{"id":24564,"date":"2026-10-04T09:00:00","date_gmt":"2026-10-04T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=24564"},"modified":"2026-10-06T21:38:53","modified_gmt":"2026-10-06T21:38:53","slug":"killsec-dismantled-16-year-old-suspected-leader","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/10\/04\/killsec-dismantled-16-year-old-suspected-leader\/","title":{"rendered":"KillSec dismantled: 16-year-old suspected of leading group"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">5 min read<\/p>\n<p><strong>On 30 September 2026, investigators took control of the KillSec ransomware group&#8217;s leak site and secured at least 110 terabytes of stolen data. They identified a 16-year-old as the suspected principal operator. Operation KillSwitch was led from Hamburg.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Hamburg&#8217;s State Criminal Police Office shut down five KillSec servers and seized five domains; three suspects were provisionally arrested.<\/strong> <\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Investigators attribute around 1,000 attacks to KillSec, at least 70 of them connected to Germany.<\/strong> <\/li>\n<li style=\"margin-bottom:0;\"><strong style=\"color:#69d8ed;\">KillSec gained access through software vulnerabilities and poorly secured access points, particularly those for cloud storage.<\/strong> <\/li>\n<\/ul>\n<\/div>\n<p style=\"border-top:1px solid rgba(230,227,218,0.14);border-bottom:1px solid rgba(230,227,218,0.14);padding:14px 0;margin:28px 0;font-size:0.92em;color:#b8c5ce;\"><strong style=\"color:#69d8ed;\">Related:<\/strong> <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/bka-revil-anfuehrer-130-angriffe-deutschland-strafverfolgung\/\">BKA Hunts REvil Leader After 130 Attacks on German Targets<\/a>  \u00b7  <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/05\/south-westphalia-it-the-lesson-of-municipal-it\/\">S\u00fcdwestfalen IT: The Lesson of Municipal IT<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">A teenager at the helm<\/h2>\n<p>The at least 110 terabytes came from the group&#8217;s earlier attacks and have now been placed beyond further access. <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site\">Europol<\/a> named the 16-year-old as the suspected principal operator on 1 October 2026.<\/p>\n<p>Authorities provisionally arrested three suspects and carried out eight searches in Greece, Romania, Spain and the United Kingdom. Investigators attribute the roles of administrator, developer, negotiator and affiliate to the suspects. One suspected developer turned 18 in August 2026 and was still a minor at the time of some of the alleged offences. Investigations into other possible members are continuing.<\/p>\n<p>Operation KillSwitch was led by Hamburg&#8217;s State Criminal Police Office and Hamburg&#8217;s Public Prosecutor&#8217;s Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part. Europol and Eurojust coordinated the operation, supported by security firms Bitdefender and Group-IB. Investigations began in several countries in early 2025.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What is ransomware-as-a-service?<\/h2>\n<p><strong>What is ransomware-as-a-service?<\/strong> Ransomware-as-a-service (RaaS) is a business model in which a group rents out its extortion software and infrastructure to so-called affiliates. The affiliates carry out the attacks and give the operators a share of the ransom; for KillSec 2.0, this was 12 percent.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Around 1,000 attacks, 70 connected to Germany<\/h2>\n<p>Hamburg&#8217;s State Criminal Police Office shut down five KillSec servers, including the main server and several exfiltration servers. It seized five of the group&#8217;s domains and placed a seizure banner on them. It also launched a dedicated website for the operation. Investigators attribute around 1,000 suspected attacks worldwide to KillSec; around 500 have so far been identified as successful. At least 70 cases are connected to Germany, with information available to investigators in Hamburg on 18 of them. Europol and the Hamburg investigators point out that these figures may still change as the evidence is analysed.<\/p>\n<div data-element=\"stat_row\" style=\"display:flex;flex-wrap:wrap;gap:16px;margin:32px 0;\">\n<div style=\"flex:1 1 200px;min-width:0;background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:22px 20px;box-sizing:border-box;\">\n<div style=\"font-size:1.4em;font-weight:800;color:#69d8ed;line-height:1.1;word-break:keep-all;\">around 1,000<\/div>\n<p style=\"margin:10px 0 0;font-size:0.88em;color:#e6e3da;line-height:1.5;\">suspected attacks worldwide; investigation findings as of 1 October 2026 (Europol)<\/p>\n<\/div>\n<div style=\"flex:1 1 200px;min-width:0;background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:22px 20px;box-sizing:border-box;\">\n<div style=\"font-size:1.7em;font-weight:800;color:#69d8ed;line-height:1.1;word-break:keep-all;\">at least 70<\/div>\n<p style=\"margin:10px 0 0;font-size:0.88em;color:#e6e3da;line-height:1.5;\">cases connected to Germany, including 18 on which investigators in Hamburg have information (Europol)<\/p>\n<\/div>\n<div style=\"flex:1 1 200px;min-width:0;background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:22px 20px;box-sizing:border-box;\">\n<div style=\"font-size:1.7em;font-weight:800;color:#69d8ed;line-height:1.1;word-break:keep-all;\">110 TB<\/div>\n<p style=\"margin:10px 0 0;font-size:0.88em;color:#e6e3da;line-height:1.5;\">of stolen data secured on the leak site (Europol)<\/p>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/www.group-ib.com\/media-center\/press-releases\/operation-killswitch-killsec\/\">Group-IB<\/a> monitored the group&#8217;s leak site and public Telegram channels. A total of 274 organisations appeared there as victims. Around 35 percent were based in the United States, 17 percent in India and 14 percent in Europe. Financial services and healthcare were the sectors most affected. Group-IB counted 274 publicly named victims on the leak site, while investigators estimate around 500 successful attacks.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">A business model with a price list<\/h2>\n<p>According to investigators&#8217; findings, KillSec has been active since around 2024. The group threatened affected organisations on its darknet leak site with the publication of stolen data. If victims did not pay, KillSec could make their files available there for free download. In some cases, the group collected substantial ransoms.<\/p>\n<p>KillSec also sold stolen data at fixed prices. Group-IB cites prices of around 4,400 euros for a single company&#8217;s datasets. For data the group claimed to have stolen from a global insurer, it demanded around 440,000 euros.<\/p>\n<p>At the same time, KillSec developed a partnership model. In October 2024, Group-IB analysed the KillSec 2.0 affiliate platform: access cost around 220 euros plus a 12 percent share of the ransom. In November 2024, the group announced a locker for VMware ESXi hosts. It shuts down virtual machines, deletes snapshots and removes logs. In January 2025, KillSec sought penetration testers and required a deposit of around 880 euros or an established reputation on a forum, as well as a 20 percent share of the ransom.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The entry point: exposed cloud access<\/h2>\n<p>For those responsible for security, the initial access route matters most. KillSec entered systems through software vulnerabilities and inadequately secured access points, particularly those for cloud storage. According to Europol, the group used artificial intelligence to build and operate its infrastructure and identify potential victims.<\/p>\n<p>Group-IB recommends five measures. Given the ESXi locker that deletes snapshots, protecting backups and virtualisation is particularly important.<\/p>\n<div data-element=\"checklist\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:22px 24px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 12px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Five measures recommended by Group-IB<\/p>\n<ul style=\"margin:0;padding-left:0;list-style:none;\">\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">\u2713<\/span>Maintain an ongoing inventory of all internet-exposed assets, including cloud storage and remote access points.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">\u2713<\/span>Protect remote access with multi-factor authentication.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">\u2713<\/span>Patch vulnerabilities that are already being actively exploited first.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">\u2713<\/span>Keep backups offline and immutable, and give virtualisation platforms particular protection.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">\u2713<\/span>Monitor leak sites and underground markets.<\/li>\n<\/ul>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why the arrests matter<\/h2>\n<p>Dmitry Volkov, CEO of Group-IB, views the success primarily in terms of identifying the perpetrators. Servers could be replaced within weeks, he explained. Only identifying the people who develop the platform and authorise every attack turns a takedown from a pause into an end. Operation KillSwitch acted on both fronts: investigators shut down five servers, seized the domains and simultaneously identified suspects in administration, development, negotiation and the affiliate business. How far this affects the group permanently depends on the ongoing investigations into other members.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Who is behind KillSec?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Investigators identified a 16-year-old as the suspected principal operator. They attribute the roles of administrator, developer, negotiator and affiliate to other suspects. Three suspects were provisionally arrested; investigations into other possible members are continuing.<\/p>\n<\/details>\n<details>\n<summary><strong>How many companies in Germany are affected?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">According to the investigation findings as of 1 October 2026, at least 70 of the roughly 1,000 suspected attacks are connected to Germany. Investigators in Hamburg have information on 18 cases. The figures may change as further evidence is analysed.<\/p>\n<\/details>\n<details>\n<summary><strong>How did KillSec enter victims&#8217; systems?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The group used software vulnerabilities and inadequately secured access points, particularly those for cloud storage. Group-IB therefore recommends an ongoing inventory of internet-exposed assets, multi-factor authentication for remote access, prioritised patching, and backups kept offline and immutable.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/09\/17\/screenconnect-client-executes-files-without-host-approval\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/screenconnect-client-fuehrt-dateien-ohne-host-ok-aus-cover-hero-250x140.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">ScreenConnect Client Executes Files Without Host Approval<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/09\/21\/practice-it-failure-before-no-one-can-decide\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/it-ausfall-ueben-bevor-niemand-mehr-entscheidet-cover-hero-250x143.png\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Rehearse the IT outage before no one is left to decide<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/27\/fortinet-2026-time-to-exploit-24-48-stunden-dach-soc\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/fortinet-2026-time-to-exploit-24-48-stunden-dach-soc-ransomware-389-prozent-2026-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Fortinet 2026: Time-to-Exploit Drops to 24-48 Hours \u2013 What DACH SOCs Must Operationalize Now<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/09\/26\/aws-uses-ai-agent-during-outages\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/10\/net-aws-laesst-bei-stoerungen-einen-ki-agent-38991680.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">AWS lets an AI agent join incident investigations<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/ai-on-the-board-why-only-12-percent-benefit\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-ki-vorstand-pwc-ceo-survey-12-prozent-ki-46402581-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">AI on the Board: Why Only 12 Percent Benefit<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;margin-top:8px;\">Image source: AI-generated (October 2026)<\/p>\n","protected":false},"excerpt":{"rendered":"Investigators dismantled the KillSec ransomware group. Its suspected leader is 16, and initial access often came through cloud storage.","protected":false},"author":50,"featured_media":24465,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"KillSec","_yoast_wpseo_title":"KillSec dismantled: 16-year-old suspected of leading group","_yoast_wpseo_metadesc":"Investigators dismantled the KillSec ransomware group. Its suspected leader is 16, and initial access often came through cloud storage.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[251],"tags":[],"class_list":["post-24564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":24463,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=24564"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24564\/revisions"}],"predecessor-version":[{"id":24565,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24564\/revisions\/24565"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/24465"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=24564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=24564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=24564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}