- Authorities provisionally detained three suspects and conducted eight searches in Greece, Romania, Spain and the United Kingdom.
- Investigators consider a 16-year-old the likely administrator and lead operator of KillSec.
- Law enforcement seized five central servers and took control of a leak site containing at least 110 TB of information.
Law enforcement authorities seized infrastructure linked to the KillSec group and provisionally detained three suspects on Sept. 30, 2026, as part of the international KillSwitch operation. The action disrupted a group linked by investigators to roughly 1,000 suspected cyberattacks worldwide and prevented further unauthorized access to at least 110 TB of information.
The Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office led the operation, according to Europol. Authorities conducted eight searches in Greece, Romania, Spain and the United Kingdom and provisionally detained three suspects.
Investigators consider a 16-year-old teenager the likely main operator of KillSec. Another suspect, believed to have served as the group’s developer, turned 18 in August 2026 but may have committed some of the alleged offenses while still a minor.
Authorities seize servers and leak site
Law enforcement took control of five central servers used to manage KillSec’s activities and store stolen information. Authorities also seized devices and assets and redirected the group’s domains to a law enforcement notice announcing the infrastructure seizure.
Investigators gained control of KillSec’s ransomware leak site, where the attackers published victims’ information or threatened to release it. The seized infrastructure contained at least 110 TB of information, which authorities said is now protected against further unauthorized access.
KillSec has operated since around 2024. According to investigators, members exploited software vulnerabilities and poorly secured access points, including access to cloud storage, to enter organizations’ systems and copy sensitive internal information.
The attackers then threatened to publish the stolen material on a darknet site. If an organization refused to pay a ransom, the files could be offered for free download. In some cases, the attackers received substantial payments.
Investigators have so far confirmed about 500 successful attacks among roughly 1,000 suspected incidents. The final total may change after authorities analyze the seized devices and information.
Law enforcement also found that KillSec used artificial intelligence to build and maintain its ransomware infrastructure and identify potential victims.
Investigation involves suspected juvenile operators
Investigations into attacks linked to KillSec began in several countries in early 2025. Authorities identified several people suspected of holding different roles in the group, including an administrator, a developer, a negotiator and an affiliate.
The suspected administrator and lead operator is 16 years old, investigators said. The investigation into other possible participants remains underway.
Authorities are examining the seized materials and tracing suspected criminal proceeds, including cryptocurrency transactions. Law enforcement agencies from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States participated in the investigation, alongside Europol and Eurojust.
In June 2026, Europol and law enforcement authorities from several countries also shut down the AudiA6 crypto service, which investigators said was used to launder about $389 million linked to ransomware groups.
Source: Incrypted
