An international law enforcement operation has dismantled key infrastructure belonging to the KillSec ransomware group, with investigators identifying a 16-year-old as the suspected main operator behind a cybercrime campaign linked to hundreds of successful attacks.
The coordinated action took place on September 30 under Operation KillSwitch, an investigation led by German authorities. Police carried out eight searches across Spain, Greece, Romania and the United Kingdom, while three suspects were provisionally arrested and evidence and assets were seized.
Authorities also gained control of five central servers used by KillSec. The seized infrastructure included systems used to manage the group’s operations and store information stolen from victims, while KillSec’s domains were redirected to a law enforcement seizure notice.
At least 110 terabytes of stolen information were secured during the operation, preventing further unauthorized access through the infrastructure now controlled by authorities. Investigators are examining the seized systems to identify additional victims and potentially uncover other people involved in the operation.
KillSec has been active since around 2024 and is suspected of carrying out approximately 1,000 attacks worldwide. Investigators have so far classified around 500 of those attacks as successful, although authorities caution that the number could change as more evidence is analyzed.
The group allegedly gained access to organizations by exploiting software vulnerabilities and poorly protected entry points, particularly those connected to cloud storage. After entering a victim’s systems, KillSec members copied sensitive information to infrastructure under their control.
That stolen information was then used for extortion. Victims were listed on KillSec’s dark-web site and threatened with publication unless they paid a ransom. When organizations refused, their stolen files could be made available for anyone to download.
The investigation has produced an unusual picture of the suspected people behind the operation. Authorities say the alleged administrator and main operator is only 16 years old, while another suspected member identified as a developer turned 18 in August and was still a minor when some of the alleged offenses occurred.
Investigators have also identified people suspected of working as a ransom negotiator and an affiliate. A 25-year-old man arrested in Manchester is suspected of negotiating with KillSec victims and was scheduled to face extradition proceedings in London.
Authorities say KillSec also incorporated artificial intelligence into its activities. Investigators found evidence that AI was used to help develop and maintain the group’s ransomware infrastructure and identify organizations that could potentially be targeted.
Operation KillSwitch involved authorities from countries including Germany, the United States, Belgium, Finland, Greece, Romania, Spain, Switzerland and the United Kingdom, with international coordination from Europol and Eurojust. Cybersecurity companies also assisted the investigation.
