DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

British national “IntelBroker” charged with causing $25 million in damages; U.S. seeks his extradition from France

Posted on June 25, 2025June 25, 2025 by Dissent
Kai West’s license in 2023. From court filing.

“IntelBroker” was arrested in France in February, 2025, but news of his arrest was first disclosed today by French authorities. Now the U.S. is revealing its charges against him as they seek his extradition from France.  From the U.S. Attorney’s Office for the Southern District of New York, this press release: 

Kai West, a British National, Is Charged With Operating the “IntelBroker” Online Identity, Infiltrating Victim Computer Networks, Stealing Data, Selling It, and Causing Millions in Damages to Dozens of Victims Around the World

The United States Attorney for the Southern District of New York, Jay Clayton, and the Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), Christopher G. Raia, announced the unsealing of a four-count criminal Indictment and Complaint charging KAI WEST, a/k/a “IntelBroker,” a/k/a “Kyle Northern,” with a years-long hacking scheme committed through the online identity “IntelBroker.”  WEST, using the IntelBroker identity, conspired with an online group named the CyberN[——], to steal data from a telecommunications company, municipal health care provider, an Internet service provider, and more than 40 other victims.  WEST, and his online co-conspirators, took that stolen data, and offered it for sale online for more than $2 million.  Collectively, WEST, through the “IntelBroker” identity and his online co-conspirators, caused in excess of $25 million in damages to victims.  WEST was arrested in France in February 2025, and the United States is seeking his extradition.  The case has been assigned to U.S. District Judge Katherine Polk Failla.

“The IntelBroker alias has caused millions in damages to victims around the world,” said U.S. Attorney Jay Clayton.  “This action reflects the FBI’s commitment to pursuing cybercriminals around the world.  New Yorkers are all too often the victims of intentional cyber schemes and our office is committed to bringing these remote actors to justice.”

“Kai West, an alleged serial hacker, is charged for a nefarious, years-long scheme to steal victim’s data and sell it for millions in illicit funds, causing more than $25 million in damages worldwide,” said FBI Assistant Director in Charge Christopher G. Raia.  “Today’s announcement should serve as a warning to anyone thinking they can hide behind a keyboard and commit cyber-crime with impunity; the FBI will find and hold you accountable no matter where you are.”

As alleged in the Indictment and Complaint:[1]

“IntelBroker” is the online moniker of WEST, who, in concert with his co-conspirators, compromised victims’ (typically companies) computer systems, exfiltrated data from those systems (e.g. customer lists and company marketing data), and then sold the stolen data for profit.  WEST accomplished his scheme in connection with his leadership of an online hacking group called the “CyberN[——],” which frequented a particular internet forum (“Forum-1”).

Between approximately 2023 to 2025, WEST offered hacked data for sale approximately 41 times; and offered to distribute hacked data for free (or for Forum-1 credits) approximately 117 times. WEST, and his co-conspirators, have sought to collect at least approximately $2,000,000 by selling the stolen data.  Based on information received from the victims of these breaches, WEST and his co-conspirators have cumulatively caused victim losses of at least $25,000,000.

Based on a review of WEST’s IntelBroker Forum-1 posts, approximately 158 threads started by WEST offered stolen data for sale, for Forum-1 credit, or for free, since in or about January 2023 through in or about February 2025.  At least 41 of those 158 public messages sell data from companies based in the United States.  Of those 158 messages, approximately 16 provided a specific asking price for the stolen data, which cumulatively totals at least $2,467,000. At least 25 of the 158 public messages invited Forum‑1 users to private message IntelBroker (i.e. WEST) to negotiate a sales price.  The remaining 117 public messages offer hacked data for free to Forum-1 users or in exchange for Forum-1 credits.  At least 46 of the 158 public messages indicate that WEST worked in concert with a particular Forum-1 user (“CC-1”) to obtain the data through a “breach” (i.e. “hack”).  WEST’s public messages (as IntelBroker) indicate that he accepts payment via Monero, which is a cryptocurrency that uses a blockchain with privacy-enhancing technologies to attempt to obfuscate transactions and seek to achieve anonymity and fungibility.

WEST’s prolific posting (as IntelBroker), and his sales of stolen data, have generated notoriety for the IntelBroker identity within the Forum-1 community. Indeed, from in or about August 2024 through in or about January 2025, “IntelBroker” was identified on Forum-1 as the site’s “owner.”  To further his username’s notoriety, WEST has associated different images with IntelBroker but primarily uses the following image as his calling card:

IB logo

WEST’s victims include a U.S.-based telecommunications provider.  WEST, using the IntelBroker moniker, sold data from that telecommunications company, which included information about its customers.  That data was accessed by WEST by illegally accessing a server which was improperly configured.  On or about March 6, 2023, WEST, using the IntelBroker moniker, authored a public message on Forum-1 titled “CyberN[——] [redacted reference to Victim] Database.”  In that post, WEST offered for sale data from a municipal healthcare provider which included patient data such as names, Social Security numbers, dates of birth, genders, health plan information, employer information, among other information, from the victim’s patients.

*               *                *

WEST, 25, a British national, is charged with conspiracy to commit computer intrusions, which carries a maximum sentence of five years in prison; conspiracy to commit wire fraud, which carries a maximum sentence of 20 years in prison; accessing a protected computer to obtain information, which carries a maximum sentence of five years in prison; and wire fraud, which carries a maximum sentence of 20 years in prison.

The maximum potential sentences are prescribed by Congress and provided here for informational purposes only, as any sentencing of the defendant will be determined by a judge.

Mr. Clayton praised the outstanding work of the FBI and the Office of International Affairs of the Department of Justice’s Criminal Division.  He also thanked the French, Spanish, and British authorities for their assistance.

The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Ryan B. Finkel is in charge of the prosecution.

The charges contained in the Indictment and Complaint are merely accusations, and the defendant is presumed innocent unless and until proven guilty.

u.s._v._west_indictment.pdf

u.s._v._west_complaint.pdf


[1] As the introductory phrase signifies, the entirety of the text of the Indictment and the Complaint, and the descriptions set forth herein, constitutes only allegations, and every fact described therein should be treated as an allegation.


Related:

  • Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials
  • John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
  • UK: 'Catastrophic' attack as Russians hack files on EIGHT MoD bases and post them on the dark web
  • Data BreachesProsper Data Breach Impacts 17.6 Million Accounts
  • The Alliance That Wasn’t: A Critical Analysis of ReliaQuest’s Q3 2025 Ransomware Report
  • F5 discloses breach tied to nation-state threat actor
Category: Business SectorHackOf Note

Post navigation

← France issues press statement about arrest of ShinyHunters members
Kansas City Man Pleads Guilty for Hacking a Non-Profit →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.