Police dismantle KillSec ransomware gang allegedly led by 16-year-old

Operation KillSwitch

An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator.

The coordinated law enforcement action was carried out on September 30, involving authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom.

Europol and Eurojust also took part in the investigation, along with cybersecurity companies Bitdefender and Group-IB.

“The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide,” says Europol.

“Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.”

Law enforcement seizing evidence

The investigation began in 2025 and helped law enforcement identify suspects believed to be an administrator, developer, negotiator, and affiliate of the cybercrime group.

According to Europol, the suspected administrator and main operator of KillSec is only 16 years old. Another suspected member, described as a developer, turned 18 in August 2026 and was still a minor when some of the alleged crimes were committed.

Authorities have also identified individuals suspected of being a negotiator and an affiliate.

Hamburg Police said it investigated the group’s server infrastructure, which led to the identification and shutdown of five servers, including KillSec’s main server and several servers allegedly used to store stolen data.

One of the seized sites is KillSec’s dark web data leak site, hosted at https://ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion/, which now contains a seizure message.

“The domain, servers and all associated data linked to Operation KillSwitch have been taken into control by State Criminal Police Office of Hamburg and international law enforcement agencies,” reads the seizure banner.

Seized KillSec data leak site
Seized KillSec data leak site
Source: BleepingComputer

Clicking the seizure banner leads to the Operation KillSwitch website, which includes a law-enforcement video about the ransomware gang and the arrests.

[embedded content]

During the operation, law enforcement also seized at least 110 terabytes of stolen data to prevent continued unauthorized access, and conducted eight searches in Greece, Romania, Spain, and the United Kingdom and provisionally arrested three suspects.

Investigators have so far determined that around 500 of KillSec’s attacks were successful, though authorities cautioned that the numbers could change as they continue to analyze seized evidence.

At least 70 of the suspected attacks are linked to organizations in Germany, including 18 cases connected to Hamburg.

KillSec has been active since around 2024 and is accused of exploiting software vulnerabilities and poorly secured edge devices and platforms to breach corporate systems and steal sensitive data.

The threat actors used the stolen corporate data to extort victims via KillSec’s dark web leak site, with threats that the data would be published if a ransom was not paid.

Europol says that KillSec received “substantial” ransom payments from these data-theft attacks.

Investigators also discovered that members of the group used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.

Authorities are now examining seized computers, servers, and other data while attempting to trace KillSec’s alleged criminal proceeds, including cryptocurrency.

Investigators say the seized evidence could reveal further victims, attacks, and people involved with the ransomware operation.

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat