Threats · 2h ago
Eurojust says arrests and seizures followed an investigation into KillSec, a ransomware group blamed for almost 1,000 data-extortion attacks worldwide. Police identified a 16-year-old as the suspected main operator, with three arrests made and servers, domains, and evidence seized across several countries.
KillSec got in through poorly secured access, especially access tied to cloud storage, then copied victim data into its own infrastructure and used samples and full dumps to pressure payment. That means the intrusion path was low-friction, but the leverage came from data theft: once the files were copied, the extortion threat survived even if the original access was cut off.
For organizations that expose cloud-linked storage or other weak remote access, the lasting exposure is the stolen data and the blackmail trail it creates, not just the operator network that police disrupted. The takedown can slow the gang; it does not rewind the theft already done.
4 sources covering this story
The Record from Recorded Future
Police disrupt KillSec ransomware, arrest suspected teenage leader
European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.
16-year-old suspected leader of KillSec ransomware group arrested - Help Net Security
A 16-year-old is suspected of being the main operator of KillSec, a ransomware group linked by Eurojust to almost 1,000 attacks worldwide.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed
Part of the PlainSec briefing for 2026-10-01