What Does Managed Threat Intelligence Actually Catch? Five Investigations to Note

Our first guide, What is Managed Threat Intelligence, covers the definition, the cost case against building a process in-house, and the US regulatory pressure that come along with it. In this blog we’ll walk you through the proof layer, in these five real investigations from CybelAngel’s REACT team.

Here’s the part most vendor content about threat intelligence skips: none of these five end with a clean resolution. A claim turns out partly inflated once you check the actor’s own track record. An accused group publicly denies involvement and the attribution stays open. An actor hits a second target ten weeks after the first, in the same region, using the same playbook. That’s real investigative work, and it’s a better argument for analyst-led intelligence than a tidy success story would be, because a dashboard can tell you an indicator matched. It takes a person to sit with an unresolved picture and still tell a security team something they can act on.

InvestigationTypeDateWhat REACT’s investigation foundWhere it stands
Accenture / “888”Rapport FlashJuly 2026The actor’s “sample” was actually a full 6.17 million-line directory listing, verified as real, not a limited teaserAccenture calls it isolated and remediated; the same actor has a documented history of overstating past claims
VercelRapport FlashApril 2026The breach traced back to a stolen OAuth token from an unrelated third-party AI tool, not Vercel’s own perimeterAttribution unresolved; the accused group, ShinyHunters, publicly denied involvement
Pure Incubation Ventures / KryptonZambieNote sur les menacesoctobre 2024The actor operates under at least five aliases and runs a 300+ subscriber Telegram channel for distributing stolen dataTargeting has expanded from India to a global list; the actor remains active
CNSS / JabarootFlash Report + follow-up Threat NoteApril to June 2025A 312% surge in regional data-leak volume over the ten weeks following the initial breachThe same actor struck a second target (ANCFCC) ten weeks later; no resolution, only continued tracking
Israel-Iran conflictRapport FlashJune 2025APT34 and APT42 activity surged within 48 hours of the physical strikeOngoing; monitored as a live geopolitical conflict, not a closed incident

1. How CISOs can tell an inflated claim from a real one

On July 6, 2026, a threat actor using the alias “888” posted a listing on the cybercrime forum PwnForums claiming 35GB of stolen Accenture data, source code, RSA and SSH keys, Azure Personal Access Tokens, and Azure Storage access keys, for sale in a one-time transaction payable in Monero. CybelAngel’s REACT team investigated as the listing broke. Accenture confirmed the incident to BleepingComputer two days later, calling it an isolated, remediated matter, but didn’t confirm the volume or specific categories of data the actor claimed to hold.

Here’s where the actor’s own history mattered more than the technical evidence. “888” had tried this before: a June 2024 listing claimed an Accenture-linked dataset covering roughly 32,826 current and former employees. Accenture publicly disputed that claim at the time, stating the real dataset referenced only three individuals. That history doesn’t prove the 2026 claim is exaggerated, but it’s exactly the kind of pattern that changes how a validated investigation approaches the new one.

So CybelAngel’s REACT team checked the evidence directly rather than taking the listing at face value. The actor had attached a file described as a “sample.” REACT’s review found it wasn’t a limited sample at all, it was a full recursive directory listing, roughly 250MB and just over 6.17 million lines, structurally consistent with the Azure DevOps repository shown in the actor’s own screenshot. The listing enumerated 87 distinct applications, 56 of which included environment-specific credential files (.env.production, .env.development, .env.staging), several with committed SQL database dumps and administrator-account files sitting alongside them. A number of the top-level folders were named and branded after specific Accenture clients, which is the detail that turns a single-vendor incident into a supply-chain question for everyone who shares infrastructure with that vendor.

Two things were true at once here, which is exactly the nuance a raw alert can’t carry: the actor has a documented history of overstating past claims, and this particular sample independently checked out as real and substantial. Believing either half on its own would have been the wrong call.

2. Where CISOs can lose visibility without ever being breached themselves

On April 19, 2026, Vercel, the company behind the widely used Next.js framework, disclosed unauthorized access to internal systems. Within hours, someone using the ShinyHunters persona claimed responsibility and put the data up for sale. When BleepingComputer contacted the actual ShinyHunters group, they denied involvement. Attribution never closed. CybelAngel’s analysts are still monitoring it.

What makes this investigation worth including is where the intrusion actually started, nowhere near Vercel at all. CybelAngel’s Cyber Operations team traced it through three stages. First, months earlier, a third-party AI productivity vendor was infected with infostealer malware on a privileged employee’s machine, at a company with no relationship to Vercel at all. Second, a Vercel employee had connected their corporate Google Workspace to that same third party’s now-deprecated consumer AI tool via OAuth, granting broad permissions. When the third party’s environment was breached, every connected user’s OAuth tokens were exposed, including that Vercel employee’s. Third, the attacker used the stolen token to take over the Workspace account and pivot directly into Vercel’s internal environment.

Vercel’s own perimeter was never touched. No zero-day, no phishing email aimed at a Vercel engineer, just an employee’s decision, made months earlier, to connect a convenient AI tool to a corporate account. CybelAngel’s analysts also traced the same upstream compromise to credentials exposed at other development and observability platforms, meaning the blast radius extended well past Vercel’s own customer list. As the investigation put it: shadow AI is shadow IT’s faster-moving successor, and the attack surface now extends into every consumer AI tool an employee has authorized against a corporate identity provider, whether security teams know about it or not.

3. How CISOs can track an actor across five different aliases

In March 2024, an actor calling themselves KryptonZambie posted a database belonging to Pure Incubation Ventures, a Massachusetts investment firm, for sale on Breach Forums. CybelAngel’s investigation found two tables were exposed, one covering potential members and one covering contacts, containing names, addresses, emails, job titles, company details, LinkedIn URLs, and encrypted passwords, spanning current and past records tied to one of the firm’s B2B data subsidiaries.

The more useful part of this investigation wasn’t the leak itself, it was building an actual profile of who was behind it. KryptonZambie turned out to operate under at least four other aliases (Barboza, robinhouse0xc4, krpzambie0xc4, robinFlexSnow), runs a Telegram channel called Robinhouse with over 300 subscribers used for distributing stolen data, and had a documented pattern: early activity concentrated on Indian companies before expanding to a global target list. None of that comes from the leaked database. It comes from tracking an actor’s behavior across multiple incidents and platforms over time, which is precisely the kind of continuity a one-off automated alert has no mechanism for building.

4. Why one incident report is never the end of the story

On April 8, 2025, an actor using the alias Jabaroot claimed responsibility for breaching Morocco’s National Social Security Fund (CNSS) on BreachForums: more than 50,000 PDF files and over a million rows across two databases, touching the Mohammed VI Investment Fund, major Moroccan banks, and even Rabat’s Israeli liaison office. CybelAngel’s REACT team covered it as it broke, then followed the story as it escalated.

The part that mattered more came afterward. In the ten weeks following the CNSS breach, CybelAngel tracked a 312% increase in leaked data volume attributed to Moroccan entities, more than 5 terabytes published across clear and dark web platforms between April 8 and June 15, against 1.61 terabytes for the entirety of 2024. Public attack claims against Moroccan assets jumped from 63 (January 2024 through early April 2025) to 88 in the two and a half months after the breach, a 43% increase in incident volume. No ransom demands were detected anywhere in that surge. The motivation was political, not financial, aimed at destabilizing institutions rather than extracting payment.

Then, on June 2, 2025, Jabaroot struck again, this time against Morocco’s National Agency for Land Registry (ANCFCC): over 10,000 property certificates, 20,000 civil records, and files touching senior officials including the head of Morocco’s foreign intelligence service, more than 4 million documents and 4 terabytes in total. Further investigation suggested Jabaroot isn’t a single actor at all but a loosely affiliated collective drawing from several North African and neighboring countries.

5. How CISOs can prepare when geopolitics becomes their threat model overnight

Following Iran’s June 13 missile strikes against Israeli military positions, pro-government threat groups on both sides activated cyber operations within hours of the physical escalation. Israeli CERTs reported a surge in activity from Iran-linked APT34 and APT42 within 48 hours of the strike, focused on reconnaissance, credential harvesting, and probing of Israel’s energy, telecom, and transport sectors. Israeli-aligned operators responded with destructive malware and low-intensity DDoS activity against Iranian infrastructure. Security researchers tracked a 700% increase in related cyber incidents, phishing, malware infections, and network disruption, in the weeks that followed.

This is the category most business threat intelligence entirely ignores: geopolitical events that become a cyber threat model within days, not months. Organizations with no direct connection to either country, but with a presence in energy, telecom, or transport, or a supply chain that touches the region, inherited real exposure within 48 hours of a missile strike they had nothing to do with. A monitoring function built around your own industry’s usual threat actors has no mechanism for catching a threat model that changes because of a geopolitical event on the other side of the world. Continuous, broad monitoring does.

Why none of these five investigations end cleanly

None of them were caught by a signature match. None involved a piece of malware with a name everyone would recognize. What they share is that each required a person to hold two things in tension at once: the evidence in front of them, and everything known about the actor, the pattern, or the geopolitical context surrounding it. An automated feed can surface a listing. It can’t tell you that the same alias inflated a claim two years ago, that a denial from the accused group doesn’t settle attribution, or that an actor’s second strike ten weeks later is part of the same campaign as the first.

That’s the case for managed threat intelligence: not that it produces cleaner outcomes, but that it produces honest ones. A vendor selling certainty about every finding is selling something these five investigations don’t support.

FAQ

They’re real, publicly documented flash reports and threat notes published by CybelAngel’s REACT team, covering incidents at organizations that are not CybelAngel clients in most cases (Accenture, Vercel, Pure Incubation Ventures, CNSS, ANCFCC). They’re used here to show the investigative process REACT applies, not as anonymized versions of confidential client work.

Because real intelligence work usually doesn’t. Attribution can stay contested (Vercel), actors can strike again after the first report (Jabaroot), and a claim can be simultaneously real and historically prone to exaggeration (888). Presenting tidier outcomes than the evidence supports would be less accurate and, longer term, less useful to a security team making a real decision.

A flash report is CybelAngel’s fast-turnaround format for a breaking incident, typically published within days. A threat note is often a deeper or follow-up analysis, sometimes tracking an actor or campaign over a longer window, as with the CNSS-to-ANCFCC threat note that connected two attacks ten weeks apart.

Behavioral patterns, which platforms an actor uses, which aliases they operate under, which regions or industries they’ve targeted historically, tend to stay relevant well after a specific incident ages out. The Pure Incubation Ventures investigation is from October 2024 and its specific data is dated, but the profiling method it demonstrates doesn’t expire the same way.

À propos de l'auteur