CSIDB logo
Threat actor

Kelvin Onaghinor

Attribution profile

Type
Criminal
Location
Nigeria
Known incidents
1 incident
First seen
2016-12-18
Last seen
2016-12-18
Updated
2026-07-31 00:46
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Kelvin Onaghinor, also known by the alias Kelvin Onaghinor, is a Nigerian national who has been publicly linked to a cyber intrusion targeting Los Angeles County government systems. According to a 2016 report, he was charged with nine counts that include unauthorized computer access and identity theft in connection with a phishing campaign that compromised the email credentials of 108 county employees. The incident occurred in May 2016 and was discovered after officials noticed unauthorized access to accounts containing confidential client and patient information. Forensic analysis indicated that the breach could have exposed personal data belonging to more than 750,000 individuals who had interacted with various county departments, such as names, dates of birth, Social Security numbers, driver’s license details, financial account information, home addresses, phone numbers, and medical records. Although no evidence of actual data misuse was confirmed, the potential scope of the exposure prompted the county to begin notification efforts and to offer free identity monitoring services to those who might have been affected.

The targeting demonstrated in this case focused on a governmental entity within the United States, specifically the Los Angeles County administration, indicating a regional focus on U.S. public sector organizations. The strategic objective implied by the filed charges centers on financial gain through identity theft, as the allegations include the unlawful acquisition and potential use of personally identifiable information for fraudulent purposes. The reported tactics, techniques, and procedures were limited to the use of deceptive phishing emails that tricked employees into revealing their usernames and passwords; no malware families, exploit kits, or additional tooling were described in the source material. Consequently, the actor’s initial access relied solely on social engineering to obtain valid credentials, which were then used to navigate the compromised email environment.

Legal proceedings against Onaghinor have highlighted the challenges of prosecuting cross‑border cybercrime, with authorities noting the need to secure evidence from third‑party service providers and to trace digital footprints across multiple jurisdictions. If convicted on all counts, he faces a maximum sentence of thirteen years in state prison. In response to the breach, Los Angeles County implemented enhanced security controls, delayed public notification to protect the integrity of the ongoing investigation, and provided affected individuals with credit monitoring, identity consultation, and identity restoration services. No public information links Onaghinor to any state‑sponsored program, criminal consortium, or broader hacking group, and the available sources do not attribute any additional campaigns or operations to him beyond the described Los Angeles County incident.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB