Operation KillSwitch: Teenager suspected of leading KillSec ransomware group


On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom.

The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.

KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organisations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.

Read more…
Source:  EUROPOL News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • San Francisco cops can use private cameras to live-monitor ‘significant events’

    September 21, 2022

    San Francisco police are now set to use non-city-owned video cameras for real-time surveillance under a rule approved by the Board of Supervisors. The controversial policy allows the US West Coast city’s cops to use privately owned surveillance cameras and camera networks to conduct investigations as well as to live monitor “significant events with public safety ...

  • Meet Pedro, the police dog sniffing out Canberra’s cybercrime

    September 17, 2022

    Hold your smartphone up to your nose and take a deep sniff. That’s what Pedro can smell too. Pedro is a technology detector dog for the National Canine Operations unit of the Australian Federal Police (AFP). He and his four-legged peers are tasked with sniffing out laptops, phones, USB sticks and other electronic devices for criminal ...

  • Albania Claims New Cyberattack on Day the US Sanctions Iran for July Attack

    September 9, 2022

    Albania said it suffered another cyberattack on the day the U.S. announced sanctions against Iran’s Ministry of Intelligence and Security (MOIS) for an attack launched against Tirana’s government computer systems in July. “The national police’s computer systems were hit Friday by a cyberattack which, according to initial information, was committed by the same actors who in ...

  • Greece wiretap and spyware claims circle around PM Mitsotakis

    September 8, 2022

    It has been dubbed the Greek Watergate. What began as a surveillance of a little-known journalist in Greece has evolved into an array of revelations circling around the Greek government. The story emerged last spring, when Thanasis Koukakis found out his phone had been infected with spyware that can extract data from a device. He also ...

  • MBDA is refuting the alleged ‘hacking’ of the company’s information systems

    August 1, 2022

    MBDA is refuting the alleged ‘hacking’ of the company’s information systems, and has filed a report with police of an attempt to blackmail the company. MBDA is the subject of a blackmail attempt by a criminal group that falsely claims to have hacked the company’s information networks. Following the company’s refusal to yield to this blackmail ...

  • End-to-end encryption is a ‘disaster’ for counter-terrorism and stops police finding right-wing extremists online

    July 13, 2022

    End-to-end encryption on messaging apps is a “disaster” for counter-terrorism officials as it stops them finding extreme-right activity online, a new report warns. Extreme right-wing terrorists’ “conspiracy theorist, anti-government outlook” means they are “often aware of what technical security measures they need to employ to avoid detection”, parliament’s Intelligence and Security Committee says in its latest ...