European law enforcement agencies have taken down the KillSec ransomware group’s infrastructure and arrested a teenager suspected of playing a leading role in the cybercriminal operation.
In a recent press release, Europol said that on September 30, law enforcement seized KillSec’s data leak site, blocking unauthorised access to more than 110 terabytes of stolen data. The takedown was part of “Operation KillSwitch”, an international probe led by German authorities into nearly 1,000 suspected cyberattacks worldwide.
Hamburg’s police and prosecutors led the operation, with assistance from 10 countries, Europol and Eurojust involved. Cyber security firms Bitdefender and Group-IB also supported the investigation.
According to Europol, several law enforcement agencies worldwide began investigating attacks linked to KillSec in early 2025. As the probe progressed, authorities identified suspects who allegedly held different roles within the group, including an administrator, developer, negotiator and affiliate. The alleged administrator and main operator is reportedly 16 years old. Another suspect, believed to be a developer, turned18 in August 2026 but was a minor when some attacks took place. Investigators also identified two individuals suspected of acting as a negotiator and affiliate.
Law enforcement agencies carried out a coordinated operation against the KillSec cybercrime group, targeting its members and infrastructure. Officers conducted eight searches across Spain, Greece, Romania and the UK, resulting in three arrests and the seizure of evidence and assets. Authorities also took control of five key servers used to manage operations and store stolen victim data, along with its domains. Investigators are analysing seized devices, digital data and cryptocurrency transactions to identify additional suspects, victims and attacks linked to KillSec.
As the KillSec investigation progressed, Europol helped coordinate intelligence and supported investigators through its European Cybercrime Centre and J-CAT. Europol also provided expertise in cryptocurrency tracing and digital evidence analysis. Eurojust assisted judicial authorities in identifying suspects, locating infrastructure and tracing financial activity, while coordinating the international action day. Authorities from 10 countries, including the UK, US and Germany, took part in the probe.
Commenting on the news, Daniel Wilcock, threat intelligence analyst at Talion Cyber Security, said, the suspected involvement of a 16-year-old as KillSec’s main operator is particularly concerning. According to Wilcock, young people with advanced technical skills should be encouraged to use those abilities through legitimate opportunities such as bug bounty programmes, which can provide both financial rewards and career opportunities in cybersecurity. He also highlighted the need for greater awareness of the risks of cybercrime and the legitimate career paths available to young people with strong technical skills.
Click Here For The Original Source.
