S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.20
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Insider Recruitment

Human Vector · Co-Opted Access-Holder · Growing
High Alert
How It WorksSEC 01

Insider recruitment persuades, induces, or coerces a person who already holds legitimate access — an employee, contractor, or partner — into abusing that access on an attacker’s behalf. Most social engineering deceives an outsider into becoming a temporary access path; this instead turns an existing, trusted access-holder into a witting collaborator.

Because the recruited insider already carries credentials, system knowledge, and a plausible reason to be where they are, their malicious actions blend into normal activity — making this one of the hardest threats to detect and among the most damaging. Attackers reach candidates through documented levers a defender should recognize: direct solicitation (increasingly via messaging-app and dark-web “help wanted” posts offering payment for access), a disgruntled employee’s grievance, financial pressure, ideological appeals, or coercion and blackmail.

Counterintelligence practitioners summarize insider motivations with the mnemonic MICE — Money, Ideology, Coercion/Compromise, Ego. For a defender this is not a playbook but a risk lens: it names the pressures that make an access-holder vulnerable, which is exactly what insider-threat programs monitor for. The defining feature for recognition: harm delivered through a legitimate access-holder acting outside their authorized purpose.

Warning SignsSEC 02
  • Access outside role or need-to-know. Reaching systems or data the person's job doesn't require, or using workarounds that avoid logging and controls.
  • Anomalous timing and volume. Downloads or access at unusual hours, in a rush, or spiking just before a resignation.
  • Grievance or disgruntlement. Expressed resentment or perceived injustice, or unusual secrecy about work activity.
  • Unexplained affluence. A lifestyle or spending change inconsistent with known income.
  • Contact offering payment for access. Undisclosed outside contacts or side arrangements — including an approach soliciting internal access.
  • Resistance to oversight. Attempts to bypass separation-of-duties, work alone on sensitive processes, or dodge review. No single sign is proof; the pattern is.
Frequently Paired WithSEC 03
  • Pretexting · T14.1
    The approach is often a pretext plus inducement
  • Privilege / Access Abuse · T20.20
    The co-opted insider's actual action
  • Quid Pro Quo · T14.11
    Bribery-flavored inducement, the exchange lever
  • Coercive Control / Blackmail · Cat 22
    The coercion/compromise vector
How the Attack UnfoldsSEC 04
  • Stage 01 · Pressure Point
    An access-holder under money pressure, grievance, coercion, or ego needs becomes a point of leverage.
  • Stage 02 · Escalation
    Small first steps ("just look something up") normalize and grow into larger complicity, quieted by rationalizations.
  • Stage 03 · Abuse of Access
    Legitimate access is used outside its authorized purpose — data leaves, controls fall, fraud clears — blending into normal activity.
Counter-ProtocolSEC 05
Defense: Make co-option hard, single-handed abuse impossible, and abuse quickly visible.
  • Least privilege and need-to-know. Grant access strictly to what the role requires so a single insider can reach little.
  • Separation of duties and dual control. Require a second approver for high-value actions so no one can act alone.
  • Audit and monitor. Log privileged access and data movement, baseline behavior (UEBA), and verify high-risk transactions out-of-band.
  • Support people, don't just watch them. A governed, legally-reviewed program with grievance and wellbeing channels reduces motivation, not just detection.
  • Harden the lifecycle and reporting. Immediate offboarding, access recertification, and a blame-aware channel to report a suspicious approach.