Jordanian national pleads guilty to selling access to at least 50 company networks

THE BRIEF
According to CyberScoop’s report on Justice Department court records, Feras Khalil Ahmad Albashiti, a 40-year-old Jordanian national, pleaded guilty on Jan. 15, 2026, to operating as an access broker. Authorities said he broke into at least 50 company networks in 2023 by exploiting two commercial firewall products and sold unauthorized access on a cybercrime forum under “r1z.” An undercover FBI agent bought access to victim networks in May 2023 and communicated with Albashiti for five months, court records said. The investigation also involved allegations that he sold malware designed to disable endpoint detection and response products from three companies. Authorities said Albashiti demonstrated the malware by using it on an FBI server without knowing the FBI was observing him. The supplied report does not provide sentencing details or identify the companies, firewall products, or affected networks. The allegations and reported plea should therefore be understood in the context of the cited court records and source report.
WHY IT MATTERS
This case illustrates how unauthorized network access can be packaged and resold as a service, rather than used only by the person who obtained it. The reported use of two commercial firewall products highlights the importance of reviewing perimeter-device exposure and patching, while the alleged EDR-disabling malware points to the value of tamper protection and independent detection. The FBI undercover purchase also shows how access-broker activity may be investigated through marketplace interactions. Because the supplied material does not name the affected organizations or products, teams should avoid assuming their own exposure from this report alone.
WHO SHOULD CARE
Security leaders, firewall and endpoint administrators, threat-intelligence teams, incident responders, and legal or compliance staff should care. Organizations using commercial firewall products or EDR should review exposure and control coverage without inferring that their networks were involved.
WHAT TO DO NOW
- Inventory commercial firewall products exposed to the internet and confirm available security updates are applied.
- Review EDR tamper-protection settings and alerting for attempts to disable or impair endpoint defenses.
- Search firewall, authentication, and endpoint logs from 2023 for unusual access or defense-disabling activity, preserving relevant evidence for review.
- Coordinate with legal, compliance, and incident-response teams before treating indicators from this case as evidence of organizational compromise.