KELA

KELA We Monitor, Hunt, and Mitigate Digital Crimes with Real Intelligence.

An award-winning cybercrime threat intelligence firm, KELA's mission is to provide 100% real, actionable intelligence on threats emerging from the cybercrime underground, to support the prevention of digital crimes. Our success is based on a unique integration of our proprietary automated technologies and qualified intelligence experts. Trusted worldwide, our technology infiltrates hidden undergro

und places and thoroughly monitors, hunts, and mitigates digital crimes to uncover real risks and allow proactive protection. KELA’s revolutionary solution arms you with highly contextualized intelligence, as seen from the eyes of attackers, thus enabling the elimination of blind spots and proactive network defense.

In March 2026, KELA's Cyber Intelligence Center briefed the AFP, the Western Australia Police Force and the FBI on TeamP...
27/08/2026

In March 2026, KELA's Cyber Intelligence Center briefed the AFP, the Western Australia Police Force and the FBI on TeamPCP (UNC6780): the identities behind the aliases, the infrastructure, and the victim set.
Two men have now been charged in Western Australia. One of them was named in KELA's TeamPCP Threat Actor Profile in April 2026, supplied to law enforcement at the time.

The AFP alleges the campaign potentially compromised more than 1,000 organizations globally, enabled the theft of over 500,000 credentials, and led to the exfiltration of at least 300GB of data, with global remediation costs running into the hundreds of millions.
What makes TeamPCP worth studying: it started as a Telegram stolen-data broker and ended up inside the tooling defenders use to check their own code. Between March 19 and 24, 2026, four waves reached Trivy, Checkmarx KICS and AST GitHub Actions, OpenVSX and LiteLLM (CVE-2026-33634, added to CISA's KEV catalog on March 26).

The AFP has said industry reporting was crucial to its investigators. That is the argument for CTI that names people, not just indicators.
Full release: https://hubs.la/Q04vzVXQ0

Published analysis, from Telegram brokering through to identification: https://hubs.la/Q04vzCt-0

Finished threat intelligence report: https://hubs.la/Q04vzKZJ0

And we are walking the whole arc, including how the investigation actually came together, in a webinar on Monday, August 31: https://hubs.la/Q04vzGQj0

The move from Tor forums to Telegram has collapsed the time between data theft and exploitation from days to minutes. St...
13/07/2026

The move from Tor forums to Telegram has collapsed the time between data theft and exploitation from days to minutes. Stealer logs, session tokens, and card data now surface in real time, and most defenders never see it coming.
Read our breakdown of the top Telegram log & carding operations

https://hubs.la/Q04pj26D0

Our latest blog breaks down 7 CTEM best practices that reduce risk in practice, not theory: across cloud, SaaS, and hybr...
24/06/2026

Our latest blog breaks down 7 CTEM best practices that reduce risk in practice, not theory: across cloud, SaaS, and hybrid environments.
A few of them:
- Prioritize by exploitability and business impact, not CVSS volume
- Build one continuously updated asset inventory (everything else depends on it)
- Make remediation ownership explicit, or findings sit unfixed
- Track metrics tied to outcomes, not activity
The test is simple: if exposure isn't going down, the program isn't working.
Read the full breakdown: https://hubs.la/Q04msm2f0

The 2026 FIFA World Cup is the biggest sporting event in history. It's also one of the biggest attack surfaces ever asse...
04/06/2026

The 2026 FIFA World Cup is the biggest sporting event in history. It's also one of the biggest attack surfaces ever assembled.
16 host cities. 48 teams. 6 billion viewers. And a digital supply chain - ticketing, hospitality, transport, telecom, hundreds of vendors - that attackers have been probing months before the June 11 kickoff.
Here’s what KELA's CIC has identified:
→ 1.5M+ compromised accounts tied to FIFA-related domains
→ 7,300+ leaked credential instances (2,800 in the past year alone)
→ plaintext credentials for FIFA's own identity infrastructure
→ alleged RDP and cloud-console access to FIFA servers, listed on a cybercrime forum
Our expert threat research team has mapped the whole landscape and makes recommendations for your security team to nation-state espionage, industrial-scale fraud, and a dark web already trading the credentials that power attacks.
Get the report → https://hubs.la/Q04k1Xpm0

Let’s connect at ISS World Prague!Click below to book a meeting and secure your spot for an exclusive happy hour in down...
28/05/2026

Let’s connect at ISS World Prague!
Click below to book a meeting and secure your spot for an exclusive happy hour in downtown historical Prague before slots fill up!
Don't miss our expert sessions:
15:00 - 15:40 | Unmasking Cybercriminals: Intelligence Fusion for Modern Cybercrime Investigations
Or Lev, VP of Sales Engineering
15:45 - 16:25 | Making Threat Infrastructure Visible: The Power of NetFlow and CTI Fusion
Ron Breger, Threat Researcher
👇
https://hubs.la/Q04jbg-F0

KELA's Cyber Intelligence Center (CIC) exposes the Infrastructure Destruction Squad, a threat actor blending political h...
27/05/2026

KELA's Cyber Intelligence Center (CIC) exposes the Infrastructure Destruction Squad, a threat actor blending political hacktivism with profit-driven cybercrime. The group recently launched the BLACKNET-00 ransomware builder for $300, alongside critical infrastructure (ICS/SCADA) exploits and banking malware.
Learn why this low-cost, high-impact arsenal is drastically lowering the barrier to entry for novice cybercriminals and how this hybrid threat model changes the game for enterprise defense.

https://hubs.la/Q04j6DwG0

Come say hey and meet us at ISS World Europe 2026!As every year, KELA will be on the ground in Prague- this time at our ...
24/05/2026

Come say hey and meet us at ISS World Europe 2026!
As every year, KELA will be on the ground in Prague- this time at our new spot, Booth #24.
Our team, alongside CEO David Carmiel, will be there to discuss how KELA supports cybercrime investigations, proactive threat visibility, and deep, actionable cyber intelligence.
To keep things interesting, we’re also hosting a secret happy hour with a password-only twist ;)
Want the password? Come meet us:
https://hubs.ly/Q04hLYfh0

20/05/2026

Shavuot 2026 🌼🌻
🎥

Only 24 hours to go: join the KELA Webinar to discuss AI Defense and the State of Cybercrime 2026, where our experts wil...
19/05/2026

Only 24 hours to go: join the KELA Webinar to discuss AI Defense and the State of Cybercrime 2026, where our experts will deep dive into ground-truth intelligence from the cybercrime ecosystem, unpack the trends that shaped 2025, and share what security teams should prepare for in 2026 and beyond.

Date: May 20, 2026
Time: 07:00 PST | 09:00 EST | 16:00 CET

In this session, we’ll cover:
- Ransomware industrialization - analysis of the 45% surge in global victim volume, reaching 7,549 victims
- 7000% increase in MacOS specific InfoStealers
- CISA KEV surge - a 28.6% increase in high-risk vulnerabilities and what it means for the patching window
- Geopolitical sabotage - the 400% jump in coordinated “deniable proxy” operations

Register now: https://hubs.la/Q04gVtsG0

CISOs aren't measured on patches deployed. They're measured on business exposure mitigated. That's the shift Continuous ...
18/05/2026

CISOs aren't measured on patches deployed. They're measured on business exposure mitigated. That's the shift Continuous Threat Exposure Management (CTEM) is forcing across security teams - and why Gartner's framework keeps gaining ground over traditional vulnerability management.
In our latest blog, we break down the 5-stage CTEM cycle, where traditional VM falls short, and why most programs fail without external threat context.
Read the full breakdown: https://hubs.la/Q04g-6wB0

Address

* Derech Menachem Begin 52 Street (24th Floor)
Tel Aviv
6713702

Alerts

Be the first to know and let us send you an email when KELA posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to KELA:

Shortcuts

Share