European authorities takedown KillSec linked with 1 000 attacks worldwide, and secure 110 TB of stolen information | #cybercrime | #infosec


European law-enforcement authorities have conducted an international large-scale operation to dismantle KillSec

European law-enforcement authorities have conducted an international large-scale operation resulting in the dismantling of IT infrastructure used by the “KillSec” ransomware group, in a coordinated international operation involving arrests, searches and the seizure of servers, domains and stolen data.

Operation KillSwitch, conducted on 30 September—led by German authorities (Hamburg State Criminal Police and Public Prosecutor’s Office), Europol, Eurojust, and the FBI—has dismantled the KillSec ransomware-as-a-service (RaaS) network, and resulted in three provisional arrests. The Europol European Cybercrime Centre, a cross-border coordination entity, provided insights into the group and technical support. The cybersecurity companies BitDefender and Group-IB were also involved in the investigation.

The operation itself. Police raided eight houses as part of the operation, in Greece, Romania, Britain and Spain, and seized five servers allegedly used to manage the group’s activities and store stolen data. Spanish police announced the arrest on 1 October 2026 of a 16-year-old Romanian national suspected leader of the KillSec ransomware group as part of an international operation that also saw the seizure of the group’s leak site and infrastructure. Police in the UK arrested Dutch national Fouad Eltibrizi, indicted by a US federal grand jury in the District of Puerto Rico on 16 September 2026 and charged with unauthorized computer access conspiracy.

KillSec has been active since around 2024 and is suspected of being responsible for almost 1,000 attacks worldwide. Investigators have so far identified approximately 500 attacks as successful, although this figure could change as the seized evidence is analysed. The group reportedly gained access to victims by exploiting software vulnerabilities and poorly secured access points, particularly those associated with cloud storage.

After copying sensitive information to infrastructure under its control, KillSec used a double-extortion model, threatening victims with publication of stolen data unless a ransom was paid. Authorities seized five central servers used to manage the group’s activities and store stolen information, as well as domains operated by the group. More than 280 victims have reportedly been identified, with some organisations allegedly paying substantial ransoms in cryptocurrency.

The next phase will involve analysing seized devices, servers and data, tracing cryptocurrency and other criminal proceeds, and identifying additional victims, attacks and individuals involved in the group. This underlines both the potential value and the complexity of large-scale cybercrime takedowns. Securing 110 TB of stolen information can prevent further disclosure, but it also creates a substantial forensic task: investigators must process enormous quantities of digital evidence while preserving its integrity and connecting information across multiple jurisdictions.

Why does it matter?

The operation illustrates the increasingly distributed nature of ransomware ecosystems and the corresponding need for cross-border investigations. KillSec’s activities extended across multiple jurisdictions, while its infrastructure, victims, financial proceeds and suspected operators were located in different countries. Europol’s European Cybercrime Centre helped consolidate intelligence, connect investigators with private-sector partners and support cryptocurrency tracing and digital-forensics work. Eurojust coordinated judicial cooperation and helped organise the simultaneous action.

The participation of cybersecurity companies such as Bitdefender and Group-IB further demonstrates the importance of public-private cooperation in reconstructing criminal infrastructure and identifying links between apparently separate incidents. Seizing servers and controlling the leak site also serves an operational purpose beyond arresting suspects: it disrupts the group’s ability to conduct extortion, while preserving evidence that can support further investigations.

The KillSec takedown illustrates both the resilience and the vulnerabilities of the ransomware ecosystem. Criminal groups can operate as distributed networks of administrators, developers, negotiators and affiliates, allowing specialised roles to be separated across jurisdictions and making conventional national investigations insufficient. At the same time, the operation shows how coordinated international law enforcement can target not only individuals but also the infrastructure, data and financial mechanisms that sustain cybercrime.

The reported use of AI adds another dimension: if criminal groups increasingly employ AI to identify targets, develop infrastructure or automate parts of their operations, the barrier to conducting large-scale ransomware campaigns could continue to fall. The case therefore connects different trends: the industrialisation of cybercrime, the growing use of AI as an operational force multiplier, and the importance of sustained international cooperation capable of following cybercriminal activity across technical, organisational and financial boundaries.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.