Cybersecurity researchers have identified a possible connection between two Yemen-based hacking groups: the Belsen and the ZeroSeven. The conclusion came after extensive research into their operational patterns and attack methodologies.

The discovery comes amid growing concerns about sophisticated network attacks targeting critical infrastructure and operational systems across multiple continents.
The Belsen Group first emerged in January 2025, making headlines when it leaked 1.6 GB of sensitive data from over 15,000 vulnerable Fortinet FortiGate. The compromised information included IP addresses, system configurations, and VPN credentials, which the group initially shared freely on BreachForums and its TOR-based blog to establish its credibility with the cybercriminal community. The group's attack method focused on exploiting CVE-2022-40684, a critical authentication bypass vulnerability in FortiGate firewalls. The hackers maintained access to the victims' systems for over two years before the public disclosure.
See also: SystemBC botnet targets VPS servers
The ZeroSeven Group has been active since July 2024, initially operating on platforms such as NulledTo . Later, it expanded to BreachForums, CrackedTo, and Leakbase. The group specialized in data commercialization strategies , targeting organizations in Poland, Israel, the United States, the UAE, Russia, and Brazil. Their most notable breach involved Toyota 's US operations in August 2024. At that time, the hackers claimed responsibility for extracting 240GB of sensitive corporate data.

Connection between Belsen and ZeroSeven
KELA Cyber Team analysts observed significant operational similarities between the groups through forensic analysis of their posting patterns and communication styles. The investigation revealed that both organizations used identical headline formatting patterns . This distinctive formatting pattern was unique to these two perpetrators in KELA’s overall threat database.
Technical analysis revealed deeper connections through the investigation of the groups’ digital fingerprints. Researchers identified corresponding stylistic patterns in their social media (e.g., similar hashtags on Twitter). Both groups demonstrated similar operational security practices, maintaining multiple communication channels, including Tox, XMPP, Telegram, and X for negotiations with victims and data sales.
See also: Vulnerability in HubSpot's Jinjava engine exposes thousands of websites
The Belsen Group’s operational infrastructure included a sophisticated onion website for victim listings and contact information (registered under a partially masked email address). The administrator’s Telegram account (@BelsenAdmin, ID 6161097506) revealed additional information, from subscription models to cybersecurity certification groups, regional Arabic-speaking communities in Yemen, and technical education channels.
The ZeroSeven Group’s technical profile showed an evolution from their previous incarnation as “ZeroXGroup” on RaidForums. password reuse in database leaks and infostealers provided critical attribution links, connecting their operations to Yemeni threat actors affiliated with the Yemen Shield hacking group.

Although the conclusion is not 100% certain, the convergence of operational standards, geographic origins and practices indicates a coordinated effort between the two groups.
See also: Warning: Critical vulnerability in the GoAnywhere MFT platform
The possible connection between these groups raises concerns about coordinated attacks on critical infrastructure and operational networks on an international scale. The common features suggest that the attacks may originate from an organized entity with extensive capabilities. Organizations and researchers are urged to enhance monitoring, detection and prevention, as the two groups appear to share tools, techniques and operational strategies that make their attacks more effective and difficult to prevent.
KELA's research provides critical insights for understanding collaborations in cyberspace and emphasizes the importance of data interconnection, digital pattern analysis, and timely response to high-complexity threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
