A 16-year-old is suspected of leading the KillSec ransomware group after police seized the gang’s leak site and took control of key servers in an international operation.
Law enforcement took control of KillSec’s leak site on 30 September 2026 and secured at least 110 terabytes of data against further unauthorised access, Europol informed on Friday.
KillSec used the site to threaten organisations with the publication of stolen files unless they paid a ransom.
The action was carried out under Operation KillSwitch — an investigation led by German authorities into about 1,000 suspected attacks worldwide — with three suspects provisionally arrested and eight properties searched in Greece, Romania, Spain and the UK.
Around 500 of the suspected attacks have so far been identified as successful, though that number may change as seized evidence is examined.
How KillSec operated
KillSec has been active since around 2024 and stole sensitive data by exploiting software vulnerabilities and poorly secured access points, particularly to cloud storage, Europol said.
Victims were named on the group’s dark web leak site — a hidden website accessible using privacy tools — and threatened with having their data published unless they paid.
Where a victim did not pay, stolen files could be made available for free download, and in some cases the group obtained substantial ransom payments.
Five central servers were brought under police control during the investigation, including infrastructure used to manage the group’s activities and store data taken from victims.
Authorities also took control of KillSec domains and redirected visitors to a law enforcement seizure notice.
The operation was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office, with authorities from multiple European countries as well as the United States involved alongside Europol and Eurojust.

