KelvinSecurity
Attribution profile
- Type
- Criminal
- Location
- Russia
- Known incidents
- 5 incidents
- Sources
- 6 sources
- First seen
- 2022-09-01
- Last seen
- 2022-11-15
- Updated
- 2026-08-28 16:04
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
KelvinSecurity, also tracked as Kelvin Security, is a cybercriminal group that has been active since approximately 2020 and is believed to operate from Russia. The actors use the aliases KelvinSecurity and Kelvin Security when claiming responsibility for intrusions and advertising stolen material on underground forums. They describe themselves as “Business Intelligence Contractors” in some communications, but open‑source reporting characterizes them as a black‑hat or grey‑hat collective that monetizes compromised information rather than pursuing ideological or state‑directed goals. Their primary objective appears to be financial gain, as they consistently offer exfiltrated data, system accesses, proof‑of‑concept exploits and stolen databases for sale on platforms such as Breach Forums and through Telegram channels.
The group’s observed targeting focuses on Italian private‑sector organizations across several industries, including energy suppliers, pharmaceutical manufacturers, telecommunications providers and financial services firms, with occasional incidents involving multinational corporations such as BMW and the U.S. consulting firm Frost & Sullivan. Their tactics involve gaining access to victim networks, exfiltrating files ranging from megabytes to tens of gigabytes, and then publicizing the breach on criminal forums where they provide contact details for prospective buyers. They routinely sell the stolen datasets, offer access to compromised systems, and distribute proof‑of‑concept tools that demonstrate the vulnerabilities they exploited. Promotion of these offerings occurs via posts on Breach Forums, announcements on Telegram, and direct links that enable negotiation with interested parties. Representative campaigns include the November 2022 intrusion against an Italian energy company that yielded 11.5 GB of PDF documents, the September 2022 breach of an Italian pharmaceutical firm resulting in 3.15 GB of mixed‑format files, and the October 2022 compromise of an Italian telecom provider that exposed 314 MB of data. Earlier operations highlight a 2020 attack on BMW that leaked 384 k customer records sold on Raid Forums and a 2020 exposure of Frost & Sullivan databases offered on a hacker forum after an unsecured backup directory was discovered. These examples illustrate the group’s pattern of data theft, monetization through illicit marketplaces, and reliance on underground communication channels to facilitate transactions.
Incidents
Attributed incidents are available to members.
5 incidentsSources
Sources available to members: 6 sources.