
On Thursday, October 1, 2026, Europol, the European Union Agency for Law Enforcement Cooperation, announced that law enforcement agencies had seized the servers and leak site of the KillSec ransomware group, and that a 16-year-old is suspected of serving as the group’s administrator and main operator.
Authorities took control of the leak site on September 30, securing at least 110 terabytes of data against further unauthorized access. The group had used the dark web site to name victims and threaten them with the release of stolen files unless they paid a ransom.
The action was part of Operation KillSwitch, an international investigation led by German authorities into roughly 1,000 suspected attacks worldwide. Three suspects were provisionally arrested, and eight properties were searched in Greece, Romania, Spain and the United Kingdom. Investigators also targeted the group’s criminal proceeds.
About 500 of the suspected attacks have so far been identified as successful, Europol said, adding that the figure could change as investigators examine the evidence seized during the operation.
The Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office led the investigation. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part, alongside Europol and Eurojust, the EU agency for judicial cooperation. The private cybersecurity companies Bitdefender and Group-IB also supported the effort.
According to Europol, KillSec has been active since around 2024. The group allegedly gained entry to organizations’ systems by exploiting software vulnerabilities and poorly secured access points, particularly those tied to cloud storage. Members then copied sensitive internal data to infrastructure under their control. Victims whose data was not paid for could see their files made available for free download, and in some cases the group collected substantial ransom payments, Europol said.
Investigators also found that the group used artificial intelligence to build and maintain its ransomware infrastructure and to identify potential victims.
Authorities in several countries began investigating attacks attributed to KillSec in early 2025. The inquiry identified suspects believed to hold distinct roles within the group: an administrator, a developer, a negotiator and an affiliate. The suspected administrator and main operator is 16.
The suspected developer turned 18 in August 2026 and was a minor when some of the alleged offenses took place. One person is believed to have acted as negotiator and another as an affiliate. Europol said inquiries into other possible members are continuing.
Over the course of the investigation, police brought five central servers under their control, including infrastructure used to manage the group’s operations and store data taken from victims. Authorities also seized domains operated by KillSec and redirected visitors to a law enforcement seizure notice. Searches in Spain, Greece, Romania and the United Kingdom yielded evidence and assets.
Investigators are now analyzing the seized devices and data and tracing the group’s proceeds, including cryptocurrency. Europol said the material may help identify additional victims, attacks and participants.
Europol said its European Cybercrime Centre pulled together intelligence from the national investigations, produced reports on the group’s activities, connected investigators with private-sector partners, and provided specialist support in tracing cryptocurrency and examining digital evidence. The Joint Cybercrime Action Taskforce, hosted at Europol, assisted with coordination, liaison and deconfliction among national authorities.
Eurojust helped judicial authorities work together to identify suspects, locate the group’s infrastructure and follow financial trails. The agency also supported planning of the action day and operated a coordination center to ensure that measures were carried out simultaneously around the world.
Source: Europol





Be the first to comment