Operation KillSwitch: Police Dismantle KillSec Ransomware Group
Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more than 110 terabytes of stolen data, cutting off further unauthorized access. Full details are in Europol’s release.
The takedown was part of Operation KillSwitch, led by German authorities. Investigators are looking into around 1,000 suspected attacks worldwide and believe the group’s main operator is just 16 years old. Three suspects were arrested and police searched eight properties in Greece, Romania, Spain, and the UK.
“On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access.” reads the press release published by EUROPOL. “KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.”
KillSec has been active since around 2024. The group broke into systems by exploiting software flaws and weak security, often targeting cloud storage. After stealing sensitive data, they posted victims on their leak site and demanded payment to keep the data private.
Investigators are looking into around 1,000 suspected attacks, with about 500 already confirmed. The number could change as police examine the seized evidence. In some cases, the group received ransom payments.
What stands out is the tooling: investigators found the group used AI to build and maintain its ransomware infrastructure and to help pick out potential victims. Ransomware crews adopting AI for target selection isn’t exactly a plot twist at this point, but seeing it confirmed in a law enforcement operation is still worth noting.
The suspected main operator is 16 years old. Another suspect, believed to be a developer, turned 18 in August 2026 and was under 18 when some of the alleged crimes happened. Investigators also found people who may have worked as a negotiator and an affiliate. The investigation is still ongoing.
The case also shows a growing trend in cybercrime: some complex ransomware operations are being run by very young people.
“The coordinated action targeted both the people behind KillSec and the systems they relied on. Authorities carried out eight house searches in Spain, Greece, Romania, and the United Kingdom, made three provisional arrests, and seized evidence and assets.” continues the press release.
Police brought five central servers under their control over the course of the investigation, including the systems used to manage KillSec’s operations and store stolen victim data. They also seized the group’s domains and redirected visitors to a law enforcement notice instead. Authorities are now working through seized devices, tracing cryptocurrency, and following up on evidence that could surface more victims and more people involved.
Ten countries took part in the operation: Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK, and the US. Europol and Eurojust also supported the investigation.
Europol shared intelligence and helped investigators work together, while Eurojust helped coordinate the legal side. Europol also helped organize the action across countries. In total, police made three arrests and searched eight properties in four countries at the same time.
Eurojust’s role was judicial coordination, getting authorities across jurisdictions to align on identifying suspects and tracking financial trails. Europol also ran a coordination center to make sure the action happened simultaneously across every country involved. Pulling off three arrests and eight searches at the same time, across four countries, isn’t a small logistics problem.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, KillSec Ransomware)
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.