Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » Police Dismantle KillSec Ransomware Group Linked to 1,000 Global Attacks

Police Dismantle KillSec Ransomware Group Linked to 1,000 Global Attacks

By:
Last updated:October 4, 2026
Human Written
  • Police seized KillSec’s leak site and five servers during Operation KillSwitch on September 30, 2026.

  • Investigators say a 16-year-old led the group, and they arrested three suspects.

  • Authorities secured over 110 terabytes of stolen data linked to about 1,000 attacks worldwide.

Police Dismantle KillSec Ransomware Group After Arresting Three Suspects

International police teams have broken up the KillSec ransomware group. Ransomware is a type of malicious software, or app, that locks or steals files. Investigators say a 16-year-old ran this gang. The raid, called Operation KillSwitch, happened on September 30, 2026. Officers targeted the systems the group used to steal data and push victims to pay.

According to Europol, investigators tied KillSec to about 1,000 suspected attacks around the world. Police arrested three suspects and searched eight properties. The searches covered Greece, Romania, Spain, and the United Kingdom. Each search aimed to gather evidence and digital devices tied to the group.

Ten countries joined the operation. They included Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK, and the US. Europol and Eurojust backed the probe from the start. Cybersecurity firms Bitdefender and Group-IB also helped out with technical support.

Hamburg’s State Criminal Police Office and its Public Prosecutor’s Office led the German side of the case. They played a key role in coordinating the whole operation across so many countries.

Servers and Leak Site Taken Offline

During the raid, investigators seized KillSec’s dark web leak site. A leak site is a hidden web page where stolen files get posted or sold. Police have also targeted other dark web data operations, including the arrest of a teen hacker in Spain over the alleged sale of 64 million citizens’ data.

They locked down at least 110 terabytes of stolen data. That is an enormous amount of files, enough to fill thousands of computers. This move stops anyone else from reaching the data without permission.

Hamburg Police confirmed they also found and shut down five servers. These included the group’s main server and systems that stored stolen files. Shutting these machines down cuts off the tools the gang relied on daily.

KillSec reportedly used its leak site to pressure victims into paying. After breaking into a company’s computer systems, the group allegedly copied private files. They then threatened to publish those files unless the victim agreed to pay up.

Europol said investigators have already confirmed about 500 successful attacks. At least 70 of these hit organizations based in Germany. Eighteen of those cases link straight to the city of Hamburg. Officials warned these numbers could still shift as they study the seized evidence further.

The group is believed to have run since around 2024, according to Bleeping Computer. Investigators think its members broke into company systems by exploiting weak spots. Many of these flaws sat inside cloud storage setups that had poor security in place.

Suspects Include a Developer and a Negotiator

Police identified several suspects tied to different roles inside the group. One suspect allegedly worked as a developer, building the group’s tools. Another served as a negotiator, talking to victims about ransom payments. A third acted as an affiliate, someone who carried out attacks for a cut of the profit.

One suspected developer turned 18 in August 2026. He was reportedly still a minor when some of the alleged crimes took place, SecurityWeek reports. This detail adds a tricky layer to the case, since rules for minors differ from rules for adults.

The teenage suspect accused of leading KillSec adds another twist to the story. Investigators say he ran the whole operation despite his young age. This raises fresh questions about how young people get pulled into cybercrime in the first place.

Three suspects now sit under provisional arrest while the case moves forward. Police searched eight properties as part of gathering evidence against them. The full list of charges has not been made public yet.

Police Now Track AI Use and Crypto Money

Investigators also found something unusual while digging through the case. They say KillSec members used artificial intelligence tools to help run their crimes. The group allegedly used AI to help build its ransomware setup and to find new victims to target.

Officers are now studying the seized computers and servers very closely. They also plan to trace any cryptocurrency the group earned from its crimes. Cryptocurrency is digital money that can be harder to track than regular cash. This part of the probe could take a while, since crypto payments can be hidden.

The investigation may still uncover more victims tied to the group. It could also reveal more people connected to the wider operation. Authorities say the case is far from finished right now. Taking down KillSec’s systems stops the tools the group used to threaten victims. Still, officials admit they don’t yet know the full size of the group’s activity.

This case builds on work that began back in 2025. Police have not finished studying all the evidence they seized so far. The suspects’ exact roles will now go through the courts to be decided.

The group’s reach stretched across many countries and hit roughly a thousand targets. That scale shows how much damage a small team, even one led by a teen, can cause online. Investigators say the fight against groups like KillSec is far from over.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.