Police Dismantle KillSec Ransomware Group in International Operation

· Original article ↗

Summary

Operation KillSwitch seized KillSec’s leak site and five servers, including infrastructure used to store stolen data, and led to three provisional arrests. Authorities identified a 16-year-old as the group’s suspected main operator.

Key points

  • Authorities from 10 countries, with Europol and Eurojust, carried out the operation on September 30 after an investigation that began in 2025.
  • Three suspects were provisionally arrested, and eight properties were searched in Greece, Romania, Spain, and the United Kingdom.
  • Investigators identified five servers, including KillSec’s main server, and seized its dark web leak site.
  • Authorities seized at least 110 terabytes of stolen data to prevent continued unauthorized access.
  • Investigators estimate that about 500 KillSec attacks succeeded, including at least 70 suspected attacks against organizations in Germany; these figures may change.
  • KillSec allegedly exploited software vulnerabilities and poorly secured edge devices and platforms to breach organizations, steal data, and demand ransoms.
  • Authorities are analyzing seized evidence and tracing alleged criminal proceeds, including cryptocurrency.

Article Details

Event Type
International law enforcement operation against the KillSec ransomware gang
Impact
Authorities shut down five servers, including KillSec’s data leak site, seized at least 110 terabytes of stolen data, provisionally arrested three suspects, and searched eight properties. Investigators estimate that around 500 of approximately 1,000 suspected attacks were successful; they cautioned that the figures may change as seized evidence is analyzed.

Threat Actors

Countries