Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Correction: The online persona is commonly spelled IntelBroker, not “InteBroker.” On June 25, 2025, the U.S. Department of Justice announced charges against British national Kai West, whom prosecutors identify as IntelBroker and “Kyle Northern.” West was arrested in France in February 2025, and the United States was seeking his extradition. He has been charged, not convicted.

Prosecutors allege that West and co-conspirators broke into computer systems, stole data, advertised it on a cybercrime forum, and caused more than $25 million in losses or damages. That figure is not the amount West allegedly earned: prosecutors separately say conspirators sought more than $2 million from data sales, while listed asking prices in approximately 16 posts totaled at least $2.467 million.

Who is Kai West, and what is IntelBroker?

The DOJ identifies Kai West as a 25-year-old British national also known online as “IntelBroker” and “Kyle Northern.” The government alleges that West operated the IntelBroker identity and participated in a cybercrime scheme that ran approximately from December 2022 through February 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IntelBroker was an online criminal persona associated with BreachForums, a marketplace and distribution channel for stolen data. It should not automatically be treated as the name of a formal company or a single-person hacking group. Prosecutors allege collaboration with other actors, and the public record does not establish that West personally carried out every breach attributed to the IntelBroker name.

From approximately August 2024 through January 2025, the identity was reportedly labeled the forum’s “owner.” That label may have enhanced IntelBroker’s reputation, but it does not by itself prove that West had full technical or operational control of BreachForums, or responsibility for every activity on the site.

What prosecutors allege

According to the indictment and complaint, West and co-conspirators compromised company computer systems and removed information including customer lists and company marketing data. The stolen material was allegedly offered for sale, distributed without charge, or exchanged for forum credits.

The charging materials refer to an online hacking group as “CyberN[redacted]” and to a forum as “Forum-1,” widely understood in reporting to refer to BreachForums. The DOJ alleges that activity affected dozens of victims worldwide, including more than 40 referenced in its announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The numbers in the case

Figure What it means
More than $25 million Alleged cumulative losses or damages suffered by victims.
More than $2 million Amount prosecutors say conspirators sought through data sales.
At least $2.467 million Combined asking prices listed in approximately 16 public posts.
Approximately 158 threads Public threads allegedly started by West involving sales, free distribution, or forum-credit exchanges.
41 threads Alleged offers to sell hacked data.
117 threads Alleged free or forum-credit-based offers.

These figures describe allegations and public offers, not necessarily completed transactions. An advertised asking price is not proof that anyone paid it, and the number of posts is not the number of successful intrusions. Likewise, the alleged $25 million in damages is not a “$25 million haul” received by West.

Which breaches were linked to IntelBroker?

IntelBroker’s name appeared in connection with numerous alleged compromises. Their evidentiary status differs substantially. A forum post can establish that the persona made a claim or offer; it does not independently prove that the advertised data was authentic, complete, or obtained by IntelBroker.

Organization or incident What is publicly reported How to interpret it
DC Health Link IntelBroker was associated with a March 2023 incident involving the health-insurance marketplace serving members of Congress and congressional staff. Data reportedly offered included personal information. The DOJ charging materials describe an unnamed municipal healthcare provider and a March 6, 2023 post offering patient information such as names, Social Security numbers, birth dates, gender, health-plan information, and employer information. Identifying that victim as DC Health Link should be attributed to secondary reporting, not presented as an explicit naming by the DOJ release.
Cisco DevHub Reporting linked IntelBroker to an alleged 2024 compromise of Cisco’s public-facing DevHub portal and a later offer of data. The full scope, authenticity, and sensitivity of the material claimed by IntelBroker should not be assumed without an authoritative victim statement or independent validation.
Hewlett Packard Enterprise IntelBroker reportedly claimed in January 2025 to have stolen confidential HPE data. A claim by the persona is not confirmation that HPE suffered a breach or that the advertised data was genuine.
AMD, Apple, Europol, T-Mobile and Home Depot Secondary coverage associated the IntelBroker name with these organizations. The references should be treated as reported claims or associations unless supported by company disclosures, court documents, or reliable independent analysis.

Dark Reading’s coverage provides context on the reported victims and cautions around the persona’s claims. A useful evidence hierarchy is: court documents for prosecutorial allegations; victim disclosures and regulatory filings for confirmed incidents; independent threat-intelligence analysis for authenticity and attribution; reputable reporting for chronology; and the actor’s own posts as evidence of claims rather than proof.

How investigators allegedly identified IntelBroker

The charging materials describe attribution as a combination of financial, account, technical and behavioral evidence—not simply a case of “cracking” a privacy-focused cryptocurrency.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Investigators allegedly traced a cryptocurrency payment to a Coinbase account linked to West.
  • Email accounts and related financial or personal records allegedly connected West to the IntelBroker identity.
  • Investigators allegedly found overlap between IP-address activity associated with West’s personal accounts and accounts used by IntelBroker.
  • The complaint also describes online-account behavior, language, travel information and identity evidence supporting the attribution.

The DOJ says IntelBroker accepted Monero, while the reported investigation included a payment connected to Coinbase. The public materials do not establish that Monero itself was “cracked” or that every transaction was traceable. The narrower lesson is that privacy-oriented payment methods do not erase risks created by exchange records, account reuse, IP exposure, operational mistakes, or investigative cooperation.

The case also depended on international cooperation. The DOJ credited authorities in France, Spain, the United Kingdom and the Netherlands.

What charges does West face?

The charges were announced by the U.S. Attorney’s Office for the Southern District of New York. The case was assigned to Judge Katherine Polk Failla. The four counts and stated statutory maximums are:

  1. Conspiracy to commit computer intrusions: up to five years in prison.
  2. Conspiracy to commit wire fraud: up to 20 years.
  3. Accessing a protected computer to obtain information: up to five years.
  4. Wire fraud: up to 20 years.

These are statutory maximums, not a prediction of a sentence. Any eventual sentence would depend on the outcome of the case, sentencing rules, relevant conduct, judicial findings and other factors. The DOJ explicitly states that the charges are allegations and that West is presumed innocent unless proven guilty.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does the arrest mean for BreachForums and cybercrime?

IntelBroker’s prominence illustrates how reputation can function as infrastructure in underground markets. A forum role, a history of posts and claims of access can make buyers more willing to believe that a seller has valuable data. Free releases and forum-credit exchanges can also serve as advertising, helping an actor build credibility before attempting larger sales.

Removing an alleged prominent operator may undermine trust among criminals and prompt other actors to reconsider their anonymity and operational security. That is an informed possibility, not a measured outcome established by the case.

The arrest does not eliminate the stolen data, other alleged participants, copycats or demand for illicit information. Cybercrime forums can migrate, rebrand or re-form elsewhere. Nor does one arrest prove that an entire group has been dismantled.

What remains unknown

  • Whether West was extradited to the United States after the February 2025 arrest in France.
  • Whether the case resulted in a plea, trial, conviction or sentence.
  • Which advertised breaches were genuine, complete or directly attributable to West.
  • How much money, if any, West or his alleged collaborators actually received.
  • How much operational control West exercised over BreachForums.
  • The identities and precise roles of all alleged co-conspirators.

The public materials covered here do not establish a conviction, final extradition outcome or final disposition. “Arrested” and “charged” should not be converted into “convicted,” and “claimed breach” should not be converted into “confirmed breach.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What organizations should take from the case

For a company whose data appears in an underground-market post, the correct response is verification and containment—not assuming that every claim is either true or false.

  • Preserve evidence: retain relevant logs, authentication records, endpoint data, cloud audit trails and copies of the alleged post through approved forensic procedures.
  • Validate the exposure: compare advertised samples with internal records and determine whether the material is current, authentic and unique.
  • Assess affected people: identify exposed credentials, personal information, tokens, customer records and business-sensitive data.
  • Coordinate carefully: involve incident-response specialists, counsel, insurers, regulators and law enforcement as appropriate.
  • Do not negotiate casually: direct contact with criminals can create legal, operational and evidentiary risks.
  • Assume persistence: removing a post or arresting one alleged actor does not guarantee that copied data has disappeared.

For individuals, the practical response depends on whether a credible organization has confirmed exposure. Changing reused passwords, enabling multifactor authentication and watching for identity misuse are sensible defensive measures, but no consumer tool can remove data already copied into criminal channels.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.