#IntelBroker
🚨 French police dismantle BreachForums leadership network

French authorities arrested four suspected #BreachForums administrators, including #IntelBroker, marking one of the largest coordinated actions against the cybercrime marketplace.

🔗 read more: www.infosecurity-magazine.com/news/french-...
July 1, 2026 at 10:01 AM
In what is becoming a rather tiresome weekly tradition, Zscaler confirmed that a threat actor called IntelBroker managed to wander into an isolated test server. While the company insists no customer data was touched and the server wasn't even on their real infrastructure, one won...

Read full story
May 13, 2026 at 5:03 PM
🧐 Confusión en la administración: Aunque nuevos administradores como 'IntelBroker' y 'Anastasia' emergieron, se sospecha que podrían ser solo figuras de fachada, mientras el control real del foro sigue fragmentado.
El administrador de BreachForums busca sustituto que asuma su 'liderazgo y soporte'
El mayor foro de piratas informáticos puede volver a cambiar de gestor (y van unas cuantas ocasiones). Su administrador ha publicado un mensaje en el que anuncia su marcha.
www.escudodigital.com
March 18, 2026 at 10:12 PM
ハッカーがデータ侵害を主張、HPEが調査を開始

Hewlett Packard Enterprise(HPE)は、著名なハッカーであるIntelBrokerがテック大手から機密データを盗み出したと主張していることを受け、調査を開始した。 このハッカーは1月16日、BreachForumsで、HPEのシステムから入手したとされるファイルを販売していると発表した。 データには、ZertoやiLOといった製品のソースコード、非公開のGitHubリポジトリ、Dockerビルド、デジタル証明書が含まれるとされている。…
ハッカーがデータ侵害を主張、HPEが調査を開始
Hewlett Packard Enterprise(HPE)は、著名なハッカーであるIntelBrokerがテック大手から機密データを盗み出したと主張していることを受け、調査を開始した。 このハッカーは1月16日、BreachForumsで、HPEのシステムから入手したとされるファイルを販売していると発表した。 データには、ZertoやiLOといった製品のソースコード、非公開のGitHubリポジトリ、Dockerビルド、デジタル証明書が含まれるとされている。 IntelBrokerはまた、過去のユーザー配送に関する個人を特定できる情報(PII)や、WePay、GitHub、GitLabなどのAPIやプラットフォームを含む複数のHPEサービスへのアクセスも保有していると主張している。 HPEの広報担当者は、同社が侵害の主張を把握していることを報道機関に確認した。しかし、同社の業務への影響はなく、顧客データが侵害された証拠もないという。 HPEは直ちにサイバー対応プロトコルを起動し、関連する認証情報を無効化したうえで、主張の妥当性を評価するための調査を開始したとみられている。 主要組織を標的にすることで知られるIntelBrokerは、Cisco、General Electric、そしてEuropolなどの企業・組織に関わるデータ侵害の経歴がある。 一部の被害者は盗まれたデータの真正性を確認している一方で、実際の影響はハッカーが示唆したほど深刻ではないことが多かったとも指摘している。 ソースコードと機密データ BreachForumsへの投稿で、IntelBrokerは侵害された項目として次のようなものを挙げた。 ZertoやiLOを含むHPE製品のソースコード 非公開のGitHubリポジトリおよびDockerビルド 公開および非公開のデジタル証明書 APIアクセスキーおよびその他のサービス認証情報 データのサンプルを確認したHackread.comは、流出データがオープンソースと独自ツールの双方を含む開発環境に言及していると報じた。 IntelBrokerについてさらに読む:General Electric、DARPA侵害疑惑を調査 IntelBrokerは、この侵害は第三者の侵害によるものではなく、直接のハッキングによるものだと主張している。このハッカーは過去1年で非常に活発に活動しており、T-Mobile、AMD、そしてAppleなどの企業を標的にしてきた。AppleやEuropolの侵害に関する過去の誇張も明らかになっているが、IntelBrokerは完全に虚偽の主張をすることで知られているわけではない。 サイバーセキュリティの専門家が、疑惑の侵害の潜在的な範囲とリスクを評価するなか、HPEの調査は継続している。 翻訳元:
blackhatnews.tokyo
February 7, 2026 at 7:58 AM
From Hacker Den to Prison Cell: The OpSec Failures That Landed IntelBroker Behind Bars + Video

Introduction: The recent video of notorious hacker Kai "IntelBroker" West in a French detention facility reveals more than just atypical prison conditions; it offers a stark case study in operational…
From Hacker Den to Prison Cell: The OpSec Failures That Landed IntelBroker Behind Bars + Video
Introduction: The recent video of notorious hacker Kai "IntelBroker" West in a French detention facility reveals more than just atypical prison conditions; it offers a stark case study in operational security (OpSec) failures. Allegedly responsible for breaching Apple and U.S. government systems, causing an estimated $25M in damages, his journey from a digital "hacker den" to a physical cell underscores a critical truth: technical prowess is futile without rigorous personal security hygiene.
undercodetesting.com
January 24, 2026 at 6:18 PM
❗️A video of threat actor IntelBroker showing his French prison cell

IntelBroker, aka Kai Logan West, was arrested in France in February 2025 for cybercrimes. He was also an admin of BreachForums.
January 20, 2026 at 11:22 PM
IntelBroker Unmasked - The Story of Hacker Kai Logan West Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor...

#Malware #News

Origin | Interest | Match
IntelBroker Unmasked - The Story of Hacker Kai Logan West
Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coupon Code MWNEWS10 Note: Affiliate link – your enrollment helps support this platform at no extra cost to you. If you’ve been following cybersecurity news lately, you’ve almost certainly heard the name "IntelBroker." For years, this digital phantom haunted major corporations and government agencies, leaking sensitive ...
malware.news
January 19, 2026 at 1:46 PM
Karma hits the cybercrime world! 💥 The user database of the notorious BreachForums has been leaked, exposing the emails, IPs, and private messages of nearly 324,000 members. A massive intelligence win for law enforcement. #BreachForums #Cybercrime ...
Poetic Justice: BreachForums Hacked, Database of 324,000 Cybercriminals Leaked
The user database of the notorious cybercrime marketplace BreachForums has been leaked, exposing the sensitive data of nearly 324,000 users, including threat actors like IntelBroker and ShinyHunters.
cyber.netsecops.io
January 13, 2026 at 8:28 PM
Does the Virginia Election System have adequate Cybersecurity to prevent hacking in this election??

www.redhotcyber.com/en/post/the-...
The Virginia Department of Elections database may have been hacked and is online on the dark web
A severe security breach at the Virginia Department of Elections led to the unauthorized release of a vast electoral database. The attack, claimed by IntelBroker on a data breach forum, raises signifi...
www.redhotcyber.com
November 2, 2025 at 2:45 PM
FBI Strikes Major Blow Against Global Cybercrime: BreachForums Seizure Disrupts Elite Hacking Network
## _International law enforcement operation dismantles marketplace used by ShinyHunters, Baphomet, and IntelBroker amid massive Salesforce extortion campaign_ **October 2025** — In a coordinated international law enforcement operation, the FBI and French authorities have seized control of BreachForums, one of the world's most notorious cybercrime marketplaces, dealing a significant blow to a criminal ecosystem that facilitated billions of dollars in data theft and extortion. The October 9-10 takedown, conducted jointly by the FBI, U.S. Department of Justice, France's Brigade de Lutte Contre la Cybercriminalité (BL2C), and the Paris Prosecutor's Office, comes as the latest chapter in an ongoing battle against a resilient network of elite threat actors who have repeatedly resurrected the platform despite law enforcement pressure. ### **A Critical Strike at a Criminal Crossroads** The seizure occurred just hours before the Scattered LAPSUS$ Hunters hacking collective—a "trinity of chaos" combining members from ShinyHunters, Scattered Spider, and Lapsus$—was set to execute their threatened October 10 deadline to leak nearly one billion records stolen from Salesforce customers. Visitors to breachforums.hn were greeted with an animated FBI seizure banner, while the site's name servers were redirected to the FBI's standard seized infrastructure at ns1.fbi.seized.gov and ns2.fbi.seized.gov. The operation marks the fourth time law enforcement has targeted the forum and its predecessors since 2022. In a PGP-signed message posted to Telegram shortly after the seizure, ShinyHunters confirmed the operation's scope, revealing that authorities had compromised not just the domains, but all backend servers, database backups dating to 2023, and escrow databases. "The era of forums is over," the message declared, warning that any future relaunch should be considered a law enforcement honeypot. ### **The Threat Actors Behind the Operation** The individuals and groups leveraging BreachForums represent some of the most prolific cybercriminals of the past five years: **ShinyHunters** : Active since 2020, this English-speaking collective has been linked to massive data breaches affecting billions of users across telecommunications, e-commerce, technology, and retail sectors, including high-profile attacks on AT&T, Salesforce, PowerSchool, Ticketmaster, Advance Auto Parts, and Neiman Marcus. The group earned notoriety for their sophisticated social engineering tactics and their exclusive dealings on RaidForums and BreachForums. **Baphomet** : A previous administrator who partnered with ShinyHunters to relaunch BreachForums following the arrest of original founder Conor Fitzpatrick in March 2023. Reports indicate Baphomet was arrested in a 2024 law enforcement operation. **IntelBroker** : The notorious data broker rose to prominence through high-profile breaches at Europol, General Electric, AMD, HPE, Nokia, Cisco, and DC Health Link—which exposed sensitive information of U.S. House members and their families. French authorities arrested IntelBroker, identified as Kai West, in February 2025, though this information was not publicly confirmed until June. ### **The Salesforce Campaign: A New Evolution in Cybercrime** The timing of the BreachForums seizure was no coincidence. The Scattered LAPSUS$ Hunters collective had launched a dedicated data leak site threatening to release approximately one billion records allegedly stolen from 39 major Salesforce customers, including Disney, Toyota, McDonald's, IKEA, FedEx, Cisco, Home Depot, Marriott, Walgreens, and Chanel. The attacks exploited social engineering techniques, particularly voice phishing (vishing), where hackers impersonated IT support staff to trick employees into authorizing malicious OAuth applications that granted persistent access to Salesforce environments, effectively bypassing multi-factor authentication. In August 2025, attackers further compromised organizations by breaching a GitHub repository used by Salesloft's Drift chatbot integration, gaining access to OAuth tokens for 760 Salesforce instances. This supply-chain attack demonstrated a sophisticated evolution from traditional ransomware to "extortionware"—leveraging data exposure rather than system encryption for extortion. Salesforce emphasized that its core platform was not breached, stating the incidents related to third-party integrations and customer-side security lapses, and publicly declared it would not pay or negotiate ransom demands. ### **A Resilient Criminal Infrastructure** BreachForums' history illustrates the persistent challenge law enforcement faces in combating decentralized cybercrime networks: * **March 2022** : Founded by Conor Brian Fitzpatrick (Pompompurin) as a successor to the FBI-seized RaidForums, the platform quickly gained traction and eventually reached nearly 225,000 members * **March 2023** : Fitzpatrick arrested in New York and later sentenced to 20 years supervised release after pleading guilty to conspiracy charges and possession of child pornography * **June 2023** : ShinyHunters and Baphomet relaunched BreachForums v2, continuing operations as a marketplace for stolen data, hacking tools, and network access * **May 2024** : Second FBI seizure, though ShinyHunters briefly retrieved control of the domain * **June 2025** : French authorities arrested four key administrators operating under the aliases "ShinyHunters," "Hollow," "Noct," and "Depressed," all accused of involvement in major breaches against French entities including France Travail, which compromised 43 million individuals * **July-August 2025** : ShinyHunters relaunched BreachForums v4 under the breachforums.hn domain, but warned in August that the forum had been compromised and was serving as a law enforcement honeypot * **October 2025** : FBI and French authorities execute the latest comprehensive seizure ### **Law Enforcement's Expanding Reach** The BreachForums operation represents part of an unprecedented acceleration of international law enforcement cooperation in 2025, building on successful 2024 operations that disrupted major ransomware groups like LockBit under Operation Cronos. FBI Assistant Director Christopher G. Raia stated that the arrests "should serve as a warning to anyone thinking they can hide behind a keyboard and commit cybercrime with impunity; the FBI will find and hold you accountable no matter where you are". The seizure demonstrated the success of global law enforcement collaboration in combating cybercrime, with similar partnerships expected to help international agencies address cybercriminal activity more quickly and effectively. ### **The Dark Web Persists** Despite the clearnet seizure, challenges remain. The Tor-based dark web version of the leak site remained operational following the seizure, and the threat actors confirmed their Salesforce extortion campaign would continue. On October 13, the group leaked data from six victims including Qantas Airlines, Gap, Albertsons, and Vietnam Airlines, which exposed 7.3 million unique email addresses. Security experts note that the forum-free, portable extortion model allows groups to pivot across Telegram, throwaway domains, and bespoke leak sites, making complete disruption difficult. ### **Implications for the Cybersecurity Landscape** The BreachForums takedown yields several critical insights for the cybersecurity community: **Lowered Barriers to Entry** : BreachForums' large user base and degree of anonymity lowered barriers for new and inexperienced cybercriminals, making it easier to locate tools and resources needed for attacks. Its disruption will temporarily fragment this ecosystem. **Evolution of Tactics** : The Salesforce campaign highlights a strategic shift from traditional ransomware that encrypts files to data theft and extortion, where leverage comes from threatened public exposure rather than system disruption. **SaaS as Target** : Security analysts note that SaaS platforms represent "the new blast radius," often compromised by abusing OAuth and app-to-app trust relationships that interconnected services depend upon. **Youth Movement** : Many of these sophisticated attacks originate from "The Com," a loosely organized English-speaking cybercrime youth movement encompassing mainly teens and twentysomethings who share tools, trade access, and collaborate on operations. ### **What's Next** ShinyHunters' statement that "BreachForums is never coming back, if it comes back, it should immediately be considered a honeypot" suggests the group recognizes traditional forums have become too compromised for safe criminal operations. The threat actors indicated they believe the FBI and international partners will crack down on many individuals in the coming weeks to months. However, cybersecurity experts remain cautious. The pattern of relaunches suggests that despite infrastructure takedowns, threat actors often resurface under new names or platforms, continuing campaigns from the dark web or encrypted channels like Telegram. For organizations, security professionals recommend using this disruption as a 30-day grace period to ramp up dark web monitoring tools, audit SaaS configurations—particularly OAuth permissions—and drill incident response playbooks. ### **Conclusion** The FBI's seizure of BreachForums represents a significant tactical victory in the ongoing battle against organized cybercrime, demonstrating the effectiveness of sustained international cooperation and the willingness of global law enforcement to impose real costs on cyber threat actors. Yet as the Scattered LAPSUS$ Hunters' continued operations demonstrate, the fight against cybercrime remains an evolving challenge. The marketplace may be gone, but the criminal expertise, social networks, and motivations that fueled it persist—a reminder that defending against these threats requires constant vigilance, international collaboration, and adaptive security strategies. As organizations worldwide grapple with the implications of the Salesforce campaign and assess their exposure from years of BreachForums operations, one thing is clear: the seizure of this criminal crossroads marks not an ending, but a new chapter in the perpetual cat-and-mouse game between cybercriminals and those working to stop them. * * * **About the Investigation** : The FBI is requesting victims and individuals contact them with information about the hacking forum and its members through dedicated channels including a special IC3 portal, email, Telegram, and TOX accounts to aid in their ongoing investigation.
breached.company
October 14, 2025 at 9:28 PM
FBIとフランス警察、BreachForumsのドメインを再び閉鎖

FBIとフランスの捜査官は、最近のSalesforce侵害に関連してリークサイトとして利用されていた人気のサイバー犯罪フォーラムの少なくとも1つのドメインを押収しました。 X(旧Twitter)に投稿されたスクリーンショットには、BreachForumsのクリアウェブサイトがFBI、司法省、フランスのサイバー犯罪警察グループBL2C、パリ検察局JUNALCOのロゴで飾られている様子が映っています。…
FBIとフランス警察、BreachForumsのドメインを再び閉鎖
FBIとフランスの捜査官は、最近のSalesforce侵害に関連してリークサイトとして利用されていた人気のサイバー犯罪フォーラムの少なくとも1つのドメインを押収しました。 X(旧Twitter)に投稿されたスクリーンショットには、BreachForumsのクリアウェブサイトがFBI、司法省、フランスのサイバー犯罪警察グループBL2C、パリ検察局JUNALCOのロゴで飾られている様子が映っています。 「FBIとそのパートナーは、ShinyHunters、Baphomet、IntelBrokerが盗まれたデータの取引や恐喝の促進に利用していた主要な犯罪マーケットプレイスであるBreachForumsに関連するドメインを押収しました」と、添付の投稿で説明しています。 「この摘発により、これらのアクターが侵害を収益化し、協力者を募集し、複数の業界で被害者を標的にするために利用していた主要なハブへのアクセスが遮断されました。これは、サイバー犯罪の背後にいる者に対してコストを課すための国際的な法執行機関の協調した作戦の影響力を示しています。」 FBIとそのパートナーは、ShinyHunters、Baphomet、IntelBrokerが盗まれたデータの取引や恐喝の促進に利用していた主要な犯罪マーケットプレイスであるBreachForumsに関連するドメインを押収しました。 この摘発により、これらのアクターが収益化に利用していた主要なハブへのアクセスが遮断されました… pic.twitter.com/aiTRzFCIYU — FBI (@FBI) 2025年10月12日 Salesforce侵害の詳細はこちら:進行中のSalesforceデータ窃盗キャンペーンで被害を受けたGoogle 通知では複数のドメインについて言及されていますが、広く報道されているところによると、当局が妨害したのは「breachforums[.]hn」のみで、関連する.onionサイトは依然としてオンラインのままです。 つまり、この押収によって最近のSalesforceキャンペーンの被害者への恐喝を止める効果はほとんどありません。Scattered Lapsus$ Huntersは10億件以上の記録を保有していると主張し、交渉の期限を10月10日としています。 SOCRadarによって再投稿されたShinyHuntersからの別のPGP署名付き声明では、Feds(連邦当局)が2023年以降のBreachForumsサイトのすべてのデータベースバックアップも押収し、すべてのエスクロー(仲介)データベースが侵害されたと主張しています。バックエンドサーバーも破壊されたと付け加えています。 「BreachForumsは二度と戻ってこない。もし戻ってきたら、それはすぐにハニーポットと見なされるべきだ」と声明は続けています。 「この押収について特に言うことはありませんが、米国政府が最近我々に対して行った行動は、我々のSalesforceキャンペーンには何の影響もありません。」 Salesforceの被害者は依然として危険にさらされている Xcapeのシニアセキュリティエンジニア、ノエル・ムラタ氏も、この摘発が恐喝キャンペーンを阻止する効果はほとんどないと同意しています。 「Salesforce侵害の影響を受けた組織は、フォーラムがオフラインになっていてもデータ漏洩の可能性に備えるべきです。これには監視体制の強化や対応計画の策定が含まれます」と彼女は述べています。 「この状況で法執行機関の効果が高まった一方で、脅威アクターが適応し新たなプラットフォームを見つける能力も高まっており、攻撃と防御、そして法執行機関の役割の間で絶えず変化する駆け引きが浮き彫りになっています。」 しかし、バックアップの押収は他の捜査で法執行機関の助けになる可能性があると、AppOmniの最高セキュリティ責任者コリー・ミカル氏は述べています。 「それが事実なら興味深いですね。なぜなら、これで捜査官が過去数年で最も活発だった犯罪コミュニティの1つから、登録情報、IPログ、プライベートメッセージ、取引記録などの過去のユーザーデータにアクセスできることになるからです」と彼は付け加えました。 「このレベルの可視性は、関係性のマッピングや、偽名と実際の身元の紐付け、常習犯に対するより強力な刑事事件の構築に直接役立ちます。単なるドメインの押収ではなく、捜査を進展させるための証拠の宝庫となる可能性があります。」 Salesforceキャンペーンを通じて、FedEx、Home Depot、Google、Air France/KLM、Chanel、Pandora、Adidasなど、数十の組織が侵害されたと考えられています。 被害者は、ビッシングキャンペーンでSalesforceのData Loaderアプリの悪意あるバージョンをダウンロードするよう騙されたか、サードパーティのSalesloft Driftアプリケーションに関連するOAuthトークンを通じて侵害されました。 翻訳元:
blackhatnews.tokyo
October 13, 2025 at 8:49 AM
The BreachForums Takedown: A Deep Dive into the FBI’s Decapitation of a Cybercrime Hub

Introduction: The recent seizure of BreachForums' domains by the FBI and international partners represents a significant blow to the cybercriminal ecosystem. This marketplace served as a primary conduit for…
The BreachForums Takedown: A Deep Dive into the FBI’s Decapitation of a Cybercrime Hub
Introduction: The recent seizure of BreachForums' domains by the FBI and international partners represents a significant blow to the cybercriminal ecosystem. This marketplace served as a primary conduit for threat actors like ShinyHunters and IntelBroker to monetize massive data breaches, making its disruption a critical event for security professionals to understand. This article dissects the technical implications, the tactics of the actors involved, and the defensive measures organizations can implement.
undercodetesting.com
October 13, 2025 at 3:52 AM
Operation Nemesis: Decoding the BreachForums Takedown and Fortifying Your Cyber Defenses

Introduction: The recent seizure of BreachForums' domains by the FBI and international partners represents a critical strike against the cybercriminal ecosystem. This takedown disrupts a key marketplace where…
Operation Nemesis: Decoding the BreachForums Takedown and Fortifying Your Cyber Defenses
Introduction: The recent seizure of BreachForums' domains by the FBI and international partners represents a critical strike against the cybercriminal ecosystem. This takedown disrupts a key marketplace where threat actors like ShinyHunters and IntelBroker monetized stolen data, recruited accomplices, and coordinated extortion campaigns. For cybersecurity professionals, this event underscores the persistent threat of data brokerage forums and the continuous need for robust defensive and intelligence-gathering measures.
undercodetesting.com
October 13, 2025 at 2:23 AM
Пойман хакер IntelBroker, выбиравший только Monero, из-за ошибки с Bitcoin

https://kripta.biz/posts/970BA9F8-FC47-4E35-AE84-48023FBDB239
September 27, 2025 at 3:44 AM
隐匿高手IntelBroker因接受FBI比特币支付被捕,引发Monero隐私币安全质疑

https://qian.cx/posts/8C6455D4-B662-404D-A566-EE7E86280EF4
September 27, 2025 at 3:43 AM
ФБР задержало администратора BreachForums «IntelBroker» в результате операции с Bitcoin на $250

https://kripta.biz/posts/C965D2D7-F099-43D5-84EB-A4E6EE5D097D
September 25, 2025 at 10:45 AM
FBI通过250美元比特币诱捕行动抓获BreachForums管理员“IntelBroker

https://qian.cx/posts/7C7B8B7E-071F-4DCC-AB47-C0FB8640E1BA
September 25, 2025 at 10:44 AM
IntelBroker: Британский хакер обвиняется в крупном взломе данных на сумму свыше 25 миллионов долларов

https://kripta.biz/posts/B4F3F613-C96F-4ABF-B7CD-885AEFFD6689
September 24, 2025 at 1:27 PM
英国黑客IntelBroker被起诉 涉及逾2500万美元数据泄露案引发网络安全警铃

https://qian.cx/posts/AEE68B41-0F2D-4D0C-8C0A-7ACD49683203
September 24, 2025 at 1:27 PM
ФБР задерживает предполагаемого администратора BreachForums «IntelBroker» по делу о продаже украденных данных за 250 долларов в биткоинах

https://kripta.biz/posts/411778A8-94F7-4318-8399-605D13EE3BBE
September 23, 2025 at 10:07 PM
FBI成功捣毁“IntelBroker”:价值250美元比特币诱捕揭露BreachForums管理员身份

https://qian.cx/posts/A5710CDF-8940-43FA-8D62-191394E92DC3
September 23, 2025 at 10:07 PM
「Scattered Lapsus$ Hunters」など、複数のグループがハッキング活動の終了を発表

出典:Stephen Dwyer(Alamy Stock Photo経由) サイバーセキュリティ業界に衝撃を与えたと思われる出来事として、新たに結成された「Scattered Lapsus$ Hunters」を含む複数の著名な脅威アクターやグループが、自らの活動を終了すると発表しました。 この発表は先週、ハッキングマーケットプレイス「BreachForums」およびScattered Lapsus$…
「Scattered Lapsus$ Hunters」など、複数のグループがハッキング活動の終了を発表
出典:Stephen Dwyer(Alamy Stock Photo経由) サイバーセキュリティ業界に衝撃を与えたと思われる出来事として、新たに結成された「Scattered Lapsus$ Hunters」を含む複数の著名な脅威アクターやグループが、自らの活動を終了すると発表しました。 この発表は先週、ハッキングマーケットプレイス「BreachForums」およびScattered Lapsus$ Huntersの公開Telegramチャンネルにて、「世界」宛ての別れの手紙という形で投稿されました。 「我々の目的は達成されたので、今こそ別れを告げる時です」とその手紙には書かれています。「我々LAPSUS$、Trihash、Yurosh、yaxsh、WyTroZz、N3z0x、Nitroz、TOXIQUEROOT、Prosox、Pertinax、Kurosh、Clown、IntelBroker、Scattered Spider、Yukari、その他多くの者たちは、闇に消えることを決めました。」 先月、Scattered Spider、Lapsus$、ShinyHuntersといった悪名高いサイバー犯罪グループ(研究者たちは「The Com」から派生したと考えている)が、新たな旗印「Scattered Lapsus$ Hunters」のもとで、公開Telegramチャンネル上で手を組んだように見えました。これらのグループのメンバーは、2つのSAP NetWeaver Visual Composerの脆弱性に対するエクスプロイトをTelegramチャンネルに投稿し、実際に攻撃が行われていることを示しました。 手紙によると、メンバーの中には、それぞれのグループで得た資金で引退を計画している者もいれば、社会により有益な形でサイバーセキュリティ分野に残り、人々が日常的に利用するシステムの改善などに取り組む者もいるとのことです。 グループは活動終了を表明していますが、一部のメッセージからは、まだ何か裏があることを示唆しています。 「ケリング、エールフランス、アメリカン航空、ブリティッシュエアウェイズ、その他多くの重要インフラは、公開または秘密裏のデータ侵害の“代償”を受けることになるのでしょうか?私が彼らの立場なら気になるでしょう。なぜなら、まだ身代金要求など何も受けていない企業もあることを彼らは知っているからです」と付け加えています。「米国、英国、オーストラリア、フランス当局が状況を掌握したと錯覚している間に、彼らのデータは現在悪用されているのでしょうか?」 Scattered Spiderは勝ち逃げか? この終了発表は、特にScattered Spiderのようなグループにとっては意外性が強いものです。同グループは、複数のメンバーが逮捕されたにもかかわらず、最近まで猛威を振るっていました。 このサイバー犯罪集団は、2023年にラスベガスのカジノ・ホテル大手であるシーザーズ・エンターテイメントやMGMリゾーツへの攻撃で悪名を高めました。主に英語を話す10代や20代で構成されているこのグループは、その後、Marks and Spencerをはじめとする英国の小売業者や、WestJet、ハワイアン航空、その他大手企業やそのIT委託先企業への攻撃も行いました。 このグループは、FBIがそのソーシャルエンジニアリング手法について警告を発するほどの重大な脅威となりました。FBIは、リスクの高いグループに対し今夏注意喚起を行っています。 ShinyHuntersのような他のギャングも、Google、ルイ・ヴィトン、アリアンツなどの大企業を攻撃する際に、Scattered Spiderの手法を模倣しています。 脅威グループの今後は? セキュリティ研究者たちは活動終了の発表に懐疑的で、一部では継続的な活動の証拠を指摘しています。 Reliaquestの研究者は月曜日に更新したブログ記事で、Scattered Spiderのメンバーが金融セクターを標的にしている兆候を観測したと述べています。「グループに関連している可能性のあるドメインが金融セクターに集中して増加していることや、最近特定された米国の銀行組織に対する標的型侵入など」が挙げられています。Reliaquestは先月、Scattered Spiderハッキング集団が間もなく金融セクターに焦点を移すと考えていると報告していました。 この活動は、グループが活動停止を主張した後に発生しているようで、被害者に偽の安心感を与えるために偽装して活動を続けている可能性があるとReliaquestは述べています。 「これらの主張にもかかわらず、TTP(戦術・技術・手順)やIoC(インジケーター・オブ・コンプロマイズ)は依然として表面化しており、脅威が依然として活動的かつ進化し続けていることを示しています」とブログ記事は述べています。「これらのグループが手法を適応させ続ける中、警戒と積極的な対応が極めて重要です。」 翻訳元:
blackhatnews.tokyo
September 17, 2025 at 7:43 PM
🚨 IntelBroker leaks 2.9 TB of exposed Cisco records! Discover the implications and what you need to know in our latest blog post. 🔍💻 Read more: https://innovirtuoso.com/cybersecurity/intelbroker-leaks-2-9-tb-of-exposed-cisco-records-what-you-need-to-know/ #Cybersecurity #DataBreach #Cisco
IntelBroker Leaks 2.9 TB of Exposed Cisco Records
The IntelBroker leak has revealed 2.9 terabytes of sensitive data related to Cisco, raising serious concerns. Stay informed about the implications
innovirtuoso.com
September 6, 2025 at 4:13 PM
26세의 나이로 2022년도부터 활동한 IntelBroker와 BreachFroms는 몰락의 길을 걷기 시작했습니다. IntelBroker도 이 해킹을 위해서 많은 시간과 공부를 했을지어도, 결국 추적당하는 결말을 맞이했습니다.
August 31, 2025 at 7:20 PM