Skip to content
    Security Operations (SecOps)StartupCybercrime Intel

    KELA

    Tel Aviv cybercrime intelligence firm monitoring dark web and underground sources; delivers attack-surface, ransomware and credential-leak intel for enterprises and governments

    Mkt Cap / ValPrivate
    Growth+101% YoY
    Mar 2026: Reported 101% YoY bookings growth on enterprise threat intel demand
    Purpose-built cybercrime underground coverage with automated collection plus analyst finish few rivals match
    Analyst take · Competitive edge

    SWOT Analysis

    Strengths
    • Deep visibility into cybercrime underground, dark web and closed forums
    • 101% YoY bookings growth reported Mar 2026 shows strong momentum
    • Operating since 2009 with government-grade intelligence tradecraft
    • Consolidated platform spanning threat intel, attack surface and identity leaks
    • Highest number of 5-star reviews in its Gartner Peer Insights category
    Opportunities
    • Surging infostealer intel demand: 2.86B credentials stolen in 2025
    • AI-driven threat actor tracking as offensive AI goes autonomous
    • Telco and government expansion after major 2026 sector deals
    • Ransomware victimology data licensing to insurers and MSSPs
    Weaknesses
    • Smaller brand than Recorded Future, Mandiant and CrowdStrike intel arms
    • Niche cybercrime focus needs pairing with broader threat intel feeds
    • Modest capital raised versus US-funded competitors
    • Analyst-heavy workflows can strain lean SOC teams
    Threats
    • Platform vendors bundling dark web monitoring at no extra cost
    • Sources going dark as forums move to closed channels
    • Legal and ethical scrutiny of underground data collection
    • Consolidation squeezing standalone threat intel pure-plays

    User Sentiment

    Synthesized from G2, Gartner Peer Insights, and analyst review data.

    What users love
    • Unmatched raw visibility into cybercrime forums and markets
    • Timely alerts on leaked credentials and stolen data
    • Strong ransomware victim and threat actor tracking
    • Responsive analyst support and finished intelligence
    Common complaints
    • UI feels dated next to newer threat intel platforms
    • Alert volume needs tuning to avoid noise
    • SOAR and ticketing integrations could be deeper

    Customer Profile

    Who buys this

    Typical segments

    Large enterprises with brand exposureGovernment, telco and financial institutions

    Typical buyer

    CTI lead or SOC manager

    Top use cases
    1. 1Dark web monitoring for leaked credentials
    2. 2Ransomware and threat actor tracking
    3. 3External attack surface and fraud intelligence

    Future Focus Areas

    1

    Autonomous AI threat research agents

    2

    Identity and infostealer intelligence expansion

    3

    Active defense and takedown services

    4

    Vertical intel packages for telco and government