IntelBroker is a financially motivated cybercriminal threat actor and stolen-data broker active publicly since at least October 2022. The actor is closely associated with BreachForums, where IntelBroker became owner in 2024 after prior law-enforcement disruption and later announced stepping down from that role. In June 2025, U.S. authorities announced charges identifying IntelBroker as 25-year-old British national Kai Logan West, alleging he operated a data brokerage enterprise from December 2022 to February 2025 that caused more than $25 million in damages across more than 40 victims worldwide. Court reporting states the actor primarily exploited security misconfigurations, insecure APIs, stolen credentials, and third-party compromises rather than relying on zero-days, although reporting also links IntelBroker to use of CVE-2024-23897 to obtain credentials and access private GitHub repositories. IntelBroker is known for advertising, leaking, and selling allegedly stolen corporate and government data on criminal forums, often requesting Monero. Reported targets and claimed victims in the provided content include U.S. government-related entities and contractors such as DC Health Link, Acuity, ICE, USCIS, the Department of Defense, the U.S. Army, and Europol, as well as private-sector organizations including Cisco, AMD, Apple, Weee!, Los Angeles International Airport, Hewlett Packard Enterprise, General Electric Aviation, Volvo Cars, Verizon, AT&T, Autotrader, Hilton Hotels, USCellular, Home Depot, and Zscaler. The actor has also been linked to the leak of data affecting PandaBuy together with Sanggiero. Tactics reflected in the content include exploitation of exposed or misconfigured internet-facing resources, abuse of insecure APIs, use of stolen credentials, theft of GitHub credentials from CI/CD infrastructure, access to private repositories, and exfiltration of source code, credentials, tokens, keys, documents, and large datasets containing PII. Multiple incidents in the content involve claims of source code theft, hardcoded credentials, API tokens, AWS buckets, Azure storage data, private keys, and sensitive government or law-enforcement information. IntelBroker has a reputation in the reporting for posting large, often apparently genuine leaks, though some claims remained unverified at the time of publication. Aliases and associated names directly mentioned in the content include intelbroker and IntelBroker. The content also notes claimed operational overlap with the persona "888," but states no definitive public proof establishes whether 888 and IntelBroker are the same individual or share tooling. IntelBroker is also described as affiliated with the group CyberN****** and as having collaborated with Sanggiero in the PandaBuy intrusion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possibly overlapping cybercrime persona associated with monetizing stolen corporate and government data, but not the primary subject of the incident.
Claimed theft of large volumes of Cisco data from a public-facing DevHub environment, including source code, credentials, API tokens, and AWS private bucket data.
Associated in the content with the public posting of DC Health Link breach data to a popular data breach forum.
Allegedly attributed as one of the actors behind the Pandabuy data breach involving the exposure of 1.3M unique email addresses and associated personal/order data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.