> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals
- URL: https://darkwebinformer.com/buyer-solicits-corporate-network-access-to-350m-western-firms-excluding-cis-schools-and-hospitals/
- Published: 2026-07-31T17:11:57.000Z
- Updated: 2026-07-31T17:11:57.000Z
- Author: Dark Web Informer
- Tags: Initial Access

Access Wanted Multi-Region Initial Access Market Buyer Advertisement 

## Buyer Solicits Corporate Network Access to $350M+ Western Firms, Excluding CIS, Schools and Hospitals

A buyer posting as **umbreon** is advertising to purchase **corporate network access** on flat-rate terms, setting out unusually specific selection criteria. Targets must sit in the **US, Canada, UK, Switzerland, France, Australia, or Ireland** and hold **verified annual revenue above $350 million**, and the access must be exclusive and previously unsold. Accepted routes include **VPN, RDP, Citrix, VDI, RMM, Active Directory, and Entra, AWS, Okta or Oracle identity systems**. The buyer explicitly refuses **CIS-region targets, schools, and hospitals**, while stating that healthcare, pharmaceutical, and biotech companies are acceptable. No breach is claimed; this is a **demand-side listing**.

Severity MODERATE 

Revenue floor$350M+

Regions7 Western

ExcludesCIS states

Actorumbreon

### ▣Listing details

TypeBuying, not selling

Regions soughtUS, CA, GB, CH, FR, AU, IE

Revenue floor$350M+ verified

TermsFlat-rate buyout, escrow

ExclusivitySingle buyer, unsold only

RefusedCIS, schools, hospitals

ObservedJul 31, 2026

Actorumbreon

### !Access sought

- VPN
- RDP
- Citrix
- VDI
- RMM platforms
- Active Directory
- Microsoft Entra
- AWS
- Okta
- Oracle Identity Manager

### ◱Screenshot

[ ![Initial access broker buying advertisement for corporate network access, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/257629857369872659876235265362.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/257629857369872659876235265362.png) 

### ⚠Potential impact

No organisation has been compromised here, but the criteria describe **who is being hunted**. A revenue floor screens for ability to pay rather than for data value, which is **ransomware victim selection** rather than data theft. The blanket **CIS exclusion** is the long-standing signature of Russian-speaking operations avoiding local prosecution. Refusing schools and hospitals while accepting pharmaceutical and biotech firms reflects **reputational risk management, not restraint**. The routes sought, particularly RMM and identity platforms, are chosen because they enable estate-wide deployment. Large Western firms in these sectors should read this as a statement of intent.

### iStatus

Advertisement 

This is a solicitation rather than an incident, so there is nothing to verify beyond the post itself. The account was **created days ago with a single post**, though a purchased premium rank and the use of forum escrow convention suggest familiarity with the market. Dark Web Informer is not reproducing the contact identifier. Whether the buyer is operational or merely aspirational cannot be established.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE