Trending: On-device modelsSearch
iHeartGeek
iTECH

Police dismantle the KillSec ransomware gang and seize its leak site

A German-led operation involving ten countries has taken control of KillSec's servers and dark-web leak site, with a 16-year-old suspected of running the group.

A person in blue forensic gloves carrying seized laptops, phones and hard drives down a corridor during a police search.

Law enforcement has shut down KillSec, a ransomware group blamed for around 1,000 suspected attacks worldwide, roughly half of which have so far been confirmed successful. On 30 September 2026 officers took control of the gang's dark-web leak site, securing at least 110 terabytes of data to stop it being used for further extortion.

The action was the centrepiece of Operation KillSwitch, an investigation led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part, alongside Europol and Eurojust, with support from the cybersecurity firms Bitdefender and Group-IB.

A group run by teenagers

KillSec has been active since around 2024. Investigators believe its known members split into distinct roles — an administrator, a developer, a negotiator and an affiliate — and say the suspected main operator is just 16 years old. A suspected developer turned 18 in August 2026, and was still a minor when some of the offences were committed.

The operation led to three provisional arrests and eight property searches across Greece, Romania, Spain and the United Kingdom. Enquiries into other possible members are continuing.

How KillSec squeezed its victims

The group broke in through software vulnerabilities and poorly secured access points, especially cloud storage, then copied sensitive internal data. Victims were named on KillSec's leak site and told their files would be published unless they paid; if they refused, the stolen material could be released for free. Europol says some victims paid substantial ransoms. Investigators also found that the group used AI to build and maintain its ransomware infrastructure and to pick out potential victims.

What police seized

Over the course of the investigation, five central servers came under police control, including systems used to manage attacks and store data taken from victims. KillSec's domains were also seized and now redirect visitors to a law enforcement notice. Officers are examining the seized devices and tracing criminal proceeds, including cryptocurrency, which may identify further victims and attacks.

Our opinion

A ransomware crew run by teenagers is not a curiosity; it is the shape of modern cybercrime. The tooling is cheap, the AI assistance is real, and the barrier to extorting a hospital or a small business keeps falling. Operation KillSwitch deserves credit for following the infrastructure and the money rather than chasing headlines, but the arrests also underline how young the offenders can be, and how badly the justice system is built for a 16-year-old with a cryptocurrency wallet.