Egidio
Case file · 2026

IntelBroker: the hacker who exposed Congress's health data

IntelBroker claimed roughly 80 breaches — AMD, Cisco, Europol, HPE among them — most disputed or unconfirmed by the named victims. One case stands apart: a real government health exchange, a real confirmed number, and a real arrest.

Who is IntelBroker

IntelBroker is the alias of Kai Logan West, a British national who spent roughly two years posting claimed breaches of major organizations on cybercrime forums. He was arrested in France in February 2025, and a US federal indictment was later unsealed. Most of his ~80 claimed victims — including AMD, Cisco, HPE, Zscaler and Europol — either denied a breach occurred, disputed the scope, or never confirmed anything. The case below is the exception: a specific, named victim organization with its own confirmed figure to check his claim against.

⚠️ What "confirmed" means here. This page separates what DC Health Link itself disclosed from what IntelBroker claimed on the forum listing where he advertised the data for sale. The two numbers do not match.
56,415
Customers whose personal information was confirmed accessed, per DC Health Link's own disclosure.
DC Health Link, official breach notification. Accessed 17/08/2026.
170,000
Individuals IntelBroker claimed were affected — not matched by the organization's own count.
IntelBroker's forum listing, March 2023, reported by specialist press. Accessed 17/08/2026.

Timeline

CONFIRMED
March 6, 2023
DC Health Link — the health-insurance marketplace used by the US House of Representatives and Senate — discloses a breach caused by an exposed, unauthenticated database. The FBI opens an investigation given the exposure of Congress members and staff.
CLAIMED, UNMATCHED
March 6, 2023
The same day, IntelBroker posts a listing offering the data for sale, claiming 170,000 affected individuals — a figure DC Health Link's own later disclosure did not match.
CONFIRMED
Following disclosure
DC Health Link confirms 56,415 customers had names, Social Security numbers, birth dates and addresses accessed or stolen.
CONFIRMED
February 2025
Kai Logan West, identified as IntelBroker, is arrested in France. A US federal indictment follows, exposing him to significant prison time.

A pattern of claims that rarely survive scrutiny

What makes IntelBroker's case instructive isn't the scale of any single breach — it's the pattern. Across dozens of claimed victims, the organizations named either denied any breach, disputed the scope dramatically, or simply never confirmed anything publicly. DC Health Link is one of the very few cases where a named victim put out its own number, making it possible to measure the gap between what was claimed and what actually happened.

Why this case matters to you

A Social Security number paired with a real birth date and address is exactly the kind of detail that makes a scam call or message impersonating an insurer, a bank, or a tax authority far more convincing — the same pattern behind the France DGFiP case covered elsewhere in this Threat Lab.

🔒 Whether your data has leaked or not, the protection principle stays the same: spot the pattern of an impersonation attempt, not just the isolated message or call. That's exactly what Medusa, Egidio's engine, does. See how it works.

Frequently asked questions

Who is IntelBroker?

The alias of Kai Logan West, a British national who claimed dozens of high-profile breaches (AMD, Cisco, Europol, and more) between 2023 and 2025. He was arrested in France in February 2025 and indicted in the US. The DC Health Link case is his single best-documented breach, with a clear victim-confirmed figure to compare against his claim.

What did DC Health Link confirm, versus what IntelBroker claimed?

DC Health Link confirmed 56,415 customers had personal information — names, Social Security numbers, birth dates, addresses — accessed or stolen. IntelBroker claimed a larger figure of 170,000 individuals affected, a claim not matched by the organization's own count.

What does this have to do with the scams an ordinary person receives?

A stolen Social Security number and birth date is exactly the kind of detail that makes a fraudulent call or message claiming to be your insurer, bank, or the IRS far more convincing.

Go further

Cite this page Egidio — The Threat Laboratory, "IntelBroker: the hacker who exposed Congress's health data", egidio.app/en/laboratoire/intelbroker-dc-health-link/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.