Skip to main content
The Wire
CyberNews by Zentrya One
Threat Intel

Police Disrupt KillSec Ransomware Group and Arrest Suspected 16-Year-Old Operator

International law enforcement disrupts KillSec ransomware in Operation KillSwitch, arresting three suspects including a 16-year-old alleged operator and securing more than 110 TB of data.

An international law-enforcement operation has disrupted the KillSec ransomware group, resulting in three arrests, the seizure of its leak site and infrastructure, and authorities securing more than 110 terabytes of data.

As part of Operation KillSwitch, Spanish police arrested a 16-year-old Romanian national in Alicante who investigators suspect was KillSec's main administrator and operator. Two additional suspects in their 20s were arrested in the United Kingdom and Romania.

Operation KillSwitch at a Glance

Detail Information
Operation KillSwitch
Target KillSec
Arrests 3
Suspected Main Operator 16-year-old
Searches 8
Countries Searched Spain, Greece, UK and Romania
Servers Shut Down 5
Data Secured 110+ TB
Suspected Attacks Around 1,000 worldwide

The investigation was led by German authorities and supported by multiple international law-enforcement agencies, with Europol and Eurojust coordinating cross-border activities.

How KillSec Operated

Investigators say KillSec compromised organizations by exploiting software vulnerabilities and poorly secured access points, particularly exposed cloud storage.

After obtaining access, attackers stole sensitive information and transferred it to infrastructure under their control.

The extortion process generally followed this pattern:

Initial Access → Data Theft → Victim Listed on Leak Site → Ransom Demand → Data Published if Payment Refused

Authorities say KillSec also obtained credentials from underground marketplaces and sometimes provided victims with samples of stolen information as proof of compromise.

KillSec evolved into a ransomware-as-a-service (RaaS) operation, allowing affiliates to use its infrastructure and ransomware tools to conduct attacks.

Around 1,000 Suspected Attacks Investigated

Operation KillSwitch covers approximately 1,000 suspected attacks worldwide, with investigators having identified around 500 as successful so far. These numbers may change as authorities continue examining the seized evidence.

Investigators identified several suspected roles within the operation, including:

  • Administrator
  • Malware developer
  • Negotiator
  • Affiliates

Authorities also identified a suspected developer who turned 18 in August 2026 and was reportedly a minor when some alleged offenses occurred. He had been identified but had not been arrested at the time of reporting.

Five Servers and Leak Site Taken Down

Law enforcement shut down five servers, including KillSec's primary server and systems used to store information stolen from victims.

Authorities also took control of KillSec's dark-web leak site and placed seizure notices on five domains. More than 110 TB of data was secured against further unauthorized access.

During searches in Spain, authorities seized computers, mobile phones and cryptocurrency wallets. Spanish investigators said an initial examination identified transactions consistent with ransom payments from some victims.

KillSec Also Used AI

Investigators found evidence that KillSec used artificial intelligence to support its criminal infrastructure and identify potential targets.

However, authorities have not publicly provided detailed information about which AI systems were used or exactly how AI was incorporated into the group's operations.

Investigation Continues

The KillSec disruption does not necessarily mean every individual associated with the operation has been arrested.

Authorities continue to analyze seized servers, devices, cryptocurrency transactions and stolen information to identify additional attacks, victims and potential members of the group.

The operation nevertheless represents a significant disruption of KillSec's infrastructure:

3 Arrests → 8 Searches → 5 Servers Shut Down → Leak Site Seized → 110+ TB Secured

Security Takeaway

Operation KillSwitch demonstrates how international cooperation can disrupt ransomware-as-a-service operations by targeting not only individual operators but also the infrastructure supporting their extortion business.

For organizations previously targeted by KillSec, the seizure could also provide investigators with valuable evidence about attack methods, stolen information, cryptocurrency transactions and additional members of the operation.

Importantly, the individuals involved remain suspects, and allegations against them have not yet been established through final court judgments.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

Threat Intel

Threat Intelligence Alone Cannot Close the Growing Exploitation Gap

Threat intelligence alone cannot stop rapidly evolving cyberattacks. Learn how security validation, risk-based vulnerability management and faster remediation can help organizations close the growing exploitation gap.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.