[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcTOJfeYOqCeRm6dGvK7hc6zqBg5c-ln0SgdWcGcnedM":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"9e0b2cde-e890-4621-a157-4ff2efa48a91","Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader","police-shut-down-killsec-ransomware-identify-alleged-teen-leader-35f806","Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek.","An international investigation, Operation KillSwitch, has led to the takedown of the KillSec ransomware group. Authorities believe a 16-year-old was the group's administrator and main operator. The operation involved multiple countries and resulted in provisional arrests, home searches, and the seizure of core servers and the group's dark web leak site, which contained 110TB of stolen victim data.","Police dismantle KillSec ransomware group, identify alleged teen leader.","Europol says a 16-year-old is believed to be the administrator and main operator of KillSec, a ransomware group linked to roughly 1,000 suspected attacks worldwide. The teen was identified in Operation KillSwitch, an international investigation led by police and prosecutors in Germany. Authorities made three provisional arrests and searched eight homes in Greece, Romania, Spain, and the UK. Investigators also identified a suspected developer who turned 18 in August, as well as one suspected negotiator and one suspected affiliate. The hunt for other possible members continues. On Wednesday, police took over KillSec’s dark web leak site and blocked further unauthorized access to at least 110TB of data, presumably stolen from victims. Europol said the group used the site to threaten organizations with publishing stolen files unless they paid a ransom. Victims who refused could see their files offered as free downloads. Over the course of the investigation, police also gained control of five core servers, including systems the gang used to manage its operations and hold data stolen from victims. KillSec’s domains now redirect visitors to a law enforcement seizure notice. KillSec, active since around 2024, broke into organizations through software flaws and weakly protected entry points, especially into cloud storage. It then copied sensitive internal data to its own infrastructure, and in some cases victims paid substantial ransoms.Advertisement. Scroll to continue reading. Authorities are currently aware of roughly 500 successful attacks. Prior to its takedown, the KillSec leak website listed roughly 450 victims. Investigators are analyzing seized devices and data and tracing KillSec’s criminal proceeds, including cryptocurrency. They hope the evidence will lead to additional victims, attacks, and suspects. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK, and the US took part in the operation, which received support from cybersecurity firms Bitdefender and Group-IB. Related: Treasury Blacklists Most-Wanted ATM Malware Developer and His Network Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon Related: ShinyHunters Defiant After FBI Calls on Members to Come Forward Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training Latest News Enterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassAI Has Changed Attack Speed, Not Security FundamentalsZimbra Vulnerability Exploited in the Wild Prior to Public DisclosureKevin Mandia’s Armadin Raises $255 Million at $2.5 Billion ValuationTreasury Blacklists Most-Wanted ATM Malware Developer and His NetworkZammad Zero-Days Exploited in AI-Powered DIVD Hack500,000 Active Credentials Left Exposed on GitHub Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fpolice-shut-down-killsec-ransomware-identify-alleged-teen-leader\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FKillSwitch.jpg","2026-10-01T14:17:07+00:00","2026-10-01T16:00:06.589227+00:00",8,[18,21,24,27,29],{"name":19,"type":20},"KillSec","threat_actor",{"name":22,"type":23},"Operation KillSwitch","campaign",{"name":25,"type":26},"Europol","vendor",{"name":28,"type":26},"Bitdefender",{"name":30,"type":26},"Group-IB","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":31,"icon":33,"name":34,"slug":35},null,"Ransomware","ransomware",[37,42,44,49],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]