Skip to content

Workforce and access social engineering · Also called insider recruitment, bribed employee, bribed support agent, insider threat recruitment, paid insider

Insider bribery and recruitment

Insider bribery is when criminals pay or recruit a company's employees or contractors to misuse their access, for example by copying customer records or installing malware. The criminals then use the data to extort the company or to trick its customers, while the bribed insider takes the blame and the legal risk.

How it works

  1. Criminals approach employees or contractors, including support staff with access to customer systems, online or in person.
  2. They offer money, sometimes a large sum in cryptocurrency, for a special project such as collecting customer data or running software on the company network.
  3. The data is taken out, or malware provided by the criminals is installed to steal it.
  4. The criminals demand payment from the company not to publish the data, and may use it to impersonate the company to its customers.

Red flags

If you are targeted

Where to report, by country

Prevention

For individuals

For organisations

Real cases

How official datasets classify it

Questions

Do criminals really bribe employees?
Yes. Coinbase told the SEC in May 2025 that a threat actor appears to have paid support contractors or employees outside the US to collect customer data, then demanded money not to disclose it. In an earlier US case, the Justice Department said a man offered a Nevada company employee a payment in bitcoin to install malware.
What should I do if someone offers me money for access at work?
Refuse, keep the messages, and report it to your security team or management at once. In the Nevada case, the employee reported the approach to the company, which contacted the FBI and the scheme was stopped.

Related scams

Read more