Operation KillSwitch: Teenager suspected of leading KillSec ransomware group


On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom.

The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.

KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.

Read more…
Source:  EUROPOL News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • ‘NetWalker’ Ransomware Attacker Gets 20 Years in Prison

    December 21, 2024

    Romanian national Daniel Christian Hulea pleaded guilty to computer fraud conspiracy and wire fraud conspiracy. NetWalker ransomware attacks often targeted the healthcare sector during the COVID-19 pandemic. The attacker obtained nearly 1,600 Bitcoin ransomware payments as a result of his attacks, netting him and another affiliate about $21.5 million. Hulea is being ordered to forfeit these ...

  • Beware Feb. 3, 2025 – Diabolic Ransomware Gang Issues New Attack Warning

    December 21, 2024

    If you thought law enforcement had not only disrupted the LockBit ransomware operation, alongside trolling the criminal gang behind it but taken it out of business altogether, then you are likely in for a shock: LockBitSupp, the group’s alleged leader, has warned LockBit 4 will return next year. In fact, a dark web posting said the ...

  • Third member of LockBit ransomware gang has been arrested

    December 20, 2024

    U.S. prosecutors in New Jersey on Friday publicly announced charges against Rostislav Panev, 51, a dual Russian-Israeli national accused of being a key developer in the LockBit ransomware gang. Panev is currently in Israeli custody and faces extradition to the United States. LockBit is one of the most prolific ransomware gangs, accused of launching crippling data-stealing ...

  • How the ransomware attack at Change Healthcare went down – a timeline

    December 18, 2024

    A ransomware attack earlier this year on UnitedHealth-owned health tech company Change Healthcare likely stands as one of the largest data breaches of U.S. health and medical data in history. Months after the February data breach, a “substantial proportion of people living in America” are receiving notice by mail that their personal and health information was ...

  • Europol spearheads largest referral action against online hate speech

    December 16, 2024

    Europol has supported 18 European law enforcement agencies in the 2024 Referral Action Day (RAD) on hate speech and incitement to violence targeting ethnoreligious groups. Spanish and Hungarian authorities led the action, which resulted in a record number of online content being identified. In total, 12 countries collected over 6 350 links from 46 online platforms ...

  • Six arrested in South Thailand for call centre scams and firearms

    December 13, 2024

    Police apprehended six people suspected of being involved in call centre scams and the illegal trade of firearms. The Cyber Crime Investigation Bureau (CCIB) announced the arrest on Tuesday, December 10, indicating possible connections between the suspects and insurgency financing in Thailand’s southern regions. The arrests took place on December 10 in Songkhla and Yala provinces ...