2 OCT 2026 — KillSec, a group that has stolen company data and threatened to publish it since around 2024, was taken apart by police in ten countries on 30 September. Investigators say its suspected main operator is 16 years old, and a suspected developer was still a minor when some of the attacks took place.
The international operation, named Operation KillSwitch, seized the group's leak site and servers, made three provisional arrests and searched eight properties, according to Europol.
What the group is accused of
Investigators link KillSec to around 1,000 suspected attacks worldwide, of which about 500 have so far been identified as successful. Both figures may change as seized evidence is examined.
The group broke into organisations through software vulnerabilities and poorly secured access points, particularly to cloud storage, and copied sensitive data to servers it controlled. Victims were named on its dark-web leak site and told their data would be published unless they paid. If they did not pay, the stolen files could be made available for free download. In some cases the group obtained "substantial" ransom payments, Europol says.
Investigators also found that the group used AI to build and maintain its ransomware infrastructure and to identify potential victims. Europol does not say which tools.
Who investigators say ran it
The investigation identified four suspected roles: an administrator, a developer, a negotiator and an affiliate. The alleged administrator is 16, and the suspected developer turned 18 in August 2026. Enquiries into other possible members are continuing.
Searches took place in Greece, Romania, Spain and the United Kingdom. Neither Europol nor the Hamburg police name the suspects or say which of them were arrested.
What police took
On 30 September, police took control of KillSec's leak site and secured at least 110 terabytes of data against further unauthorised access. The Hamburg police say five central servers were brought under police control over the course of the investigation, including the main server and several used to store data taken from victims. KillSec's domains now show a seizure notice with a link to an Operation KillSwitch website, BleepingComputer reports.
Investigators are examining seized devices and tracing the group's proceeds, including cryptocurrency, and say the evidence may identify more victims and more people involved.
A German-led case with ten countries
Hamburg's State Criminal Police Office and public prosecutor led the operation. At least 70 of the attacks are linked to Germany and 18 to Hamburg, according to the Hamburg police. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part, alongside Europol and Eurojust. The US side was the FBI's San Juan field office and the US Attorney's Office for Puerto Rico.
Europol says the security companies Bitdefender and Group-IB supported the investigation, and that its European Cybercrime Centre helped trace cryptocurrency and examine digital evidence.
What is still unknown
Neither statement lists victims or says where they are outside Germany, how much the group was paid, or which AI tools it used. The suspects have been provisionally arrested, not charged. Securing the leak site stops further downloads from it, but files taken before the seizure may still be circulating.