Operation KillSwitch: Law Enforcement Seizes KillSec Ransomware Servers and Leak Site
An international law enforcement operation known as Operation KillSwitch has seized the KillSec ransomware group’s data leak site and servers, provisionally arrested three suspects, and identified a 16-year-old as the group’s alleged main administrator.
The coordinated action took place on September 30 and involved authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom.
Europol, Eurojust, cybersecurity company Bitdefender, and Group-IB also supported the investigation.
According to Europol, the international investigation was led by German authorities and concerns approximately 1,000 suspected attacks worldwide.
“Investigators have identified a 16-year-old believed to be the group’s main operator. Three suspects were provisionally arrested and eight properties were searched in Greece, Romania, Spain and the United Kingdom. Authorities also targeted the group’s proceeds of crime.”
KillSec ransomware infrastructure seized
The investigation began in 2025 and helped law enforcement identify suspected administrators, developers, negotiators, and associates connected to the cybercriminal group.
Europol said the alleged KillSec administrator and main operator is 16 years old. Another suspected developer, who turned 18 in August 2026, was a minor when some of the alleged crimes were committed.
Authorities also identified suspected negotiators and other associates.
Hamburg police said investigators identified and shut down five servers. The seized infrastructure included KillSec’s main server and multiple servers allegedly used to store stolen data.
Law enforcement also seized the KillSec dark web data leak site. The site now displays messages from authorities explaining the seizure.
“The domains, servers and all related data related to Operation Kill Switch were controlled by the Hamburg State Criminal Police Office and international law enforcement agencies,” the seizure banner says.

Source: BleepingComputer
The seizure banner links to the Operation KillSwitch website, which contains law enforcement videos about ransomware groups and arrests.
110 terabytes of stolen data seized
During the operation, authorities seized at least 110 terabytes of stolen data to prevent continued unauthorized access. Investigators conducted eight raids in Greece, Romania, Spain, and the United Kingdom, and provisionally arrested three suspects.
Investigators have so far determined that approximately 500 KillSec attacks were successful. They cautioned that this figure could change as authorities analyze the seized evidence.
At least 70 suspected attacks involved organizations in Germany, including 18 linked to Hamburg.
KillSec accused of exploiting vulnerabilities and edge devices
KillSec has been active since around 2024 and is accused of exploiting software vulnerabilities, poorly secured edge devices, and vulnerable platforms to infiltrate corporate networks and steal sensitive data.
The attackers allegedly used stolen corporate information to extort victims through the KillSec dark web leak site, threatening to publish the data if a ransom was not paid.
Europol said KillSec received “significant” ransom payments from these data theft attacks.
Investigators also found that members of the group used artificial intelligence to help build and maintain ransomware infrastructure and identify potential victims.
Investigation continues
Authorities are examining seized computers, servers, and other data while attempting to trace KillSec’s alleged criminal proceeds, including cryptocurrency.
Investigators said the evidence could identify additional victims, attacks, and people involved in the ransomware operation.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about how AI-driven attacks will change cybersecurity, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



