VORANT. Threat Intelligence Research Sign in Create a free account

Europol dismantles KillSec ransomware operation

elevated threat

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

International law enforcement seized KillSec ransomware's servers and leak site and arrested three suspects, including a 16-year-old alleged leader.

Operation KillSwitch, led by German authorities (Hamburg State Criminal Police Office and Public Prosecutor's Office) with support from Europol, Eurojust, and law enforcement across ten countries, dismantled infrastructure belonging to the KillSec ransomware group. Active since 2024, KillSec gained access to victim organisations primarily by exploiting software vulnerabilities and poorly secured access points, particularly cloud storage, exfiltrating sensitive data and extorting victims via a dark web leak site. Of roughly 1,000 suspected attacks worldwide, around 500 are confirmed successful compromises. Notably, investigators found the group used AI tools to help build and maintain its ransomware infrastructure and to identify potential victims.

The action day on 30 September 2026 resulted in law enforcement taking control of at least 110TB of stolen data, five central servers, and KillSec-operated domains (now redirecting to a seizure notice). Eight searches were conducted across Spain, Greece, Romania, and the UK, with three provisional arrests. The suspects reportedly held distinct roles — administrator/main operator, developer, negotiator, and affiliate — with the alleged lead administrator being 16 years old and a developer having been a minor at the time of some offences. Authorities continue to investigate additional members, trace cryptocurrency proceeds, and analyse seized evidence, which may surface further victims.

For defenders, this takedown reduces near-term risk from an actively extorting group but does not eliminate residual risk: victims previously listed or exfiltrated by KillSec should verify whether their data was among the 110TB seized, and organisations should continue to harden cloud storage access controls and patch management given the group's reliance on vulnerability exploitation and misconfigured access points as its primary initial access vector.

Mentioned in this report

Threat actors killsec
Malware KillSec
Campaigns Operation KillSwitch

Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,768 reports from 152 sources, 472 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs