IntelBroker is a financially motivated cybercriminal persona and stolen-data broker active since at least late 2022, widely associated with BreachForums and a long series of intrusions, breach claims, and data-leak sales affecting technology companies, telecommunications providers, retailers, government contractors, and public-sector entities. In June 2025, U.S. authorities identified the persona as British national Kai Logan West and alleged that he operated a major cybercriminal data brokerage enterprise from December 2022 to February 2025, causing more than $25 million in damages across more than 40 victims worldwide. IntelBroker also served as a prominent BreachForums moderator and later owner, making the persona highly visible in the cybercrime ecosystem. The actor is best known for monetizing stolen corporate and government data through forum sales, public leak posts, and reputation-building disclosures. Reported and claimed victims linked to IntelBroker include DC Health Link, Europol, Acuity, Cisco, AMD, Apple, PandaBuy, Weee!, Los Angeles International Airport, Hewlett Packard Enterprise, AT&T, Verizon, Volvo Cars, Autotrader, Hilton Hotels, Home Depot, ICE, USCIS, the U.S. Department of Defense, and the U.S. Army. Some incidents were confirmed by victims as limited exposures or credential-based compromises, while others remained unverified claims or were disputed in scope. IntelBroker has also been associated with the group CyberNiggers and has been described as having operational overlap with the persona 888, although public proof of identity overlap is not definitive. IntelBroker’s tradecraft centers on credential abuse, exploitation of insecure APIs and misconfigurations, compromise of third-party environments, and theft from developer and cloud platforms. Public reporting tied the actor to use of CVE-2024-23897 in Jenkins to obtain credentials and pivot into private GitHub repositories, resulting in source-code theft and access to proprietary data. Other incidents involved alleged exploitation of API flaws, CI/CD infrastructure, public-facing developer resources, and stolen credentials to access collaborative or code-hosting environments. The actor has repeatedly targeted repositories, source code, internal documents, tokens, keys, and personally identifiable information, indicating strong post-compromise focus on exfiltration and monetization rather than disruptive destruction. The actor’s targeting pattern shows particular interest in U.S. government-related data and organizations supporting federal missions. IntelBroker has been linked to leaks involving employee or contractor data from agencies including the Department of State, Department of Justice, DHS, FBI, ICE, USCIS, and military-related entities, as well as claims involving Five Eyes material. Europol confirmed unauthorized access to a limited portion of its expert platform and assessed that stolen credentials, not a platform vulnerability, were the likely access vector. Acuity confirmed a breach of GitHub repositories containing dated, non-sensitive information after an incident it attributed to a zero-day vulnerability, while reporting tied IntelBroker and Sanggiero to exploitation of a CI/CD environment and theft of GitHub credentials. IntelBroker has also been repeatedly linked to theft and sale of source code and internal technical artifacts from major technology vendors. In the Cisco case, the actor claimed large-scale theft from a public-facing developer resource exposed by misconfiguration; Cisco acknowledged exposure of files not intended for public download but stated its internal systems were not breached. In the Apple case, IntelBroker claimed access to internal tools; subsequent analysis indicated the leak consisted of proprietary plugins and configurations supporting internal authentication integrations rather than full source code for the named tools. AMD likewise acknowledged investigating IntelBroker’s claims of stolen internal data. The persona’s dominant motivation is financial gain. Court filings and reporting describe a business model based on selling stolen datasets, brokering access, and using high-profile leaks to build credibility in underground markets. Although some commentary has speculated about disruptive or geopolitical dimensions because of the actor’s government-related targeting, the strongest corroborated pattern is monetization of stolen information and access. No high-confidence evidence in the supplied facts establishes IntelBroker as a ransomware operator, despite one secondary claim linking the persona to an “Endurance Ransomware” name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possibly overlapping cybercrime persona associated with monetizing stolen corporate and government data, but not the primary subject of the incident.
Claimed theft of large volumes of Cisco data from a public-facing DevHub environment, including source code, credentials, API tokens, and AWS private bucket data.
Associated in the content with the public posting of DC Health Link breach data to a popular data breach forum.
Allegedly attributed as one of the actors behind the Pandabuy data breach involving the exposure of 1.3M unique email addresses and associated personal/order data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.