An international law enforcement operation has taken down KillSec, a ransomware-as-a-service group linked to roughly 1,000 suspected attacks worldwide, and identified a 16-year-old as its alleged main operator.

Europol said investigators took control of the group's dark-web leak site on 30 September 2026, securing at least 110 terabytes of data that had been stolen from victims and used as leverage in extortion. Three suspects were provisionally arrested and eight properties were searched across Greece, Romania, Spain and the United Kingdom. Over the course of the investigation, five central servers were seized, including the infrastructure used to manage the gang's operations and store stolen files; KillSec's domains now redirect visitors to a law enforcement seizure notice.

The operation, dubbed "Operation KillSwitch", was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States took part, alongside Europol and Eurojust, with technical support from the security firms Bitdefender and Group-IB.

KillSec has been active since around 2024. According to Europol, it broke into corporate systems by exploiting software vulnerabilities and poorly secured access points, particularly cloud storage, then copied sensitive internal data and threatened to publish it unless victims paid. Around 500 of the suspected attacks have so far been confirmed as successful, a figure investigators expect to revise as they analyse seized evidence; at least 70 are linked to organisations in Germany, 18 of them in Hamburg. Europol says the group obtained "substantial" ransom payments in some cases.

Investigators identified distinct roles inside the group — an administrator, a developer, a negotiator and an affiliate — and said the alleged administrator turned out to be 16 years old, while a suspected developer turned 18 in August 2026 and was a minor when some of the alleged offences were committed. Europol also said the group used artificial intelligence to build and maintain its ransomware infrastructure and to identify potential victims. Authorities are now examining seized devices and tracing the group's proceeds, including cryptocurrency.