Police Disrupt KillSec Ransomware Group and Arrest Suspected 16-Year-Old Operator
International law enforcement disrupts KillSec ransomware in Operation KillSwitch, arresting three suspects including a 16-year-old alleged operator and securing more than 110 TB of data.

An international law-enforcement operation has disrupted the KillSec ransomware group, resulting in three arrests, the seizure of its leak site and infrastructure, and authorities securing more than 110 terabytes of data.
As part of Operation KillSwitch, Spanish police arrested a 16-year-old Romanian national in Alicante who investigators suspect was KillSec's main administrator and operator. Two additional suspects in their 20s were arrested in the United Kingdom and Romania.
Operation KillSwitch at a Glance
| Detail | Information |
|---|---|
| Operation | KillSwitch |
| Target | KillSec |
| Arrests | 3 |
| Suspected Main Operator | 16-year-old |
| Searches | 8 |
| Countries Searched | Spain, Greece, UK and Romania |
| Servers Shut Down | 5 |
| Data Secured | 110+ TB |
| Suspected Attacks | Around 1,000 worldwide |
The investigation was led by German authorities and supported by multiple international law-enforcement agencies, with Europol and Eurojust coordinating cross-border activities.
How KillSec Operated
Investigators say KillSec compromised organizations by exploiting software vulnerabilities and poorly secured access points, particularly exposed cloud storage.
After obtaining access, attackers stole sensitive information and transferred it to infrastructure under their control.
The extortion process generally followed this pattern:
Initial Access → Data Theft → Victim Listed on Leak Site → Ransom Demand → Data Published if Payment Refused
Authorities say KillSec also obtained credentials from underground marketplaces and sometimes provided victims with samples of stolen information as proof of compromise.
KillSec evolved into a ransomware-as-a-service (RaaS) operation, allowing affiliates to use its infrastructure and ransomware tools to conduct attacks.
Around 1,000 Suspected Attacks Investigated
Operation KillSwitch covers approximately 1,000 suspected attacks worldwide, with investigators having identified around 500 as successful so far. These numbers may change as authorities continue examining the seized evidence.
Investigators identified several suspected roles within the operation, including:
- Administrator
- Malware developer
- Negotiator
- Affiliates
Authorities also identified a suspected developer who turned 18 in August 2026 and was reportedly a minor when some alleged offenses occurred. He had been identified but had not been arrested at the time of reporting.
Five Servers and Leak Site Taken Down
Law enforcement shut down five servers, including KillSec's primary server and systems used to store information stolen from victims.
Authorities also took control of KillSec's dark-web leak site and placed seizure notices on five domains. More than 110 TB of data was secured against further unauthorized access.
During searches in Spain, authorities seized computers, mobile phones and cryptocurrency wallets. Spanish investigators said an initial examination identified transactions consistent with ransom payments from some victims.
KillSec Also Used AI
Investigators found evidence that KillSec used artificial intelligence to support its criminal infrastructure and identify potential targets.
However, authorities have not publicly provided detailed information about which AI systems were used or exactly how AI was incorporated into the group's operations.
Investigation Continues
The KillSec disruption does not necessarily mean every individual associated with the operation has been arrested.
Authorities continue to analyze seized servers, devices, cryptocurrency transactions and stolen information to identify additional attacks, victims and potential members of the group.
The operation nevertheless represents a significant disruption of KillSec's infrastructure:
3 Arrests → 8 Searches → 5 Servers Shut Down → Leak Site Seized → 110+ TB Secured
Security Takeaway
Operation KillSwitch demonstrates how international cooperation can disrupt ransomware-as-a-service operations by targeting not only individual operators but also the infrastructure supporting their extortion business.
For organizations previously targeted by KillSec, the seizure could also provide investigators with valuable evidence about attack methods, stolen information, cryptocurrency transactions and additional members of the operation.
Importantly, the individuals involved remain suspects, and allegations against them have not yet been established through final court judgments.
Related reporting
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The FBI seized domains linked to NightmareStresser, a major DDoS-for-hire service blamed for hundreds of thousands of actual or attempted attacks worldwide since 2022.
Threat Intelligence Alone Cannot Close the Growing Exploitation Gap
Threat intelligence alone cannot stop rapidly evolving cyberattacks. Learn how security validation, risk-based vulnerability management and faster remediation can help organizations close the growing exploitation gap.
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have uncovered a sophisticated banking-malware campaign that hijacks Google Chrome and Microsoft Edge using malicious browser extensions capable of stealing credentials, cookies, session tokens and other sensitive browser data.


