Who is IntelBroker
IntelBroker is the alias of Kai Logan West, a British national who spent roughly two years posting claimed breaches of major organizations on cybercrime forums. He was arrested in France in February 2025, and a US federal indictment was later unsealed. Most of his ~80 claimed victims — including AMD, Cisco, HPE, Zscaler and Europol — either denied a breach occurred, disputed the scope, or never confirmed anything. The case below is the exception: a specific, named victim organization with its own confirmed figure to check his claim against.
Timeline
A pattern of claims that rarely survive scrutiny
What makes IntelBroker's case instructive isn't the scale of any single breach — it's the pattern. Across dozens of claimed victims, the organizations named either denied any breach, disputed the scope dramatically, or simply never confirmed anything publicly. DC Health Link is one of the very few cases where a named victim put out its own number, making it possible to measure the gap between what was claimed and what actually happened.
Why this case matters to you
A Social Security number paired with a real birth date and address is exactly the kind of detail that makes a scam call or message impersonating an insurer, a bank, or a tax authority far more convincing — the same pattern behind the France DGFiP case covered elsewhere in this Threat Lab.
Frequently asked questions
Who is IntelBroker?
The alias of Kai Logan West, a British national who claimed dozens of high-profile breaches (AMD, Cisco, Europol, and more) between 2023 and 2025. He was arrested in France in February 2025 and indicted in the US. The DC Health Link case is his single best-documented breach, with a clear victim-confirmed figure to compare against his claim.
What did DC Health Link confirm, versus what IntelBroker claimed?
DC Health Link confirmed 56,415 customers had personal information — names, Social Security numbers, birth dates, addresses — accessed or stolen. IntelBroker claimed a larger figure of 170,000 individuals affected, a claim not matched by the organization's own count.
What does this have to do with the scams an ordinary person receives?
A stolen Social Security number and birth date is exactly the kind of detail that makes a fraudulent call or message claiming to be your insurer, bank, or the IRS far more convincing.
Go further
Egidio — The Threat Laboratory, "IntelBroker: the hacker who exposed Congress's health data", egidio.app/en/laboratoire/intelbroker-dc-health-link/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.