reliably resellable class of listing. - **Supplier and contractor access held to the same bar** closes the route where the listing is against someone else and the value is your estate. Each of those takes away something the purchase depends on and cannot be substituted for cheaply. Controls aimed at the last step of the chain, by contrast, arrive after the buying decision, the entry and the traversal have all already happened. ## The sentence to have ready "Entry was a purchased good. A broker selected us for sellability and an affiliate selected our listing for margin, so the entry route describes the broker's stock rather than the crew's capability - and the exposure starts at the harvest, not at the encryptor."

  • Why does removing the account that was used not close the exposure?
    Because the product being sold was the class of access, not that one account. The same harvest usually yields more than one credential, a listing can be sold to more than one buyer, and it can sit unsold for months. Until the property that made the access sellable changes - reusable secrets, single-factor reachable remote access - the inventory can be replenished.
  • When would purchased entry not be the right assumption?
    When the entry itself required something not obtainable at wholesale - a capability spent against your specific estate, or an approach that only pays off against you. Broker inventory is by definition generic and repeatable, so an entry route that cannot be mass-produced is the signal that selection was made about you rather than about a price.
  • How does purchased access distort a judgment about the crew's sophistication?
    It removes entry from the evidence entirely. The affiliate bought that step, so its ease or difficulty reflects the broker's harvesting, not the buyer's ability. Sophistication has to be read from the parts they actually performed: how they crossed the estate, how much they understood about what mattered, and how deliberate the endgame was.

It is a wholesale market: one party collects stock that can be sold, another buys whatever fits their margin that week. The shop did not choose you; your item simply had a price.

saying these in an interview costs you the question

  • Reads the entry route as evidence of the crew's capability
  • Assumes the organisation was specifically singled out
  • Dates the exposure from the encryptor rather than the harvest
  • Closes one account and calls the access retired
  • Thinks the ransomware brand chose the victim

context