INTERNATIONAL OPERATION DISMANTLES KILLSEC RANSOMWARE GROUP LINKED TO NEARLY 1,000 ATTACKS

AUTHORITIES ARREST THREE SUSPECTS AND SEIZE CORE INFRASTRUCTURE

An international law-enforcement operation has dismantled infrastructure belonging to the KillSec ransomware group, which authorities link to almost 1,000 attacks worldwide.

Eurojust announced the results of Operation KillSwitch on October 1, 2026. Authorities arrested three suspects, searched eight properties and seized five servers, multiple domains and at least 110 terabytes of data stolen from victims.

Investigators identified a 16-year-old as KillSec’s alleged administrator and principal operator. Another suspect, believed to have worked as a developer, recently turned 18 and was reportedly a minor when some of the alleged offenses occurred. eurojust.europa.eu

KILLSEC USED DATA THEFT AND EXTORTION

KillSec has operated since 2024, according to Eurojust. The group generally compromised organizations through poorly protected access points, particularly those connected to cloud-storage environments.

After gaining access, the attackers copied sensitive files to infrastructure under their control. Victims were then threatened with public disclosure unless they paid a ransom.

The group sometimes provided victims with samples to demonstrate that it possessed their data. When organizations refused to pay, KillSec allegedly published the stolen material for free.

Authorities said some victims made substantial ransom payments, but they have not disclosed KillSec’s total proceeds or identified the affected organizations.

OPERATION INVOLVED NINE COUNTRIES

Law-enforcement and judicial authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom and the United States participated in the investigation.

Eurojust established a joint investigation team and coordinated the international action day. Europol produced intelligence reports, connected investigators with private-sector organizations and helped trace cryptocurrency and examine digital evidence.

Searches were conducted in Greece, Romania, Spain and the United Kingdom. KillSec’s domains now redirect visitors to a law-enforcement seizure notice.

Investigators are continuing to analyze confiscated devices, stolen files and financial records. The seized evidence could identify additional victims, attacks and participants.

Leave a Comment

Your email address will not be published. Required fields are marked *