Identity · 129 days ago
The risk is not just that workers sell logins. It is that senior people are more willing to excuse it, which turns insider threat into a governance problem, not a junior-employee discipline problem. A security program that assumes higher rank means lower abuse risk is missing the point.
Cifas says 13% of employees at large UK companies admitted selling corporate logins or knowing someone who had. The same survey found acceptance rose to 32% for senior managers, 36% for directors, 43% for C-suite executives, and 81% for business owners.
That changes the blast radius. Trusted accounts at the top can unlock internal systems, fraud workflows, and data that lower-trust users cannot reach, and credential reuse makes the exposure persist after the original sale.
4 sources covering this story
One in eight UK Workers has Sold Their Company Passwords, and Bosses Think it's Fine
An uncomfortable number of people appear to be quite willing to sell critical credentials and passwords to the highest bidder.
Your coworker might be selling company logins, and thinks it's fine - Help Net Security
Cifas Workplace Fraud Trends reveals growing acceptance of employee fraud, from expense scams to selling login credentials.
1 in 8 employees totally cool with selling work credentials
13% say they’ve sold logins or know someone who has, survey suggests
One in Eight Workers Has Sold Their Corporate Logins
Cifas says that 13% of employees admit selling company credentials to a former colleague
Part of the PlainSec briefing for 2026-05-09