Workforce and access social engineering · Also called insider recruitment, bribed employee, bribed support agent, insider threat recruitment, paid insider
Insider bribery and recruitment
Insider bribery is when criminals pay or recruit a company's employees or contractors to misuse their access, for example by copying customer records or installing malware. The criminals then use the data to extort the company or to trick its customers, while the bribed insider takes the blame and the legal risk.
How it works
- Criminals approach employees or contractors, including support staff with access to customer systems, online or in person.
- They offer money, sometimes a large sum in cryptocurrency, for a special project such as collecting customer data or running software on the company network.
- The data is taken out, or malware provided by the criminals is installed to steal it.
- The criminals demand payment from the company not to publish the data, and may use it to impersonate the company to its customers.
Red flags
- Someone outside the company offers you money for a project that involves your work systems or access.
- You are asked to install software or connect a device that someone outside the company gave you.
- You are asked to look up or export customer records that your job does not require.
- Payment is offered in cryptocurrency, part up front and the rest later.
If you are targeted
- Stop: refuse the offer, take no money, and do not run anything you were given.
- Report the approach to your security team or management straight away, and keep the messages; companies can bring in the FBI or police.
- If your company receives an extortion demand, do not rush to pay; the FBI warns that complying with extortion does not guarantee the data will not be shared.
- Report it to your security team, then to the national service; our Report a scam page lists where, such as ic3.gov in the US.
Prevention
For individuals
- Report any offer of money for access to work systems or data, however it is framed.
- Never install software or plug in devices supplied by people outside the company.
- Only open customer records you need for the task in front of you.
For organisations
- Give support staff and contractors only the access their role requires, and monitor for data access without a business need.
- Run an insider threat programme that defines, detects, assesses, and manages risky behaviour, combining technical monitoring with staff awareness.
- Make it easy and safe for staff to report being approached, and involve law enforcement early.
- If customer data is taken, warn affected customers and add fraud monitoring, because the data can be used to impersonate you.
Real cases
2025-05 · US · Disclosed · $180M estimate
Coinbase support staff bribed to leak customer data, 2025
How official datasets classify it
Questions
- Do criminals really bribe employees?
- Yes. Coinbase told the SEC in May 2025 that a threat actor appears to have paid support contractors or employees outside the US to collect customer data, then demanded money not to disclose it. In an earlier US case, the Justice Department said a man offered a Nevada company employee a payment in bitcoin to install malware.
- What should I do if someone offers me money for access at work?
- Refuse, keep the messages, and report it to your security team or management at once. In the Nevada case, the employee reported the approach to the company, which contacted the FBI and the scheme was stopped.