A 10-country cybersecurity blitz leads to three provisional arrests, eight searches, and confiscation of server hardware and 110TB of stolen data
Following an investigation into about 1,000 suspected attacks worldwide, an international law enforcement operation by Europol has seized core infrastructure used by the KillSec ransomware group.
On 30 September, Operation KillSwitch, led by the Hamburg State Criminal Police Office and Hamburg Public Prosecutor’s Office in Germany, resulted in three provisional arrests and eight property searches across Greece, Romania, Spain and the United Kingdom.
Authorities took control of KillSec’s Dark Web leak site, secured at least 110TB of data against further unauthorized access, and redirected the group’s domains to a police seizure notice. Investigators have also gained control of five central servers used to manage the operation and store data stolen from victims.
Europol said investigators had identified a 16-year-old as KillSec’s suspected administrator and main operator. A suspected developer turned 18 in August and was a minor when some of the alleged offences occurred.
Threat group backgrounder
According to Europol, KillSec gains access to organizations by exploiting software vulnerabilities and poorly secured entry points, particularly those connected to cloud storage. The group copies sensitive data to its own infrastructure, names victims on its leak site, and threatens to publish stolen files unless ransoms are paid. Data belonging to organizations could be offered for free download upon ransom refusal.
Authorities have identified about 500 of the suspected attacks as successful, although that total could change as investigators examine the seized evidence. The devices and data may also help identify further victims, attacks and participants, while investigators continue tracing alleged criminal proceeds.
The operation has started in early 2025 but the group had been in operation since 2024. Europol said the seized material would remain under police control while national authorities pursue further investigative and judicial action against suspected members worldwide.
Security firms Bitdefender and Group-IB supported Europol in the investigation, together with official support from agencies across Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK and the US.
