An international law enforcement operation has taken down the infrastructure of the KillSec ransomware gang and led to three arrests, with a 16-year-old identified as the group's suspected main administrator and operator. Authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom carried out the coordinated action on September 30 as part of an investigation named Operation KillSwitch. Europol and Eurojust participated alongside cybersecurity firms Bitdefender and Group-IB, according to Europol.
German authorities led the investigation, which examined roughly 1,000 suspected attacks worldwide. Europol said three suspects were provisionally arrested and eight properties were searched in Greece, Romania, Spain, and the United Kingdom, with law enforcement also targeting the group's criminal proceeds. A second suspected member described as a developer turned 18 in August 2026 and was still a minor when some of the alleged crimes took place, Europol said.
Hamburg Police investigated the group's server infrastructure, identifying and shutting down five servers, including KillSec's main server and several used to store stolen data. Among the seized sites was the gang's dark web data leak site, which now displays a seizure message stating that the domain, servers, and all associated data tied to Operation KillSwitch have been taken under the control of the State Criminal Police Office of Hamburg and international law enforcement agencies. The banner directs visitors to an Operation KillSwitch website that includes a law enforcement video about the gang and the arrests.
Investigators seized at least 110 terabytes of stolen data to prevent continued unauthorized access. They have determined that around 500 of KillSec's attacks succeeded, a figure authorities cautioned could change as analysis of seized evidence continues. At least 70 of the suspected attacks are linked to organizations in Germany, including 18 cases connected to Hamburg.
KillSec has been active since around 2024 and is accused of exploiting software vulnerabilities and poorly secured edge devices and platforms to breach corporate systems and steal sensitive data. The group used the data to extort victims through its dark web leak site, threatening publication if a ransom was not paid. Europol said KillSec received substantial ransom payments from the data-theft attacks, and investigators found members used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.
Authorities are now examining seized computers, servers, and other data while attempting to trace the group's alleged criminal proceeds, including cryptocurrency. Investigators say the evidence could reveal further victims, attacks, and people involved in the operation.
More cybersecurity news from TechManNews.







