Initial access broker
A criminal specialist who breaks into organizations and sells that access to others, such as ransomware crews.
The criminal economy has specialized. One group harvests credentials and establishes footholds, then sells verified access by size, sector, and revenue. The buyer does the extortion.
This is why the time between a credential leaking and a ransomware event can be months, and why a compromised account that seems to do nothing is not a false alarm. It may simply be inventory that has not been sold yet.
Where this comes up
Initial access broker sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.