Police Take Down KillSec Ransomware Network Tied to 1,000 Suspected Attacks

Police seized KillSec’s infrastructure, arrested suspects, and tied the ransomware group to about 1,000 suspected attacks worldwide.

Oct 4, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

KillSec has lost much of the infrastructure it used to steal data and extort organizations worldwide. The international crackdown also identified a 16-year-old as the group’s suspected main operator.

Operation KillSwitch seized KillSec’s leak site on Sept. 30 and protected at least 110 terabytes of stolen data from further unauthorized access. Three suspects were provisionally arrested, and eight properties were searched across Spain, Greece, Romania, and the United Kingdom.

The German-led investigation covers about 1,000 suspected attacks, roughly 500 of which have been identified as successful. Europol said five central servers were also brought under police control during the investigation, while KillSec domains were redirected to law-enforcement seizure notices.

Police seize servers and arrest KillSec suspects

KillSec, also known as Kill Security or k1llsec, is a financially motivated ransomware-as-a-service operation first identified by Group-IB in 2024. Affiliates used its platform in exchange for a share of ransom payments, a model that lets operators shift between ransomware brands; Microsoft recently documented one affiliate reusing the same attack trail across four ransomware families.

Investigators identified a 16-year-old as KillSec’s suspected main operator. Spain’s Guardia Civil confirmed the arrest of a Romanian minor in Alicante over alleged involvement, while authorities identified other suspected administrator, developer, negotiator, and affiliate roles.

US prosecutors separately charged Dutch national Fouad Eltibrizi, also known as “Archduke,” with computer-access, computer-damage, and extortion-related offenses allegedly tied to KillSec. The US Department of Justice said he was arrested in the United Kingdom on Sept. 30 and is awaiting extradition.

KillSec exploited software vulnerabilities and weakly secured access points, particularly cloud storage, before stealing data and threatening disclosure. Investigators also found that the group used AI to help maintain its infrastructure and identify potential victims; separately, Google has documented attackers turning AI agents into attack tools to automate parts of intrusion workflows.

Group-IB tracked 274 organizations publicly claimed by KillSec. About 35% were in the United States and 17% in India, with financial services and healthcare the most affected sectors in its dataset.

Advertisement

KillSec exploited familiar security gaps

The access paths KillSec used remain common across ransomware campaigns. Medusa operators, for example, have been observed exploiting newly disclosed vulnerabilities rapidly, increasing pressure on organizations to reduce exposure before attackers gain a foothold.

Organizations should:

  • Patch internet-facing systems quickly and restrict unnecessary exposed services.
  • Enforce multifactor authentication, least privilege, and regular privileged-account reviews.
  • Harden cloud storage, hypervisors, and management consoles by limiting administrative access.
  • Segment critical systems and restrict unnecessary ports, protocols, and administrative paths.
  • Centralize logging and monitor unusual data transfers, privilege changes, and remote access.
  • Maintain offline or immutable backups and regularly test ransomware response, containment, communications, and recovery plans.

The KillSec investigation remains active, and the number of identified successful attacks could increase as authorities analyze seized devices, stolen data, and cryptocurrency flows.

Also read: As ransomware operations adopt more automation, agentic ransomware is creating new detection and response challenges for security teams.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.