Opens in a new tab

KillSec Ransomware Site Seized, Three Arrested

Police dismantle KillSec ransomware and seize 110 TB of stolen data

The KillSec ransomware operation has been disrupted in an international law enforcement action. Authorities seized its leak site and servers, secured at least 110 terabytes of stolen data and provisionally arrested three suspects.

The action took place on 30 September 2026 and was announced by Europol and Eurojust on 1 October 2026. Investigators also identified a 16-year-old as the suspected administrator and main operator behind the group.

How the KillSec ransomware takedown unfolded

Law enforcement took control of KillSec’s public leak site during a coordinated operation on 30 September. The site had formed a central part of the group’s extortion model, allowing it to name alleged victims, publish stolen information and pressure organisations into paying ransoms.

Authorities seized five servers used by the operation, along with multiple associated domains. At least 110 terabytes of data stolen from victims was secured, potentially giving investigators extensive evidence about KillSec’s members, affiliates, infrastructure and past attacks.

Eight locations were searched across Spain, Greece, the United Kingdom and Romania. Three suspects were provisionally arrested, including the alleged main operator and two other individuals.

Reuters reported that the 16-year-old arrested in Alicante was a Romanian national. Two further suspects, both reportedly in their twenties, were arrested in the UK and Romania.

A suspected teenage administrator

Investigators identified the teenager as KillSec’s suspected administrator and main operator. This is an allegation, and the law enforcement announcements do not establish guilt, but the identification provides an important indication of the structure investigators believe was behind the service.

KillSec was not described as the work of one person. Roles within the wider operation allegedly included an administrator, developer, negotiator and affiliates, reflecting a service-based criminal model in which different participants could support intrusions and extortion.

Some media reports have referred to the disruption as Operation KillSwitch. However, that codename was not included in the Europol or Eurojust material published on 1 October, so it should currently be treated as an informal media description rather than an officially confirmed operation name.

KillSec ransomware activity and victim impact

Officials linked KillSec ransomware activity to almost 1,000 attacks worldwide since around 2024. Media reports summarising the investigation said approximately 500 suspected attacks had so far been identified as successful, although that figure may change as seized evidence is examined.

The operation primarily relied on data theft and public exposure to force payment. After gaining access to an organisation, its operators allegedly copied information to infrastructure under their control and threatened to release it through the KillSec leak site.

Victims could receive samples of stolen files as proof that an intrusion had occurred. If a ransom was not paid, KillSec could publish the information or make it available for free download, increasing the potential for regulatory, commercial and reputational consequences.

How KillSec gained access

No specific software products or affected versions were named in the official announcements. This means the event is not connected to one disclosed vulnerability for which every organisation can apply the same patch.

Instead, investigators said KillSec exploited vulnerabilities and poorly secured access points, particularly those associated with cloud storage. These weaknesses allegedly allowed participants to enter systems, locate valuable information and exfiltrate it to KillSec-controlled servers.

The reported attack process can be summarised as follows:

  • Exploit a vulnerability or poorly protected access point.
  • Access business systems or cloud storage containing sensitive data.
  • Copy selected information to attacker-controlled infrastructure.
  • Send samples to the victim as evidence of the theft.
  • Demand payment under threat of publication through the leak site.

This double extortion approach can create pressure even where an organisation has reliable backups. Restoring systems does not prevent criminals from publishing information that has already been copied.

Timeline of the KillSec ransomware disruption

Activity since around 2024

Eurojust said KillSec had operated since around 2024. During that period, the group allegedly developed a global victim base and built infrastructure for storing stolen data, negotiating payments and publishing information.

Action on 30 September 2026

On the operation’s action day, law enforcement took control of the public leak site and seized five servers and multiple domains. Searches were conducted at eight locations in four countries, while at least 110 terabytes of victim data was secured.

Announcements on 1 October 2026

Europol and Eurojust publicly confirmed the disruption, arrests, searches and infrastructure seizures on 1 October. Further reporting supplied additional details about the arrest in Alicante and the two arrests in the UK and Romania.

The available evidence confirms that the KillSec ransomware infrastructure was being actively used in real attacks before the seizure. This is not a proof-of-concept security issue or a theoretical software flaw, but a disruption of an established criminal extortion operation.

What remains unclear after the takedown

No domains, IP addresses, file hashes or other indicators of compromise were publicly released with the initial announcements. Organisations therefore cannot rely on a newly published official indicator list to determine whether KillSec previously accessed their environments.

It is also too early to know whether the disruption has permanently ended the group’s activity. Taking control of the leak site and storage servers removes important infrastructure and reduces immediate publication pressure, but affiliates or remaining members may retain stolen files, establish replacement systems or adopt a new identity.

The seized 110 terabytes could help investigators identify further victims and participants. It may also lead to law enforcement contact with affected organisations as the material is reviewed and attributed.

What organisations should do now

Organisations previously named or contacted by KillSec should preserve ransom messages, access logs, forensic images and related communications. They should also be ready to verify any contact claiming to come from law enforcement before sharing sensitive information.

Because the reported access routes included vulnerable systems and weakly secured cloud storage, immediate checks should focus on those areas:

  • Review cloud audit logs for unexpected access, downloads and permission changes.
  • Confirm that internet-facing services are patched and no longer expose unnecessary access points.
  • Check privileged and cloud accounts for weak authentication, unknown sessions or unauthorised credentials.
  • Assess whether sensitive data was copied, rather than looking only for encryption or system disruption.
  • Continue monitoring for attempts to revive or rebrand the KillSec ransomware operation.

The takedown is a significant operational setback for KillSec, particularly because servers, domains and a large volume of stolen data were seized together. However, affected organisations should treat it as an active investigation rather than confirmation that all copies of their data or every participant have been contained.

Originally reported by securityweek.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call