Insider recruitment persuades, induces, or coerces a person who already holds legitimate access — an employee, contractor, or partner — into abusing that access on an attacker’s behalf. Most social engineering deceives an outsider into becoming a temporary access path; this instead turns an existing, trusted access-holder into a witting collaborator.
Because the recruited insider already carries credentials, system knowledge, and a plausible reason to be where they are, their malicious actions blend into normal activity — making this one of the hardest threats to detect and among the most damaging. Attackers reach candidates through documented levers a defender should recognize: direct solicitation (increasingly via messaging-app and dark-web “help wanted” posts offering payment for access), a disgruntled employee’s grievance, financial pressure, ideological appeals, or coercion and blackmail.
Counterintelligence practitioners summarize insider motivations with the mnemonic MICE — Money, Ideology, Coercion/Compromise, Ego. For a defender this is not a playbook but a risk lens: it names the pressures that make an access-holder vulnerable, which is exactly what insider-threat programs monitor for. The defining feature for recognition: harm delivered through a legitimate access-holder acting outside their authorized purpose.