Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Police dismantle KillSec ransomware group, identify 16-year-old suspect

An international law enforcement operation has seized the data leak site and servers of the KillSec ransomware group and led to three provisional arrests. Investigators identified a 16-year-old as the group’s suspected main operator.

Dubbed Operation KillSwitch, the coordinated action took place on September 30. Authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland and the United Kingdom took part, alongside Europol, Eurojust and cybersecurity companies Bitdefender and Group-IB. The investigation, led by German authorities, began in 2025 and concerns around 1,000 suspected attacks worldwide.

Authorities searched eight properties in Greece, Romania, Spain and the United Kingdom. Hamburg Police said investigators identified and shut down five servers, including KillSec’s main server and others allegedly used to store stolen data. At least 110 terabytes of stolen data were seized to prevent further unauthorized access.

Investigators have so far determined that around 500 attacks attributed to KillSec were successful. Authorities cautioned that the figure could change as they analyze the seized evidence. At least 70 suspected attacks involved organizations in Germany, including 18 linked to Hamburg.

KillSec has been active since around 2024 and is accused of exploiting software vulnerabilities and poorly secured edge devices and platforms to breach corporate systems. The group allegedly used stolen data to extort victims through its dark web leak site. Europol said members also used artificial intelligence to help build and maintain ransomware infrastructure and identify potential victims. Authorities are examining seized evidence and tracing suspected criminal proceeds, including cryptocurrency.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.