KillSec ransomware group downed by multinational law enforcement team and Europol

Sponsor ad - 728w x 90h (at 72 dpi)

At the end of September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom.

The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.

Piracy Monitor Supporter

KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation. KillSec had been active since around 2024.

Stolen data used to pressure victims

The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organisations’ systems. Its members then copied sensitive internal data to infrastructure under their control.

Victims were named on the group’s dark web leak site and threatened with publication of their data unless paid. Where a victim did not pay, the stolen files could be made available for free download. In some cases, the group obtained substantial ransom payments.

Investigators also uncovered how the group used AI to build and maintain its ransomware infrastructure and identify potential victims.

Operation Kill Switch

Authorities in several countries began investigating attacks attributed to KillSec in early 2025. The international investigation identified suspects believed to have taken on different roles within the group, including an administrator, a developer, a negotiator, and an affiliate.

The alleged administrator and main operator is 16 years old. A suspected developer turned 18 in August 2026 and was a minor when some of the offences were committed. Investigators also identified one person believed to be in a negotiator role and another in an affiliate role. Enquiries into other possible members are continuing.

Servers and criminal assets targeted

The coordinated action targeted both the people behind KillSec and the systems they relied on. Authorities carried out eight house searches in Spain, Greece, Romania, and the United Kingdom, made three provisional arrests, and seized evidence and assets.

Over the course of the investigation, five central servers were brought under police control, including infrastructure used to manage the group’s activities and store data taken from victims. Authorities also took control of domains operated by KillSec and redirected visitors to a law enforcement seizure notice.

Servers seized by Operation Kill Switch. Image source: EUROPOL

Investigators are examining the seized devices and data and tracing the group’s criminal proceeds, including cryptocurrency. The evidence may help identify further victims, attacks, and people involved.

European coordination

The operation was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States took part in the investigation, alongside Europol and Eurojust. The investigation was also supported by the private cybersecurity companies Bitdefender and Group-IB.

As investigations into KillSec developed in several countries, Europol helped bring the intelligence together. Its European Cybercrime Centre produced reports on the group’s activities, connected investigators with private-sector partners, and provided specialist support to trace cryptocurrency and examine digital evidence.

The Joint Cybercrime Action Taskforce (J-CAT) hosted at Europol also supported coordination, liaison, and deconfliction efforts with national authorities.

Through coordination by Eurojust, judicial authorities worked together to identify suspects, find the group’s infrastructure and follow financial trails. The Agency supported the planning of the action day and ran a coordination centre to ensure the measures were executed simultaneously worldwide.

The following authorities participated in the investigation:

  • Belgium: Public Prosecutor’s Office Brussels; Federal Police (Federale Politie/ Police Fédérale)
  • Finland: National Bureau of Investigation (Keskusrikospoliisi)
  • Germany: Public Prosecutor’s Office Hamburg; Federal Criminal Police Office (Bundeskriminalamt); Hamburg State Criminal Police Office (Landeskriminalamt Hamburg)
  • Greece: Hellenic Police (Ελληνική Αστυνομία)
  • Netherlands: Centre for International Legal Assistance in Criminal Matters – Amsterdam
  • Romania: National Police (PoliÈ›ia Română)
  • Spain: Investigative Court number 20 of Barcelona; Public Prosecutors’ Office Barcelona; Mossos d’Esquadra; Guardia Civil
  • Switzerland: Federal Office of Police (fedpol), Office of the Attorney General of Switzerland (OAG)
  • United Kingdom: Eastern Region Special Operations Unit (ERSOU)
  • United States: United States Attorney’s Office for the District of Puerto Rico; Federal Bureau of Investigation (FBI) San Juan Field Office

Why it matters

The European Multidisciplinary Platform Against Criminal Threats (EMPACT) tackles the most important threats posed by organised and serious international crime affecting the EU. EMPACT strengthens intelligence, strategic and operational cooperation between national authorities, EU institutions and bodies, and international partners. EMPACT runs in four-year cycles focusing on common EU crime priorities.

Further reading

Teenager suspected of leading KillSec ransomware group, as law enforcement seizes servers and leak site. Press release. October 1, 2026. EUROPOL

From our Sponsors