
Paul Mansfield at Accenture describes the rapid growth of the dark web’s exploit market, and explains what businesses can do to defend themselves
The dark web has long been a hub for cyber-criminal activity, but over the past year, its vulnerability exploit market has experienced exponential growth, both in scale and in value.
In fact, according to a new Accenture Cyber Threat Intelligence (ACI) report, the number of exploits for sale on dark web forums has surged by over 270% year-on-year, with prices soaring to unprecedented levels. Some highly sought-after exploits are now being listed for as much as $5 million, while others commonly sell for hundreds of thousands of dollars.
Exploits - pieces of code designed to take advantage of software vulnerabilities - have become an essential commodity among cyber-criminals. When weaponised effectively, they can enable everything from ransomware attacks to large-scale data breaches. Prominent ransomware groups are increasingly leveraging exploit code to enhance their campaigns, making this underground market more lucrative than ever before.
One of the most worrying shifts is the rise of dark web brokers. These intermediaries specialise in acquiring and selling exploit code, ensuring a steady supply to buyers. Much like brokers in other industries, they facilitate transactions and ensure a steady supply of high-demand “products” to eager buyers. In some cases, they’re collaborating with insiders at legitimate companies to gain access to sensitive, exploitable code. This adds an alarming layer of sophistication to the threat.
It is an industry that pays well. Many brokers are earning significant profits, selling their wares to affiliates of prolific ransomware groups who can weaponise these tools for devastating attacks. The focus on 1- and n-day exploits - which target vulnerabilities that have been publicly disclosed but not yet patched by all defenders - is particularly concerning.
Threat actors are taking advantage of the short window of opportunity before patches are widely deployed, and the demand for these exploits has exploded. Remote Code Execution (RCE) exploits, in particular, saw a 200% year-on-year increase in 2024. RCEs allow attackers to cause substantial damage without requiring access to the host system - and they are relatively easy to obfuscate, making them even more dangerous.
AI is transforming the exploit market, accelerating the timeline between identifying vulnerabilities and deploying attacks. Large language models are not yet capable of autonomously generating exploit code, but they are already assisting cyber-criminals in streamlining the process. Basic scripting, troubleshooting, and piecing together code fragments are just a few of the ways AI is making the exploit-building process more efficient - and more accessible to a broader range of attackers.
The bar for entry is lower, the speed of development is higher, and the window for defenders to act is shrinking. The focus on n-day exploits is especially concerning, as threat actors can weaponise them even against enterprises with rapid patching cycles.
While exploits dominate dark web marketplaces, another AI-driven trend is quickly gaining traction: deepfakes. ACI’s research found a 223% increase in deepfake-related tool trading on dark web forums. The ability to manipulate and deceive with AI-powered tools has never been more accessible.
In Accenture’s most recent Pulse of Change research, slightly more than half of organisations (53%) report to be completely prepared to defend against emerging threats, including deepfakes and generative AI powered malware. At the same time, and more encouragingly, nearly three in five organisations have implemented cyber-security training in multiple areas to combat phishing attacks or deepfakes.
As these very real threats rise, and tactics evolve, more proactive measures must be taken to keep pace. The rise of AI-driven threats means organisations can’t rely on traditional defence methods alone – and AI and intelligence-driven security programmes are also very much part of the armour a business now needs.
Cyber-criminals are operating at speed, leveraging the latest technologies to exploit vulnerabilities. The good news is that businesses can take action to prevent and detect attacks, which includes:
Most importantly, it’s vital to improve the speed of patching, using intelligence as much as possible, of n-day vulnerabilities.
The dark web exploit market is booming, and organisations must act with urgency and vigilance. A proactive, intelligence-driven approach is the only defence.
Paul Mansfield is Threat Intelligence Lead at Accenture
Main image courtesy of iStockPhoto.com and thomaguery
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543