Cyber Threat Intel 4 min read

Police Shut Down the KillSec Ransomware Group. Its Suspected Leader Is 16.

Operation KillSwitch seized the gang's leak site and servers and made three arrests. Investigators link it to about 1,000 attacks, roughly half of them successful, and say it used AI to pick victims.

Priya Nair
Data, AI Governance & Policy Analyst
Published 2 Oct 2026, 4:44 PM (SGT)
Share:
A German police car marked Polizei parked on a street A German police car marked Polizei parked on a street Photo by TechLine on Pixabay
Advertisement

2 OCT 2026 — KillSec, a group that has stolen company data and threatened to publish it since around 2024, was taken apart by police in ten countries on 30 September. Investigators say its suspected main operator is 16 years old, and a suspected developer was still a minor when some of the attacks took place.

The international operation, named Operation KillSwitch, seized the group's leak site and servers, made three provisional arrests and searched eight properties, according to Europol.

What the group is accused of

Investigators link KillSec to around 1,000 suspected attacks worldwide, of which about 500 have so far been identified as successful. Both figures may change as seized evidence is examined.

The group broke into organisations through software vulnerabilities and poorly secured access points, particularly to cloud storage, and copied sensitive data to servers it controlled. Victims were named on its dark-web leak site and told their data would be published unless they paid. If they did not pay, the stolen files could be made available for free download. In some cases the group obtained "substantial" ransom payments, Europol says.

Investigators also found that the group used AI to build and maintain its ransomware infrastructure and to identify potential victims. Europol does not say which tools.

~1,000Suspected attacks worldwide linked to KillSec
~500Attacks identified so far as successful
110 TBStolen data secured when police took the leak site
16Age of the group's suspected administrator and main operator

Who investigators say ran it

The investigation identified four suspected roles: an administrator, a developer, a negotiator and an affiliate. The alleged administrator is 16, and the suspected developer turned 18 in August 2026. Enquiries into other possible members are continuing.

Searches took place in Greece, Romania, Spain and the United Kingdom. Neither Europol nor the Hamburg police name the suspects or say which of them were arrested.

What police took

On 30 September, police took control of KillSec's leak site and secured at least 110 terabytes of data against further unauthorised access. The Hamburg police say five central servers were brought under police control over the course of the investigation, including the main server and several used to store data taken from victims. KillSec's domains now show a seizure notice with a link to an Operation KillSwitch website, BleepingComputer reports.

Advertisement

Investigators are examining seized devices and tracing the group's proceeds, including cryptocurrency, and say the evidence may identify more victims and more people involved.

A German-led case with ten countries

Hamburg's State Criminal Police Office and public prosecutor led the operation. At least 70 of the attacks are linked to Germany and 18 to Hamburg, according to the Hamburg police. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part, alongside Europol and Eurojust. The US side was the FBI's San Juan field office and the US Attorney's Office for Puerto Rico.

Europol says the security companies Bitdefender and Group-IB supported the investigation, and that its European Cybercrime Centre helped trace cryptocurrency and examine digital evidence.

What is still unknown

Neither statement lists victims or says where they are outside Germany, how much the group was paid, or which AI tools it used. The suspects have been provisionally arrested, not charged. Securing the leak site stops further downloads from it, but files taken before the seizure may still be circulating.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement