---
title: "How One Criminal Tried to Sell an MSP on the Dark Web"
url: https://daily.dev/posts/how-one-criminal-tried-to-sell-an-msp-on-the-dark-web-rnvzy6poj
source_url: https://www.huntress.com/blog/how-one-criminal-attempted-to-sell-an-msp-on-the-dark-web
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:08.956Z
updated: 2026-05-31T09:03:10.961Z
tags: ["cyber", "ransomware", "phishing"]
reading_time: 11
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How One Criminal Tried to Sell an MSP on the Dark Web

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 11 min read · 0 upvotes · 0 comments

## Summary

Huntress recounts a real-world incident where a cybercriminal (later identified as a disgruntled ex-employee) attempted to sell access to a compromised MSP's VPS control panel on the dark web for $600 BTC. The Huntress team, working through an MSP-ISAC Slack community with Datto and ConnectWise, directly engaged the attacker undercover on Wickr to extract enough details to identify and warn the victim MSP. Key takeaways include the importance of threat intel sharing between vendors, auditing admin accounts after employee departures, enforcing MFA, and avoiding exposed RDP. The attacker was later arrested in Atlanta and identified as a former employee of the victimized MSP with poor operational security.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/how-one-criminal-attempted-to-sell-an-msp-on-the-dark-web>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#ransomware](https://daily.dev/tags/ransomware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/how-one-criminal-tried-to-sell-an-msp-on-the-dark-web-rnvzy6poj)
