Police take down dangerous KillSec ransomware gang and discover it is led by a teenager
- Operation KillSwitch dismantled KillSec and seized infrastructure, cryptocurrency and 110TB of data
- The investigation identified the main members; Several arrests were made, including key operators.
- KillSec claimed 1,000 attacks targeting healthcare, finance, government and SMEs.
The infamous KillSec ransomware group is no more after Europol, along with multiple national law enforcement agencies and cybersecurity companies, seized the group’s infrastructure and data, made some arrests, and even identified the group’s leader.
On September 30, law enforcement began Operation KillSwitch. It was led by German authorities, with the assistance of many other agencies: Europol, Eurojust, as well as authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States.
Private cybersecurity companies such as Group-IB also participated with vital intelligence, having rated KillSec as one of the most active ransomware groups in 2025 in Asia-Pacific, Latin America and the Middle East.
Latest videos ofTechnologyRadar
Operation KillSwitch
KillSec emerged as a serious threat actor sometime in 2024, Europol said. Over the next two years, it carried out approximately 1,000 attacks around the world, at least half of which were likely successful. KillSec primarily targeted small and medium-sized organizations, often in professional services, technology, healthcare, or financial services.
They primarily targeted organizations with valuable or sensitive data and potentially insecure Internet and cloud infrastructures. Large companies and government organizations also appeared, but company size does not appear to have been the main selection criterion.
Law enforcement began investigating the group in 2025, Europol said, and quickly determined it was made up of at least four people: the ringleader, the promoter, the negotiator and an affiliate. The identity of the ringleader was not revealed publicly because the person is 16 years old. The lead developer recently turned 18, but many of the crimes he committed were committed when he was a minor. There is also a possibility that the group was even larger – the investigation is still ongoing.
Group-IB analysts had identified at least 274 victim organizations, the majority of which (35%) were from the United States.
They are followed by India (17%), Brazil, the United Kingdom, Australia and Colombia (3% each). He focused primarily on financial services and healthcare companies, but did not shy away from government organizations and large companies. Among its victims, Group-IB says, are a “major insurer, investment firms and a consumer app with millions of users.”
Multiple arrests
During the operation, three people were apparently arrested. Europol’s wording is somewhat vague, but it appears that the ringleader is not among them. Police confiscated 110 terabytes of data, as well as “the group’s criminal proceeds” (mostly cryptocurrencies extorted from victim organizations). They seized five central servers, as well as the infrastructure used to manage the group’s activities and store stolen data. Several domains used by KillSec were also captured and now display the usual seizure notice.
Police carried out eight house searches across Europe, in Spain; Greece, Romania and the United Kingdom.
Initially, KillSec focused on the Windows platform. However, in late 2024 it launched its affiliated KillSec 2.0 platform, which soon expanded to VMware ESXi virtualization hosts that were capable of shutting down virtual machines, deleting snapshots, erasing logs, and more. In January 2025, the group was openly recruiting “qualified pentesters”, demanding a forum reputation or a $1,000 deposit.
He demanded 20% of each ransom from his members.
“KillSec affiliates went after the organizations people depend on most: hospitals, government agencies, and financial institutions. Closing the loopholes these groups exploit is essential, but that doesn’t put an end to an operation like this. Servers can be replaced in weeks; the people who build the platform and approve each attack can’t. Identifying them and supporting law enforcement to bring them to justice is what takes a takedown from a lull to an end. We’re proud to have contributed to the Operation KillSwitch and we will continue to support Europol and our law enforcement partners in the fight against cybercrime,” said Dmitry Volkov, CEO of Group-IB.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment