Operation KillSwitch: Teenager suspected of leading KillSec ransomware group


On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom.

The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.

KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.

Read more…
Source:  EUROPOL News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Proposed Irish hate speech regulations could have a chilling effect on freedom

    January 4, 2024

    In light of the Dublin riots, which estimates suggest resulted in millions of euro worth of damage, following the stabbing of three children outside their school by a foreign national, Ireland’s regional free speech culture war battleground has become global. Several public figures from across the world have sounded the alarm over potential threats to freedom ...

  • Pakistan: Separate agency set up to tackle cybercrime challenge

    December 28, 2023

    The government has established a separate agency, National Cyber Crime Investigation Agency, equipped with all the required equipment and skills with which Pakistan’s cyberspace, data of public and private institutions, business transactions, and online activities of citizens can be secured, effectively. This was stated by Caretaker Federal Minister for Information Technology and Telecommunication Dr Umar Saif, ...

  • UK: 767 sex crime victims affected by Norfolk police data leak

    December 27, 2023

    Hundreds of victims of sexual offences were among those to have personal details leaked as part of a huge police data breach. Norfolk and Suffolk constabularies revealed in August that a technical issue had led to sensitive raw data about crimes being mistakenly disclosed as part of responses to freedom of information requests. Among the data ...

  • Lapsus$: GTA 6 hacker handed indefinite hospital order

    December 22, 2023

    An 18-year-old hacker who leaked clips of a forthcoming Grand Theft Auto (GTA) game has been sentenced to an indefinite hospital order. Arion Kurtaj from Oxford, who is autistic, was a key member of international gang Lapsus$. The gang’s attacks on tech giants including Uber, Nvidia and Rockstar Games cost the firms nearly $10m. The judge ...

  • UK: Police to be able to run face recognition searches on 50m driving licence holders

    December 20, 2023

    The police will be able to run facial recognition searches on a database containing images of Britain’s 50 million driving licence holders under a law change being quietly introduced by the government. Should the police wish to put a name to an image collected on CCTV, or shared on social media, the legislation would provide them ...

  • #StopRansomware: ALPHV Blackcat

    December 19, 2023

    The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint CSA to disseminate known IOCs and TTPs associated with the ALPHV Blackcat ransomware as a service (RaaS) identified through FBI investigations as recently as Dec. 6, 2023. This advisory provides updates to the FBI FLASH BlackCat/ALPHV Ransomware Indicators ...