Kelvin Security hacking group leader arrested in Spain

The Spanish police have arrested one of the alleged leaders of the 'Kelvin Security' hacking group, which is believed to be responsible for 300 cyberattacks against organizations in 90 countries since 2020.
News of the arrest of a leader of the financial component of the group was posted to the Spanish National Police's Telegram channel Sunday morning, stating that the threat actors are linked to attacks on government institutions across Spain, Germany, Italy, Argentina, Chile, Japan, and the United States.
Kelvin Security is a hacking group believed to have been active since 2013, leveraging vulnerabilities in public-facing systems to obtain valid user credentials and steal confidential data from breached systems.
The threat actors were active on hacking forums, such as RaidForums and BreachForums, where they would sell the stolen data or leak it for free to other threat actors.
Two notable examples of Kelvin Security breaches are an attack on Vodafone Italia in November 2022 and a breach on U.S. consulting firm Frost & Sullivan in June 2020.
In both cases, Kelvin Security attempted to sell the data they had obtained from the victimized companies on hacker forums.
More recently, in April 2023, cybersecurity firm Cyfirma reported discovering links between Kelvin Security and ARES, a newly-emerged cybercrime platform dedicated to selling databases stolen from state organizations.
The Spanish police said the law enforcement operation involved multiple police units and was coordinated by the Alicante Prosecutor's Office.
According to the document, the police arrested one of Kelvin Security's leaders, a Venezuelan national, in Alicante on December 7, 2023.
The threat actor was primarily involved in laundering the criminal proceeds obtained through sales of stolen data, using cryptocurrency exchanges to make it harder to trace the money.
The police say the investigation on the group started in December 2021, which shows how complicated it is to track and identify cybercriminals.
The police confiscated several electronic items for forensic investigation in the hope that they would lead to the identification of co-conspirators, data buyers, affiliates, and others.
Law enforcement shared a video showing the raid on the threat actor's home and their arrest.
Spain arrests 34 cybercriminals who stole data of 4 million people.
Police takes down BulletProftLink large-scale phishing provider.
Pirate IPTV network in Austria dismantled and $1.74 million seized.
HTC Global Services confirms cyberattack after data leaked online.
Tipalti investigates claims of data stolen in ransomware attack.


This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 11 Dec 2023 14:30:08 +0000


Cyber News related to Kelvin Security hacking group leader arrested in Spain

Kelvin Security hacking group leader arrested in Spain - The Spanish police have arrested one of the alleged leaders of the 'Kelvin Security' hacking group, which is believed to be responsible for 300 cyberattacks against organizations in 90 countries since 2020. News of the arrest of a leader of the ...
2 years ago Bleepingcomputer.com
CVE-2022-50280 - In the Linux kernel, the following vulnerability has been resolved: ...
3 months ago
25 Best Managed Security Service Providers (MSSP) - 2025 - Pros & Cons: ProsConsStrong threat intelligence & expert SOCs.High pricing for SMBs.24/7 monitoring & rapid incident response.Complex UI and steep learning curve.Flexible, scalable, hybrid deployments.Limited visibility into endpoint ...
6 months ago Cybersecuritynews.com
Encouraging Ethical Hacking Skills in Students - This article delves into the significance of encouraging ethical hacking skills in students and the numerous benefits it offers to individuals and society as a whole. Possessing ethical hacking skills can provide students with a competitive advantage ...
2 years ago Securityzap.com
BreachForums admin jailed again for using a VPN, unmonitored PC - The administrator behind the notorious BreachForums hacking forum has been arrested again for breaking pretrial release conditions, including using an unmonitored computer and a VPN. The BreachForums admin, Conor Fitzpatrick, was arrested on March ...
2 years ago Bleepingcomputer.com
Hacker hijacks Orange Spain RIPE account to cause BGP havoc - Orange Spain suffered an internet outage today after a hacker breached the company's RIPE account to misconfigure BGP routing and an RPKI configuration. The routing of traffic on the internet is handled by Border Gateway Protocol, which allows ...
2 years ago Bleepingcomputer.com
Weak password and infostealer blamed for Orange Spain outage The Register - A weak password exposed by infostealer malware is being blamed after a massive outage at Orange Spain disrupted around half of its network's traffic. The network provider is Spain's second most popular and on Wednesday evening confirmed its RIPE ...
2 years ago Go.theregister.com
Spain arrests hackers who targeted politicians and journalists - In recent years, Spanish police has been successful in tracking and arresting several high-profile cybercriminals. This February, they arrested a hacker believed to have breached Guardia Civil, the Ministry of Defense, NATO, the U.S. Army, and ...
6 months ago Bleepingcomputer.com Scattered Spider
Key Group uses leaked builders of ransomware and wipers | Securelist - The first discovered sample of Key Group, the Xorist ransomware, established persistence in the system by changing file extension associations. The .huis_bn extension added to encrypted files in the early versions of Key Group samples, Xorist and ...
1 year ago Securelist.com
Interpol operation arrests 3,500 cybercriminals, seizes $300 million - An international law enforcement operation codenamed 'Operation HAECHI IV' has led to the arrest of 3,500 suspects of various lower-tier cybercrimes and seized $300 million in illicit proceeds. The South Korean authorities led HAECHI operations and ...
2 years ago Bleepingcomputer.com
Europol shutters ransomware operation with kingpin arrests The Register - International law enforcement investigators have made a number of high-profile arrests after tracking a major cybercrime group for more than four years. A joint investigation team, spearheaded by French authorities, formed in 2019 to bring down a ...
2 years ago Theregister.com LockBit Rhysida
Nationwide Power Outages in Portugal & Spain Possibly Due to Cyberattack - A massive power outage struck the Iberian Peninsula on April 28, 2025, plunging millions of people into darkness as electricity supplies were suddenly cut across Spain and Portugal. Electric sector sources dismiss the possibility of a simple short ...
8 months ago Cybersecuritynews.com
Kraft Heinz investigates hack claims, says systems 'operating normally' - Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site. Kraft Heinz is one of the world's largest food and beverage companies, with ...
2 years ago Bleepingcomputer.com Qilin Snatch
CVE-2022-48895 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
Palo Alto Networks Recognized as a Leader in the 2023 Gartner Magic Quadrant for Endpoint Protection Platforms - Today, we are pleased to announce that Palo Alto Networks has been named a Leader in the 2023 Gartner Magic Quadrant for Endpoint Protection Platforms. Before we dive into the significance of this year's Magic Quadrant for EPP, I want to take a ...
2 years ago Paloaltonetworks.com
Spain arrests two over data leaks targeting state officials, journalists | The Record from Recorded Future News - Spain’s Interior Ministry said Yoel was responsible for stealing and leaking personal data belonging to high-ranking political figures, including Prime Minister Pedro Sánchez, President of the Congress of Deputies Francina Armengol and ...
6 months ago Therecord.media
Ransomed.vc shuts after apparent failure to sell operation The Register - Vc claims to have shut down for good after a number of suspected arrests. The announcement comes just weeks after the group announced it planned to sell the operation to "Someone that can be verified or is already verified as a trusted person." Two ...
2 years ago Theregister.com
Ragnar Locker ransomware developer arrested in France - Law enforcement agencies arrested a malware developer linked with the Ragnar Locker ransomware gang and seized the group's dark web sites in a joint international operation. Authorities from France, the Czech Republic, Germany, Italy, Latvia, the ...
2 years ago Bleepingcomputer.com Trigona Ragnar Locker
Spain arrests 34 cybercriminals who stole data of 4 million people - The Spanish National Police have dismantled a cybercriminal organization that carried out a variety of computer scams to steal and monetize the data of over four million people. Law enforcement in the country conducted 16 targeted searches in Madrid, ...
2 years ago Bleepingcomputer.com LockBit Ragnar Locker
Exabeam Recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, for the Fifth Year - Global cybersecurity leader that delivers AI-driven security operations and has been recognized as a Leader in the Gartner Magic Quadrant. Exabeam, a leading global entity in AI-driven security operations, today announced its designation as a Leader ...
1 year ago Cybersecurity-insiders.com
Exabeam Recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, for the Fifth Year - Global cybersecurity leader that delivers AI-driven security operations and has been recognized as a Leader in the Gartner Magic Quadrant. Exabeam, a leading global entity in AI-driven security operations, today announced its designation as a Leader ...
1 year ago Cybersecurity-insiders.com
Exabeam Recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, for the Fifth Year - Global cybersecurity leader that delivers AI-driven security operations and has been recognized as a Leader in the Gartner Magic Quadrant. Exabeam, a leading global entity in AI-driven security operations, today announced its designation as a Leader ...
1 year ago Cybersecurity-insiders.com
Exabeam Recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, for the Fifth Year - Global cybersecurity leader that delivers AI-driven security operations and has been recognized as a Leader in the Gartner Magic Quadrant. Exabeam, a leading global entity in AI-driven security operations, today announced its designation as a Leader ...
1 year ago Cybersecurity-insiders.com
Exabeam Recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, for the Fifth Year - Global cybersecurity leader that delivers AI-driven security operations and has been recognized as a Leader in the Gartner Magic Quadrant. Exabeam, a leading global entity in AI-driven security operations, today announced its designation as a Leader ...
1 year ago Cybersecurity-insiders.com
Exabeam Recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, for the Fifth Year - Global cybersecurity leader that delivers AI-driven security operations and has been recognized as a Leader in the Gartner Magic Quadrant. Exabeam, a leading global entity in AI-driven security operations, today announced its designation as a Leader ...
1 year ago Cybersecurity-insiders.com