Insider Threat Matrix™Insider Threat Matrix™

External Credential Sharing

A subject discloses, transfers, or otherwise enables the use of their credentials by an external individual, entity, or unauthorized third party, including threat actors, criminal groups, or unaffiliated persons.

This behavior represents a direct breakdown of organizational trust boundaries, extending authenticated access beyond the controlled population. Unlike internal account sharing, which degrades accountability, external account sharing introduces active adversarial risk, enabling unauthorized access, data exfiltration, system manipulation, or persistence within the environment.


External credential sharing may occur through:

  • Deliberate collusion (e.g., financial incentive, coercion, or ideological alignment)
  • Negligent disclosure (e.g., phishing, social engineering, insecure storage)
  • Covert facilitation (e.g., creating shared access channels or maintaining persistent sessions for external use)