Security Operations (SecOps)StartupCybercrime Intel
KELA
Tel Aviv cybercrime intelligence firm monitoring dark web and underground sources; delivers attack-surface, ransomware and credential-leak intel for enterprises and governments
Mkt Cap / ValPrivate
Growth+101% YoY
Mar 2026: Reported 101% YoY bookings growth on enterprise threat intel demand
Purpose-built cybercrime underground coverage with automated collection plus analyst finish few rivals match
SWOT Analysis
Strengths
- Deep visibility into cybercrime underground, dark web and closed forums
- 101% YoY bookings growth reported Mar 2026 shows strong momentum
- Operating since 2009 with government-grade intelligence tradecraft
- Consolidated platform spanning threat intel, attack surface and identity leaks
- Highest number of 5-star reviews in its Gartner Peer Insights category
Opportunities
- Surging infostealer intel demand: 2.86B credentials stolen in 2025
- AI-driven threat actor tracking as offensive AI goes autonomous
- Telco and government expansion after major 2026 sector deals
- Ransomware victimology data licensing to insurers and MSSPs
Weaknesses
- Smaller brand than Recorded Future, Mandiant and CrowdStrike intel arms
- Niche cybercrime focus needs pairing with broader threat intel feeds
- Modest capital raised versus US-funded competitors
- Analyst-heavy workflows can strain lean SOC teams
Threats
- Platform vendors bundling dark web monitoring at no extra cost
- Sources going dark as forums move to closed channels
- Legal and ethical scrutiny of underground data collection
- Consolidation squeezing standalone threat intel pure-plays
User Sentiment
Synthesized from G2, Gartner Peer Insights, and analyst review data.
What users love
- Unmatched raw visibility into cybercrime forums and markets
- Timely alerts on leaked credentials and stolen data
- Strong ransomware victim and threat actor tracking
- Responsive analyst support and finished intelligence
Common complaints
- UI feels dated next to newer threat intel platforms
- Alert volume needs tuning to avoid noise
- SOAR and ticketing integrations could be deeper
Customer Profile
Who buys this
Typical segments
Large enterprises with brand exposureGovernment, telco and financial institutions
Typical buyer
CTI lead or SOC manager
Top use cases
- 1Dark web monitoring for leaked credentials
- 2Ransomware and threat actor tracking
- 3External attack surface and fraud intelligence
Future Focus Areas
1
Autonomous AI threat research agents
2
Identity and infostealer intelligence expansion
3
Active defense and takedown services
4
Vertical intel packages for telco and government