
By Assaf Morag, Cybersecurity Researcher
Somewhere on the dark web, a threat actor is running a business with published prices, customer reviews, communication channels, and an escrow system, much like legitimate online businesses. It may seem ridiculous, but it is exactly how much of the hacker-for-hire market operates today. This is an underground ecosystem that has transformed offensive cyber capabilities into a service that can be discovered, purchased, and outsourced on demand.
For decades, the idea of a “hacker-for-hire” has occupied a unique place in cybercrime folklore. Popular culture portrays shadowy individuals capable of breaking into any account, stealing any information, or disrupting any target for the right price. Most published research on hacker-for-hire has focused on the high-end firms that target journalists, lawyers and executives. Far less attention has gone to the storefronts where ordinary buyers go shopping.
To better understand the hacker-for-hire ecosystem, we analyzed discussions, advertisements, and service offerings collected from underground communities and dark web sources available through Flare. Our research reveals a surprisingly structured marketplace where operators advertise services ranging from account compromise and surveillance to reputation attacks and corporate espionage.
Key Findings About the Hacker-for-Hire Market
- The hacker-for-hire market is more mundane than its reputation suggests. Most offerings are not elite, targeted operations but a predictable menu of account compromise, surveillance, and information gathering.
- Sellers mimic legitimate business practices to build trust. Pricing lists, customer reviews, escrow services, and reputation systems are standard across dark web marketplaces, underground forums, and Telegram channels.
- Demand is driven by personal crises, not sophisticated crime. Among the Reddit requests we reviewed, most came from non-technical people dealing with breakups, infidelity suspicions, or account lockouts, not organized criminals.
- Trust is the market’s central weakness. Both buyers and sellers operate with no legal recourse, which exposes both sides to scams, exit fraud and extortion, exit fraud, and post-transaction extortion.
- While open-source publications covered stories and the market for corporate espionage, we haven’t seen any posts that openly discussed or offered that. It may resemble a private-sector version of an advanced persistent threat (APT) campaign, aimed at financial gain rather than geopolitical objectives.
How Flare Can Help
Gain Visibility Into the Underground Services Targeting Your Organization
Hacker-for-hire activity is scattered across hundreds of underground forums, dark web sites, encrypted messaging platforms, paste sites, and social media communities. Flare continuously collects, indexes, and analyzes data across the deep and dark web, aggregating this fragmented ecosystem into a single platform so your team can identify emerging threats and detect malicious services targeting your brand, executives, employees, and assets.
What Is a Hacker-for-Hire Service?
In one of the most iconic and memorable scenes in The Godfather, singer Johnny Fontane wants a film role that producer Jack Woltz refuses to give him. He takes the problem to Don Corleone, a Mafia boss, and Woltz wakes up to find the severed head of his prized horse in his bed. The scene demonstrates what happens when a powerful client (singer Johnny Fontane), outsources the criminal, outcome driven action to Corleone (Mafia boss), to target Woltz (producer who won’t give Fontane the role).

The iconic godfather scene
Modern hacker-for-hire ecosystems operate on a surprisingly similar principle (minus the horse). Instead of sending enforcers, clients hire cyber mercenaries to compromise accounts, steal information, disrupt operations, or intimidate targets online. Anyone with offensive hacking skills and a willingness to work for pay can become a service provider.
At its core, a hacker-for-hire service involves one party paying another to conduct unauthorized digital activity against a target: a spouse, a business competitor, a corporation, a social media influencer, or anyone else the buyer wants to target.
The services can range from simple task to complex, and they tend to fall into consistent categories:
- Intelligence collection: reconnaissance, OSINT, etc.
- Social engineering: phishing, smishing, vishing, etc.
- Hacking: social media, email, device, network, etc.
- Disruption: DoS, DDoS
- Custom: an open invitation to “challenge me and we will negotiate the price”
Below you can observe one of the Tor sites, offering various hacking services:

The Hacking Project’s Tor site

Offerings listed on The Hacking Project’s website
Let’s Hire a Hacker
We started by searching for “hacker for hire” or “hacker-for-hire” in Flare.

Our initial search
We discovered almost 40,000 records. After data cleaning and analysis, about 87% of the records were relevant, so we split the relevant subset into two clusters:
- Only 30 who were actively seeking services (about 0.1% of records): These are users looking for someone to perform an attack, compromise an account, investigate a spouse, recover access, or conduct some form of unauthorized activity. Examples posts include “Need hacker” or “Looking for someone to hack Instagram/Facebook/Telegram”
- Almost 34,000 were offering services: cyber mercenaries advertising services such as email and social media compromise, account recovery, doxxing, credential extraction, and more.
The 13% of the records that were not relevant included discussions and speculations about the hackers, and tool offerings as a submarket for the hacker-for-hire themselves.

The post is an advertisement offering ethical hacking but also digital access which in a more cleaner language is illegally hacking to these targets on a Telegram channel (Flare link to post, sign up for the free trial to access if you aren’t already a customer)
Note that this section describes what operators advertise and self-claim. None of the offerings were tested, and a meaningful share may likely be fraudulent.
Services Commonly Offered
Based on the advertisements we reviewed, cyber mercenary commercial offerings extend far beyond account hacking. We also saw posts spanning surveillance, credential theft, social media compromise, corporate espionage, various forms of information gathering, and digital coercion.

The post is a self-described red team operator looking for hacker-for-hire work for a fee or a percentage, and claiming access to “various industries” on the forum Dread (Flare link to post, sign up for the free trial to access if you aren’t already a customer)
Account Compromise
One of the most common offerings involves compromising online accounts. Threat actors typically run a targeting phishing, credential stuffing, social engineering, SIM swapping, malware deployment, or token theft operation to break into accounts on platforms such as:
- Email: Gmail, Outlook, Yahoo
- Social media: Instagram, Facebook, X, LinkedIn
- Messaging: Telegram, WhatsApp, Discord

A hacking service for WhatsApp offered on the dark web
Surveillance and Monitoring
Some customers seek persistent access to a target’s digital life (rather than a one-time compromise). Threat actors can do so by hacking an account and/or deploying malware to maintain visibility into a victim’s activities. While the goal is different from account compromise, the methods to achieve it are strikingly similar. This area frequently overlaps with domestic abuse, stalking, and harassment investigations. Common offerings include:
- Email monitoring
- Device surveillance
- Social media tracking
- GPS monitoring
- Communication interception
Doxxing and Information Collection
Doxxing services focus on identifying personal information about targets. Attackers often combine open-source intelligence with illegally obtained data from breaches and underground databases. Information collected may include:
- Home addresses
- Phone numbers
- Family members
- Employment history
- Financial details
- Travel records
- Social media accounts
Denial-of-Service Attacks
DoS and DDoS services are a distinct and much larger market on their own, but many operators who market themselves under the “hacker-for-hire” label also offer DDoS attacks, likely because it adds a more personalized service angle for buyers, including:
- Disrupt websites
- Target competitors
- Extort businesses
- Attack gaming platforms
- Harass individuals

The Tor site offering looks almost like one from a legitimate service provider
Reputation Destruction
These activities often blur the line between cybercrime and information operations. Services may include:
- Social media impersonation
- Account takedowns
- Information leaks
- Coordinated harassment campaigns
- Fake review campaigns
- Defamation operations
Academic Grade Manipulation for Sale
Educational institutions present an attractive combination for attackers, where their IT environments are often less well-funded and protected than those of large enterprises, yet they expose a broad attack surface and may contain significant security weaknesses.
At the same time, demand for unauthorized access can be unusually strong, particularly when a single grade may determine whether a student retains a scholarship, qualifies for admission, or remains enrolled. All three advertisements examined in this section explicitly offer the ability to alter school grades, suggesting the existence of a distinct hack-for-hire market serving “customers” willing to pay for academic record manipulation.
Corporate Espionage
Still rare in threat actors’ advertisements, corporate espionage represents one of the most lucrative segments of the industry. Attackers may leverage phishing campaigns, credential theft, insider recruitment, malware deployment, or cloud service compromise.
A Reuters investigation documented how Indian hack-for-hire firms targeted thousands of lawyers, executives, and companies to obtain confidential emails and privileged documents. The stolen information was used to influence litigation, expose commercial strategies, and provide clients with an advantage in high-value corporate disputes.
In many cases, the operation resembles an advanced persistent threat campaign but is conducted for private financial interests rather than geopolitical objectives. Customers may request:
- Internal documents
- Product roadmaps
- Intellectual property
- Source code
- Customer databases
- Sales pipelines
- Merger information
- Executive communications

Hackers for hire website shows offerings for database hacking services, often targeting SMBs and larger organizations
Interestingly, the rest of the dataset containing the keyword “hacker-for-hire” is linked to “enablers,” which are hacking tools rather than services, such as bulletproof VPS services, account access and credentials. The threat actors marketed a RAT under the promise that buyers were purchasing hacker-for-hire services.
Where Hacker-for-Hire Services Are Found
Finding a hacker-for-hire service is often far easier than many people assume. Over the years, a mature underground ecosystem has emerged around cyber mercenary services, allowing for prospective customers to discover providers, compare offerings, review reputations, and even conduct transactions using mechanisms that resemble legitimate online marketplaces.
We identified four common channels through which hacker-for-hire operators advertise and conduct business: dark web search engines, underground forums, encrypted messaging platforms, and escrow-based marketplaces.
Dark Web Search Engines
Dark web search engines often serve as the first stop for individuals seeking hacker-for-hire services, enabling users to discover marketplaces, forums, service directories, and independent operator websites. Searches for terms such as account recovery, digital investigations, surveillance, or hacking services frequently lead users to underground communities where cyber mercenaries advertise their capabilities, pricing, and contact information, effectively acting as an entry point into the broader hacker-for-hire ecosystem.

An example of Tor search engine results
Underground Forums
Traditional cybercrime forums continue to serve as a major venue where threat actors advertise services, showcase past successes, publish customer reviews, and provide pricing information. Reputation systems play a critical role in establishing trust, with highly ranked and well-established members often commanding premium prices for their services.
Telegram
Telegram has emerged as one of the primary platforms for cyber mercenary activity (with almost 85% of the total posts). This is probably due to its large user base, pseudonymous communication, cryptocurrency-friendly ecosystem, and ease of direct interaction between buyers and sellers. Many operators use dedicated channels and groups to advertise services, showcase successful operations, share customer testimonials, and build credibility within the underground community.

Telegram group for cyber mercenaries
Escrow Services
Many underground marketplaces rely on escrow services to facilitate transactions between buyers and sellers who have no prior relationship or reason to trust one another. These intermediaries temporarily hold funds until the agreed service or deliverable is provided, helping reduce (but not eliminating) fraud and disputes. Scams, impersonation, and exit fraud remain common even where escrow is used, which is why trust remains one of the industry’s most persistent challenges.
The Hiring Process
Based on our observations, hacker-for-hire service acquisition generally falls into two categories:
- Standardized services: operators openly advertise predefined services (such as social media account access, email compromise, surveillance, or information gathering) often with published pricing and customer reviews, making the process feel surprisingly similar to a legitimate e-commerce site.
- Custom engagements: clients present a specific target or objective and the operator provides a custom quote based on the complexity of the request.

Price list based on “job” size
In both cases, transactions frequently rely on cryptocurrency and underground escrow services to help build trust between strangers. Once an agreement is reached, the operator carries out the requested activity. While the escrow is designed to verify that the hacker delivers the agreed-upon results, we don’t have supporting data to verify this. In reality, hackers can fake an entire website and supporting escrow system to defraud their victims. The provided services can range from account access and collecting information to documents, screenshots, or other evidence requested by the client.



The HackTeam Tor site price list
What About the Demand Side?
So far we have mainly focused on supply. But who is actually buying these services, and why?
To answer that, we looked for ordinary people seeking hacking services, and found them across platforms including Facebook, X, Telegram, Reddit, and more.
We focused on Reddit and analyzed 20 relevant posts from the past year. The requests were largely personal and emotional rather than tied to sophisticated cybercrime operations. Users frequently sought help accessing a spouse’s messages, investigating suspected infidelity, recovering lost accounts, retaliating against individuals who had compromised their accounts, or obtaining information they believed was otherwise inaccessible.

Reddit post recommending a hacker who can hack to spouse’s social media
Many requests appeared to come from individuals with little or no technical expertise, highlighting how hacker-for-hire services effectively lower the barrier to conducting unauthorized cyber activities. They don’t need to know how to hack; they just need to know how to find and pay someone who does.

Reddit post about someone hacking into an account and seeking a hacker to gain access again
The demand side of the market is driven by a combination of curiosity, revenge, desperation, financial motives, and perceived injustice. Some users sought evidence for divorce proceedings or relationship disputes, while others wanted to regain access to compromised gaming, social media, or email accounts.
In several cases, individuals explicitly asked where they could find a trustworthy hacker, what such services should cost, and how to avoid scams. This suggests that for many customers, the challenge is not performing the attack themselves, but rather identifying someone willing and claiming to be capable of carrying it out.

Reddit post seeking a hacker to (allegedly) hack a website
Many advertisements exploit these emotional circumstances by presenting cyber mercenary services as a quick solution to personal problems. Operators frequently market account access, surveillance, monitoring, and information-retrieval services directly to individuals experiencing relationship issues, disputes, or account losses. This dynamic reinforces the broader trend observed throughout the underground ecosystem: hacker-for-hire services are increasingly marketed not as highly technical cybercrime operations, but as accessible, consumer-like services aimed at non-technical customers seeking a shortcut to information, access, or retribution.
Trust is the Biggest Challenge
Trust is arguably the hardest problem within the hacker-for-hire ecosystem. Unlike legitimate service providers, neither side has any real assurance that the other will honor the agreement.
Buyers must determine whether:
- the advertised service is genuine
- the operator is capable of delivering the requested outcome
- their funds will simply disappear
At the same time, operators face their own concerns, including the possibility that a prospective customer is an undercover law enforcement officer, a scammer, or someone seeking to involve them in a politically sensitive operation.
To address these concerns, underground communities have developed mechanisms that closely resemble those found in legitimate marketplaces, including:
- escrow services
- reputation systems
- customer reviews
- verified vendor programs
- referral networks
Despite these safeguards, fraud remains widespread like the Telegram avatar where the operator flags impersonator accounts as scammers. Many hacker-for-hire advertisements are scams, with customers paying significant sums only to receive nothing in return. In some cases, the relationship itself becomes a risk: once a customer reveals their intentions, the operator may attempt to extort additional payments by threatening to expose conversations or evidence of the request. Buyers also face the possibility of becoming victims themselves, with unscrupulous operators stealing credentials, cryptocurrency, or personal information from their own customers. Beyond the immediate financial loss, exposure can lead to reputational damage, civil lawsuits, criminal investigations, or employment consequences.
Operators face their own risks: increasing pressure from law enforcement agencies that routinely monitor underground communities and conduct undercover operations. International cooperation has made it significantly easier to investigate and prosecute cyber mercenary activity across borders like in the case of Aviram Azari, who was sentenced in the US in 2023 for a hack-for-hire phishing operation, and the UK and France-led Pall Mall Process (2024). In addition, disputes with customers can quickly escalate, particularly when expectations are not met or promised results fail to materialize. Because reputation is a critical asset in underground markets, negative reviews, public accusations, and doxxing campaigns can have a direct impact on future business. As a result, trust remains both the foundation and the greatest weakness of the hacker-for-hire industry, forcing participants to navigate a marketplace where neither side can fully trust the other.
Recommendations for Security Teams
While these messages may seem irrelevant to organizations because of their somewhat personal and illusive nature, they can still contain important pieces of information, especially if the name of your company or the sector you work in appears as a potential target. Adding this dark web activity segment may support the bigger scope of your threat model.
By automating monitoring for hacker-for-hire activity across hundreds of underground forums, dark web sites, encrypted messaging platforms, paste sites, and social media communities with a platform like Flare, would speed up comprehensive coverage.
- This will help your security team identify emerging threats, monitor discussions related to your brands, executives, employees, or assets, and detect malicious services that may be targeting them.
- You can also gain context around threat actor activity, underground advertisements, leaked credentials, exposed data, and cybercrime services that may pose a risk to your organization. This allows your team to move from reactive investigations to proactive threat detection, supporting you in identifying potential threats earlier and understanding how your organization may be discussed or advertised within underground communities, especially as targets of corporate espionage, DDoS, and campaigns seeking to damage reputation.
In a landscape where cybercrime increasingly operates as a service economy, visibility into the ecosystems that facilitate these activities is critical for effective threat intelligence and risk management.
Insight into the Availability of Hackers-for-Hire
Our analysis suggests that the hacker-for-hire ecosystem is both smaller and more structured than popular perception might suggest. While the term “hacker-for-hire” evokes images of elite cyber operators capable of infiltrating any target, the majority of observed activity centers around a relatively predictable set of services, including account compromise, surveillance, information gathering, social engineering, reputation attacks, and, in some cases, corporate espionage. Many operators openly advertise their capabilities, maintain reputations, collect customer reviews, and rely on trusted communication and payment channels that closely resemble legitimate e-commerce sites.
The most important takeaway is the accessibility of operators’ services rather than their sophistication. By lowering the technical barrier to entry, hacker-for-hire providers enable individuals with little or no technical expertise to outsource offensive cyber activities against personal, commercial, or organizational targets. As cybercrime continues to evolve into a service-based economy, understanding how these markets operate provides valuable insight into the growing commercialization of digital attacks and the increasingly blurred line between traditional cybercrime, private espionage, and cyber mercenary activity.
How Flare Can Help
Gain Visibility Into the Underground Services Targeting Your Organization
Hacker-for-hire activity is scattered across hundreds of underground forums, dark web sites, encrypted messaging platforms, paste sites, and social media communities. Flare continuously collects, indexes, and analyzes data across the deep and dark web, aggregating this fragmented ecosystem into a single platform so your team can identify emerging threats and detect malicious services targeting your brand, executives, employees, and assets.





