International law enforcement agencies, in an operation dubbed "Operation KillSwitch," have dismantled the KillSec ransomware group. This coordinated action led to the seizure of the group's dark web leak site and five core servers, effectively disrupting its operations.
The operation involved authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom, with participation from Europol and Eurojust. Cybersecurity companies Bitdefender and Group-IB also assisted in the investigation.
Investigators identified a 16-year-old as the alleged administrator and main operator of the KillSec ransomware group. The investigation also identified a suspected developer who turned 18 in August, a suspected negotiator, and a suspected affiliate. The search for other potential members is ongoing.
Three provisional arrests were made, and eight homes were searched in Greece, Romania, Spain, and the UK as part of the operation.
On September 30, police took control of KillSec's dark web leak site, blocking unauthorized access to at least 110TB of data believed to be stolen from victims. The group used this site to threaten organizations with publishing stolen files unless a ransom was paid, offering files as free downloads for those who refused.
Authorities also gained control of five core servers, which the gang used to manage operations and store stolen victim data. KillSec's domains now redirect visitors to a law enforcement seizure notice.
KillSec is linked to approximately 1,000 suspected attacks worldwide. The investigation into the group began in 2025, leading to the identification of key suspects within the cybercrime organization.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Police in Spain arrested a 16-year-old suspected of operating the KillSec ransomware group, which stole data and demanded payment to prevent its publication. This operation also led to two other arrests in the UK and Romania, and the seizure of KillSec's leak site and servers, disrupting the group's activities.
Police in Spain arrested the suspected 16-year-old leader of the KillSec ransomware group, a Romanian national, as part of an international operation that also seized the group's leak site and servers. The group, which emerged in 2024, launched approximately 1,000 attacks, exploiting cloud storage vulnerabilities to extort victims.
An international law enforcement operation, "Operation KillSwitch," seized the KillSec ransomware gang's servers and data leak site, leading to three arrests. Authorities identified a 16-year-old as the group's suspected main operator and seized 110 terabytes of stolen data.
Europol and international law enforcement agencies have shut down the KillSec ransomware group, identifying a 16-year-old as its alleged administrator and main operator. The operation seized KillSec's dark web leak site and five core servers, blocking access to 110TB of stolen data and disrupting the group's operations.