Cybercrime

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.

KillSec ransomware shut down

Europol says a 16-year-old is believed to be the administrator and main operator of KillSec, a ransomware group linked to roughly 1,000 suspected attacks worldwide.

The teen was identified in Operation KillSwitch, an international investigation led by police and prosecutors in Germany. Authorities made three provisional arrests and searched eight homes in Greece, Romania, Spain, and the UK.

Investigators also identified a suspected developer who turned 18 in August, as well as one suspected negotiator and one suspected affiliate. The hunt for other possible members continues.

On Wednesday, police took over KillSec’s dark web leak site and blocked further unauthorized access to at least 110TB of data, presumably stolen from victims. Europol said the group used the site to threaten organizations with publishing stolen files unless they paid a ransom. Victims who refused could see their files offered as free downloads.

Over the course of the investigation, police also gained control of five core servers, including systems the gang used to manage its operations and hold data stolen from victims. KillSec’s domains now redirect visitors to a law enforcement seizure notice.

KillSec, active since around 2024, broke into organizations through software flaws and weakly protected entry points, especially into cloud storage. It then copied sensitive internal data to its own infrastructure, and in some cases victims paid substantial ransoms.

Advertisement. Scroll to continue reading.

Authorities are currently aware of roughly 500 successful attacks. Prior to its takedown, the KillSec leak website listed roughly 450 victims. 

Investigators are analyzing seized devices and data and tracing KillSec’s criminal proceeds, including cryptocurrency. They hope the evidence will lead to additional victims, attacks, and suspects.

Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK, and the US took part in the operation, which received support from cybersecurity firms Bitdefender and Group-IB.

Related: Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Related: ShinyHunters Defiant After FBI Calls on Members to Come Forward

Related Content

Cybercrime

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

Cybercrime

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Cybercrime

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.

Cybercrime

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.

Cybercrime

The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.

Cybercrime

Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version