# Europol dismantles KillSec ransomware operation

Published: 2026-10-01 · Severity: elevated
Canonical: https://vorant.io/reports/4728c542-bacb-51bd-89a4-7eaeb6cde822/europol-dismantles-killsec-ransomware-operation

> International law enforcement seized KillSec ransomware's servers and leak site and arrested three suspects, including a 16-year-old alleged leader.

Operation KillSwitch, led by German authorities (Hamburg State Criminal Police Office and Public Prosecutor's Office) with support from Europol, Eurojust, and law enforcement across ten countries, dismantled infrastructure belonging to the KillSec ransomware group. Active since 2024, KillSec gained access to victim organisations primarily by exploiting software vulnerabilities and poorly secured access points, particularly cloud storage, exfiltrating sensitive data and extorting victims via a dark web leak site. Of roughly 1,000 suspected attacks worldwide, around 500 are confirmed successful compromises. Notably, investigators found the group used AI tools to help build and maintain its ransomware infrastructure and to identify potential victims.

The action day on 30 September 2026 resulted in law enforcement taking control of at least 110TB of stolen data, five central servers, and KillSec-operated domains (now redirecting to a seizure notice). Eight searches were conducted across Spain, Greece, Romania, and the UK, with three provisional arrests. The suspects reportedly held distinct roles — administrator/main operator, developer, negotiator, and affiliate — with the alleged lead administrator being 16 years old and a developer having been a minor at the time of some offences. Authorities continue to investigate additional members, trace cryptocurrency proceeds, and analyse seized evidence, which may surface further victims.

For defenders, this takedown reduces near-term risk from an actively extorting group but does not eliminate residual risk: victims previously listed or exfiltrated by KillSec should verify whether their data was among the 110TB seized, and organisations should continue to harden cloud storage access controls and patch management given the group's reliance on vulnerability exploitation and misconfigured access points as its primary initial access vector.

## Mentioned in this report

- Threat actors: killsec
- Malware: KillSec
- Campaigns: Operation KillSwitch

Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4728c542-bacb-51bd-89a4-7eaeb6cde822/europol-dismantles-killsec-ransomware-operation.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
