logo

Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks

ID: bafc2afe-019b-5b4e-a3b6-f27af8e82014

STIX ID: report--bafc2afe-019b-5b4e-a3b6-f27af8e82014

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-01-16

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

A Jordanian national pleaded guilty to operating as an access broker under the moniker “r1z,” selling unauthorized access to at least 50 victim company networks in 2023, along with malware that disables endpoint detection and response, privilege-escalation tools, and modified pentesting software. An FBI undercover agent purchased access and malware and observed the EDR-killing malware used on an FBI server; investigators linked the actor’s infrastructure to prior intrusions and a June 2023 ransomware attack that caused at least $50M in losses. The suspect was arrested in July 2024, pleaded guilty to trafficking unauthorized access devices and credentials, and faces sentencing with potential imprisonment and fines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.