---
title: "Europol Targets KillSec in Massive Ransomware Operation"
date: 2026-10-01
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/10/europol-cybercrime-takedown.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Europol Targets KillSec in Massive Ransomware Operation

Police took control of KillSec’s leak site on 30th September 2026 and secured at least 110 terabytes of data. Investigators identified a 16-year-old as the ransomware group’s suspected main operator in a Hamburg-led probe of around 1,000 suspected attacks.

## The Brief

- Europol said law enforcement secured the leak site’s data against further unauthorized access after KillSec used it to extort organizations.
- Investigators identified a 16-year-old as the alleged administrator, plus a suspected developer who turned 18 in August 2026.
- Operation KillSwitch has so far identified about 500 of the suspected attacks as successful, and that tally may still change.
- Authorities made three provisional arrests and searched eight properties across Greece, Romania, Spain and the United Kingdom.
- Bitdefender and Group-IB supported the probe, which found KillSec used AI to build its infrastructure and pick targets.

## A 16-year-old allegedly sat at the top

Investigators mapped **KillSec** as a small crew with defined jobs. The [Europol announcement](https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site) lists four roles among the suspects: an administrator, a developer, a negotiator and an affiliate. The administrator, whom Europol describes as the main operator, is 16.

The suspected developer was still a minor when some of the alleged offenses took place. Investigators tied one more person to the negotiator role and another to the affiliate role. Inquiries into other possible members are continuing.

That structure looks like a business with a front desk. A dedicated negotiator implies ransom talks ran as their own function. An affiliate role usually means someone carrying out intrusions under a group’s brand. Europol’s account fits that reading but doesn’t spell out how the roles split the money.

> Today we’re announcing Operation KillSwitch, a joint sequenced operation led by [@FBISanJuan](https://x.com/FBISanJuan?ref_src=twsrc%5Etfw) targeting the Kill Security Ransomware Group (“KillSec”). Authorities in the U.S. and Europe took control of KillSec’s leak site, securing at least 110 terabytes of data against further… [pic.twitter.com/ZYvxosEPyv](https://t.co/ZYvxosEPyv)
> 
> — FBI Cyber Division (@FBICyberDiv) [October 1, 2026](https://x.com/FBICyberDiv/status/2105708131351146668?ref_src=twsrc%5Etfw)

 ## Poorly secured cloud storage was the way in

KillSec has been active since around 2024, according to Europol. Its members exploited software vulnerabilities and poorly secured access points, particularly to [cloud storage](https://sqmagazine.co.uk/cloud-storage-usage-statistics/). Once inside, they copied sensitive internal data to infrastructure they controlled.

The extortion followed a familiar script. KillSec named victims on its [dark web leak site](https://sqmagazine.co.uk/dark-web-statistics/) and threatened to publish their files unless they paid. When a victim refused, the stolen files could be made available for free download. In some cases, Europol said, the group obtained substantial ransom payments.

Investigators also found the group used AI to build and maintain its ransomware infrastructure and to identify potential victims. The release doesn’t name the tools. KillSec’s entry route echoes recent [attacks on exposed cloud storage](https://sqmagazine.co.uk/azure-blob-storage-attacks-cloud-security-gaps/) seen across the past year.

## Police took the servers and the leak site

The action went after people and machines at the same time. During the investigation, police brought **five central servers** under their control. Those included systems used to manage the group and store data taken from victims. Authorities also took over KillSec’s domains and pointed visitors to a law enforcement seizure notice.

The searches and arrests came with seizures of evidence and assets. Investigators are now examining the devices and data and tracing the group’s criminal proceeds, including cryptocurrency.

The leak site matters most to victims. While it stayed live, any file KillSec chose to release could be downloaded freely. Police control of the site cuts off further access to the data stored there, though it can’t recall copies already taken.

## Hamburg led a case spanning two continents

The **Hamburg State Criminal Police Office** and the **Hamburg Public Prosecutor’s Office** led Operation KillSwitch. Authorities from Belgium, Finland, Germany, Greece and the Netherlands took part. So did teams from Romania, Spain, Switzerland, the United Kingdom and the United States.

Some of the participants are a long way from Hamburg. The US side ran through the US Attorney’s Office for the District of Puerto Rico and the FBI San Juan Field Office. Britain sent the **Eastern Region Special Operations Unit (ERSOU)**. Spain fielded Investigative Court number 20 of Barcelona, the Mossos d’Esquadra and the Guardia Civil.

**Europol’s European Cybercrime Centre** pulled the national threads together. It wrote reports on KillSec, linked investigators with private-sector partners and helped trace crypto and examine digital evidence. Eurojust, the EU agency for judicial cooperation, ran a coordination center so measures landed at the same moment worldwide. Europol has backed similar joint work this year, including [the Audia6 crypto laundering takedown](https://sqmagazine.co.uk/europol-takes-down-audia6-crypto-laundering-service/).

The release leaves several gaps:

- **Which of the three provisionally arrested suspects hold which roles, and whether the 16-year-old is among them?**
- **How much KillSec collected in total ransom payments?**
- **Which organizations were among the successful attacks?**
- **Which AI tools the group used, and for which tasks beyond infrastructure and targeting?**

Organizations that keep data in cloud storage can audit public access settings and rotate exposed access keys now. That helps reduce risk from copycat crews using the same entry route. Any organization KillSec contacted, paid or not, can report it to national police.

## Why It Matters?

The case shows how little a ransomware crew needs to do real damage: a teenager at the controls, weak cloud settings and AI-assisted tooling. The next marker is the evidence review. On the success count, Europol cautioned that “**this figure may change as investigators examine the evidence seized during the operation.**” The same material may also point to further victims, attacks and suspects.