Operation KillSwitch: Teenager suspected of leading KillSec ransomware group


On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom.

The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.

KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.

Read more…
Source:  EUROPOL News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Australia plans law for tech firms to hand over encrypted private data

    August 14, 2018

    Australia on Tuesday proposed a new law requiring technology firms such as Alphabet Inc’s Google, Facebook and Apple to give police access to private encrypted data linked to suspected illegal activities. The measure, which targets platforms the Australian government says could be used for criminal activities or to plan a terror attack, would require police to ...

  • FBI struggles to retain top cyber talent

    August 3, 2018

    The recent departures of four top FBI cyber officials reflect a troubling trend: The bureau is losing its most seasoned agents and supervisors tasked with disrupting digital threats from Russia and elsewhere, even as threats to the nation’s power grid and elections grow. Close to 20 top FBI cybersecurity leaders have left for high-paying corporate jobs over the ...

  • DOJ Nab Three FIN7 Cybercrime Suspects in Europe

    August 1, 2018

    Three people believed to be member of the FIN7 (or Carbanak) hacking group have been arrested in Europe, according to the US DOJ. Three suspected members of the FIN7 cybercrime group have been arrested in Europe and accused of hacking more than 120 U.S.-based companies with the intent of stealing bank cards. In total, U.S. Department of ...

  • Indictments Against 12 Russians Show How Hackers Were Hacked

    July 18, 2018

    Hi everybody, Jordan Robertson here. I cover cybersecurity in Washington, D.C. Today’s newsletter is about Special Counsel Robert Mueller’s indictment this week of 12 Russian military officers for allegedly orchestrating the hacks of the 2016 U.S. presidential election. The indictment, which I encourage you to read if you’re interested in technical details about how the hacks worked, is remarkable in a number ...

  • Ex-NSO Employee Caught Selling Stolen Phone Hacking Tool For $50 Million

    July 5, 2018

    A former employee of one of the world’s most powerful hacking companies NSO Group has been arrested and charged with stealing phone hacking tools from the company and trying to sell it for $50 million on the Darknet secretly. Israeli hacking firm NSO Group is mostly known for selling high-tech malware capable of remotely cracking into ...

  • GCHQ chief highlights UK’s ‘critical role’ in thwarting European attacks

    June 19, 2018

    Speaking after meetings at NATO’s Brussels headquarters, Jeremy Fleming cited GCHQ’s involvement in disrupting terrorist activity on the continent in a bid to highlight the importance of UK-EU security links. The comments will be viewed in some quarters as a pointed intervention in the Brexit debate, coming hot on the heels of remarks by the EU’s chief ...