The risk is not just that workers sell logins. It is that senior people are more willing to excuse it, which turns insider threat into a governance problem, not a junior-employee discipline problem. A security program that assumes higher rank means lower abuse risk is missing the point.
Cifas says 13% of employees at large UK companies admitted selling corporate logins or knowing someone who had. The same survey found acceptance rose to 32% for senior managers, 36% for directors, 43% for C-suite executives, and 81% for business owners.
That changes the blast radius. Trusted accounts at the top can unlock internal systems, fraud workflows, and data that lower-trust users cannot reach, and credential reuse makes the exposure persist after the original sale.