Police Seize KillSec Ransomware Empire and Arrest Alleged 16-Year-Old Leader After 110TB Haul
Operation KillSwitch seized KillSec's leak site, five servers and 110TB of stolen data, with three arrests and a 16-year-old identified as the alleged main administrator of a gang tied to about 1,000 attacks.

Police across Europe and the United States have taken down KillSec, a ransomware gang suspected in roughly 1,000 attacks worldwide, and the person investigators say ran it is 16 years old. The operation, dubbed Operation KillSwitch, struck on September 30, seizing the group's leak site and servers and leading to three provisional arrests.
The age of the alleged main administrator is the detail that stops people. KillSec was not a fringe crew. It extorted companies for two years and, according to Europol, collected substantial ransom payments.
How the takedown unfolded
The investigation was led by Germany, with authorities from Belgium, the United States, Finland, Greece, the Netherlands, Romania, Spain, Switzerland and the United Kingdom taking part. Europol and Eurojust coordinated, and cybersecurity firms Bitdefender and Group-IB supported the work.
Hamburg Police traced and shut down five servers, including KillSec's main server and machines used to store stolen data. Officers searched eight properties across Greece, Romania, Spain and the UK. Authorities also seized at least 110 terabytes of stolen data, a move meant to stop the gang, or anyone else, from continuing to access it or dump it on the leak site.
Of the roughly 1,000 suspected attacks under investigation, about 500 appear to have succeeded so far, according to SecurityWeek. Those figures could shift as investigators work through the seized evidence. At least 70 suspected attacks are linked to German organizations, 18 of them connected to Hamburg.
A gang run by minors
The 16-year-old is not the only young suspect. Another alleged member, described as a developer, turned 18 in August 2026 and was still a minor when some of the alleged crimes took place. None of the suspects have been convicted, and their identities have not been released.
That raises hard questions for prosecutors. Juvenile justice systems in Europe are built around rehabilitation, not the kind of sentences that usually follow large-scale extortion. Yet the damage attributed to KillSec looks like the work of a mature criminal business.
Investigators say members used artificial intelligence to help build and maintain their ransomware infrastructure and to identify potential victims. That detail, highlighted by Help Net Security, suggests AI tools are lowering the skill bar enough for teenagers to run an operation that once required seasoned criminals.
How KillSec worked
Active since around 2024, KillSec is accused of exploiting software vulnerabilities and poorly secured edge devices to break into corporate networks. Once inside, it stole data and pressured victims to pay by threatening publication on its dark web leak site. That double-extortion model is now standard across the ransomware economy, and the leak site was the gang's main lever.
With the leak site seized, that lever is gone. Leak sites have become contested ground: rival crews have even hijacked each other's portals, and police increasingly treat them as the first target in any takedown.
What it means for victims
Seizing 110TB of stolen data does not undo the breaches. Companies that were hit still face notification duties and the risk that copies of their data exist elsewhere. But pulling the servers cuts off the gang's ability to keep extorting them, and the seized evidence may help investigators identify victims who never came forward.
The entry points KillSec allegedly used are also a reminder of where defenders keep losing. Unpatched edge devices and neglected web software, the same weak spots behind persistent threats like a self-healing WordPress backdoor, remain the easiest way in, whether the attacker is a seasoned crew or a teenager with an AI assistant.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free