KillSec dismantled: 16-year-old suspected of leading group
On 30 September 2026, investigators took control of the KillSec ransomware group’s leak site and secured at least 110 terabytes of stolen data. They identified a 16-year-old as the suspected principal operator. Operation KillSwitch was led from Hamburg.
Key takeaways
- Hamburg’s State Criminal Police Office shut down five KillSec servers and seized five domains; three suspects were provisionally arrested.
- Investigators attribute around 1,000 attacks to KillSec, at least 70 of them connected to Germany.
- KillSec gained access through software vulnerabilities and poorly secured access points, particularly those for cloud storage.
Related: BKA Hunts REvil Leader After 130 Attacks on German Targets · Südwestfalen IT: The Lesson of Municipal IT
A teenager at the helm
The at least 110 terabytes came from the group’s earlier attacks and have now been placed beyond further access. Europol named the 16-year-old as the suspected principal operator on 1 October 2026.
Authorities provisionally arrested three suspects and carried out eight searches in Greece, Romania, Spain and the United Kingdom. Investigators attribute the roles of administrator, developer, negotiator and affiliate to the suspects. One suspected developer turned 18 in August 2026 and was still a minor at the time of some of the alleged offences. Investigations into other possible members are continuing.
Operation KillSwitch was led by Hamburg’s State Criminal Police Office and Hamburg’s Public Prosecutor’s Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part. Europol and Eurojust coordinated the operation, supported by security firms Bitdefender and Group-IB. Investigations began in several countries in early 2025.
What is ransomware-as-a-service?
What is ransomware-as-a-service? Ransomware-as-a-service (RaaS) is a business model in which a group rents out its extortion software and infrastructure to so-called affiliates. The affiliates carry out the attacks and give the operators a share of the ransom; for KillSec 2.0, this was 12 percent.
Around 1,000 attacks, 70 connected to Germany
Hamburg’s State Criminal Police Office shut down five KillSec servers, including the main server and several exfiltration servers. It seized five of the group’s domains and placed a seizure banner on them. It also launched a dedicated website for the operation. Investigators attribute around 1,000 suspected attacks worldwide to KillSec; around 500 have so far been identified as successful. At least 70 cases are connected to Germany, with information available to investigators in Hamburg on 18 of them. Europol and the Hamburg investigators point out that these figures may still change as the evidence is analysed.
suspected attacks worldwide; investigation findings as of 1 October 2026 (Europol)
cases connected to Germany, including 18 on which investigators in Hamburg have information (Europol)
of stolen data secured on the leak site (Europol)
Group-IB monitored the group’s leak site and public Telegram channels. A total of 274 organisations appeared there as victims. Around 35 percent were based in the United States, 17 percent in India and 14 percent in Europe. Financial services and healthcare were the sectors most affected. Group-IB counted 274 publicly named victims on the leak site, while investigators estimate around 500 successful attacks.
A business model with a price list
According to investigators’ findings, KillSec has been active since around 2024. The group threatened affected organisations on its darknet leak site with the publication of stolen data. If victims did not pay, KillSec could make their files available there for free download. In some cases, the group collected substantial ransoms.
KillSec also sold stolen data at fixed prices. Group-IB cites prices of around 4,400 euros for a single company’s datasets. For data the group claimed to have stolen from a global insurer, it demanded around 440,000 euros.
At the same time, KillSec developed a partnership model. In October 2024, Group-IB analysed the KillSec 2.0 affiliate platform: access cost around 220 euros plus a 12 percent share of the ransom. In November 2024, the group announced a locker for VMware ESXi hosts. It shuts down virtual machines, deletes snapshots and removes logs. In January 2025, KillSec sought penetration testers and required a deposit of around 880 euros or an established reputation on a forum, as well as a 20 percent share of the ransom.
The entry point: exposed cloud access
For those responsible for security, the initial access route matters most. KillSec entered systems through software vulnerabilities and inadequately secured access points, particularly those for cloud storage. According to Europol, the group used artificial intelligence to build and operate its infrastructure and identify potential victims.
Group-IB recommends five measures. Given the ESXi locker that deletes snapshots, protecting backups and virtualisation is particularly important.
Five measures recommended by Group-IB
- ✓Maintain an ongoing inventory of all internet-exposed assets, including cloud storage and remote access points.
- ✓Protect remote access with multi-factor authentication.
- ✓Patch vulnerabilities that are already being actively exploited first.
- ✓Keep backups offline and immutable, and give virtualisation platforms particular protection.
- ✓Monitor leak sites and underground markets.
Why the arrests matter
Dmitry Volkov, CEO of Group-IB, views the success primarily in terms of identifying the perpetrators. Servers could be replaced within weeks, he explained. Only identifying the people who develop the platform and authorise every attack turns a takedown from a pause into an end. Operation KillSwitch acted on both fronts: investigators shut down five servers, seized the domains and simultaneously identified suspects in administration, development, negotiation and the affiliate business. How far this affects the group permanently depends on the ongoing investigations into other members.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Who is behind KillSec?
Investigators identified a 16-year-old as the suspected principal operator. They attribute the roles of administrator, developer, negotiator and affiliate to other suspects. Three suspects were provisionally arrested; investigations into other possible members are continuing.
How many companies in Germany are affected?
According to the investigation findings as of 1 October 2026, at least 70 of the roughly 1,000 suspected attacks are connected to Germany. Investigators in Hamburg have information on 18 cases. The figures may change as further evidence is analysed.
How did KillSec enter victims’ systems?
The group used software vulnerabilities and inadequately secured access points, particularly those for cloud storage. Group-IB therefore recommends an ongoing inventory of internet-exposed assets, multi-factor authentication for remote access, prioritised patching, and backups kept offline and immutable.
Editor’s Picks
Editor’s PickScreenConnect Client Executes Files Without Host ApprovalEditor’s PickRehearse the IT outage before no one is left to decideEditor’s PickFortinet 2026: Time-to-Exploit Drops to 24-48 Hours – What DACH SOCs Must Operationalize Now
More from the MBF Media Network
cloudmagazinAWS lets an AI agent join incident investigationsDigital ChiefsAI on the Board: Why Only 12 Percent Benefit
Image source: AI-generated (October 2026)
Translated from the German original using artificial intelligence. The German version is authoritative.




