Under attack?
What we do when the clock is running
Ransomware negotiation, incident intelligence, threat actor engagement and takedowns: four things KELA’s Cyber Intelligence Center can start today, alongside your incident response team, your board and your insurer. Pick one or all of them.
Ransomware negotiation
Secure, anonymous channels with the operators. Lower demands and better terms, decryption keys, negotiated removal of stolen data, daily updates and a post-incident report.
Incident intelligence support
Dark web and OSINT intelligence fed into your response: the access that was used, what is already leaked or for sale, the actor’s tactics, and answers to your team’s questions as they come.
Threat actor engagement
Direct engagement with the attackers to collect intelligence on access, leaks and indicators, run by analysts who speak their languages and their slang.
How it works
1. You reach us
Use the form. Tell us what you see: a ransom note, a leak claim, a suspicious login, a domain. Partial information is fine.
2. We triage within hours
Analysts validate the claim, identify the group and pull everything KELA already holds on them: their playbook, their negotiation habits, their leak sites.
3. We act with you
Negotiation, takedowns, briefings for your board and insurer, and updates every day until the incident is closed.
Put intelligence on your side.
KELA’s Cyber Intelligence Center works alongside your incident response team, your board and your insurer with what only the underground can tell you: who is behind it, what they took, what they want, and what to do next.
Get Started for Free
Fill in your details and we will follow up right away. 24×7, multilingual analysts. A human replies, not a ticket.
Why KELA in a crisis
Fifteen years inside the underground
KELA has monitored cybercrime forums, markets and messaging channels since 2009, and tracked 6,418 ransomware victims from January to August 2026 alone (KELA data lake).
Analysts, not a hotline
12+ analysts with military intelligence and cybersecurity backgrounds, multilingual and fluent in criminal slang, working 24×7 across time zones.
Group-by-group knowledge
Each crew negotiates differently. KELA studies how they open, how they move and whether they keep their word, and tailors the approach to the group you face.
What we can and cannot promise
Expert handling lowers the risk, the cost and the confusion. It does not remove the uncertainty. Criminals can push for more, change terms, fail to decrypt or leak data after payment. We will tell you what we know, what we do not, and what each choice is likely to cost, so the decisions stay yours and stay informed.
Prevent the next one: solutions by threat
Ransomware crews, stolen identities, phishing kits, exploited CVEs, exposed suppliers and abused AI: pick the threat and get the intelligence, the monitoring and the response built around it.
FAQ
What happens after I submit the form?
An analyst from KELA’s Cyber Intelligence Center contacts you, usually within hours, to understand the situation and agree the scope: negotiation, intelligence support, takedowns, or all three. Nothing is started without your go-ahead.
Does KELA pay ransoms?
No. KELA negotiates on your behalf through secure, anonymous channels and advises on the terms. Any decision to pay, and the payment itself, stay with you and your advisers.
Can stolen data really be removed?
Often it can be negotiated off leak sites, bot markets and shops, and phishing domains can be taken down. Removal is never guaranteed, and copies may already exist, which is why we also tell you exactly what was taken so you can act on it.
Do you work with our incident response firm and insurer?
Yes. KELA is the intelligence layer beside them: we supply the underground view, the actor’s profile and the negotiation, while they handle containment, forensics and the claim.
What do you need from us?
Whatever you have: the ransom note or contact details, the claim on a leak site, suspicious logins or domains, and the names of your response partners. We take it from there.
Not under attack yet?
Most incidents start with a login bought on a forum weeks earlier. KELA finds it first.



