Police seize KillSec servers and data in Operation KillSwitch takedown
Seizures, arrests and new evidence are expected to expose more victims and accomplices linked to the KillSec ransomware group.
European and US authorities have disrupted the KillSec ransomware group in an operation called “Operation KillSwitch,” seizing its dark‑web leak site, core servers, and at least 110 TB of stolen data. The coordinated takedown on September 30 involved law‑enforcement agencies from ten countries, with Europol, Eurojust, Bitdefender, and Group‑IB providing support. Investigators say KillSec has been active since about 2024, exploiting software vulnerabilities and exposed edge systems to steal corporate data, then extorting victims via its Tor-based leak portal; roughly 500 attacks are believed to have succeeded so far, including at least 70 against German organizations. Police provisionally arrested three people and searched eight locations across Greece, Romania, Spain, and the UK, identifying suspects believed to have served as the group’s administrator, developer, negotiator, and an affiliate. Authorities report that the alleged main operator is just 16 years old, that the group received significant ransom payments, and that its members relied on AI tools to build and run their infrastructure and select targets, with further victims and accomplices expected to emerge from the seized evidence.
Why it matters
Disabling KillSec’s core infrastructure and capturing a large trove of stolen data sharply curbs one active ransomware operation and gives investigators material to trace further suspects and victims. The case also highlights how young operators and the use of artificial intelligence are shaping modern cybercrime, putting extra pressure on law enforcement and security teams to adapt to faster, more automated attacks.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer