Teenager Suspected of Leading KillSec Ransomware Group as Law Enforcement Seizes Servers and Leak Site
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom.
The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.
KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.
The operation was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States took part in the investigation, alongside Europol and Eurojust. The investigation was also supported by the private cybersecurity companies Bitdefender and Group-IB.
Stolen data used to pressure victims
KillSec has been active since around 2024. The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organisations’ systems. Its members then copied sensitive internal data to infrastructure under their control.
Victims were named on the group’s dark web leak site and threatened with publication of their data unless paid. Where a victim did not pay, the stolen files could be made available for free download. In some cases, the group obtained substantial ransom payments.
Investigators also uncovered how the group used AI to build and maintain its ransomware infrastructure and identify potential victims.
Teenagers at the centre of the investigation
Authorities in several countries began investigating attacks attributed to KillSec in early 2025. The international investigation identified suspects believed to have taken on different roles within the group, including an administrator, a developer, a negotiator, and an affiliate.
The alleged administrator and main operator is 16 years old. A suspected developer turned 18 in August 2026 and was a minor when some of the offences were committed. Investigators also identified one person believed to be in a negotiator role and another in an affiliate role. Enquiries into other possible members are continuing.
Servers and criminal assets targeted
The coordinated action targeted both the people behind KillSec and the systems they relied on. Authorities carried out eight house searches in Spain, Greece, Romania, and the United Kingdom, made three provisional arrests, and seized evidence and assets.
Over the course of the investigation, five central servers were brought under police control, including infrastructure used to manage the group’s activities and store data taken from victims. Authorities also took control of domains operated by KillSec and redirected visitors to a law enforcement seizure notice.
Investigators are examining the seized devices and data and tracing the group’s criminal proceeds, including cryptocurrency. The evidence may help identify further victims, attacks, and people involved.
European coordination
As investigations into KillSec developed in several countries, Europol helped bring the intelligence together. Its European Cybercrime Centre produced reports on the group’s activities, connected investigators with private-sector partners, and provided specialist support to trace cryptocurrency and examine digital evidence.
The Joint Cybercrime Action Taskforce (J-CAT) hosted at Europol also supported coordination, liaison, and deconfliction efforts with national authorities.
Through coordination by Eurojust, judicial authorities worked together to identify suspects, find the group’s infrastructure and follow financial trails. The Agency supported the planning of the action day and ran a coordination centre to ensure the measures were executed simultaneously worldwide.





