logo

How One Criminal Tried to Sell an MSP on the Dark Web

ID: df35f787-2ccd-5b6d-8b11-06f4ee25ccb4

STIX ID: report--df35f787-2ccd-5b6d-8b11-06f4ee25ccb4

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress documents an active cybercriminal who sold access to an MSP's control panel on the dark web after obtaining credentials via phishing; investigators engaged the seller, traced the access to an MSP (and to an alleged ex-employee), coordinated with vendors to notify and remediate the victim, and emphasize defensive measures (MFA, avoid exposed RDP, phishing awareness) and the value of intel-sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.