{
  "id": 11423528,
  "title": "Police take down dangerous KillSec ransomware gang — and find out it's being run by a teenager",
  "url": "https://urgent.news/2026/10/02/police-take-down-dangerous-killsec-ransomware-gang-and-find-out-its",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T11:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/police-take-down-dangerous-killsec-ransomware-gang-and-find-out-its-being-run-by-a-teenager"
  },
  "original_language": "en",
  "account": "Operation KillSwitch successfully dismantled the dangerous KillSec ransomware gang, seizing their infrastructure, cryptocurrency, and massive amounts of data. This operation, led by German authorities with the help of Europol, Eurojust, and multiple national law enforcement agencies, as well as cybersecurity companies like Group-IB, marked the end of the notorious KillSec group.\n\nKillSec, which emerged in 2024, made around 1,000 attacks worldwide, mostly on smaller to medium-sized organizations in sectors like healthcare, finance, and technology. The group's attacks primarily targeted organizations with sensitive data and potentially weak cybersecurity measures. While large enterprises and government organizations were targeted as well, size did not appear to be the main factor in selection.\n\nInvestigations revealed that KillSec was run by at least four individuals, including a 16-year-old ringleader whose identity remains undisclosed. The main developer recently turned 18, but many of the group's crimes were committed when he was a minor. It's possible the group was even larger, as the investigation is ongoing. Group-IB identified over 274 victim organizations, with most being from the United States (35%), followed by India, Brazil, the UK, Australia, and Colombia.\n\nThe group targeted various sectors, including financial services, healthcare, government organizations, and large enterprises. Notable victims included a major insurer, investment firms, and a popular consumer app with millions of users. During the operation, three individuals were arrested, though the ringleader was not among them.\n\nLaw enforcement seized 110 terabytes of data, the group's criminal proceeds in cryptocurrency, five central servers, and the infrastructure used to manage the group's activities and store stolen data. Multiple domains associated with KillSec were also seized and now display standard seizure notices. Police conducted eight house searches across Europe in Spain, Greece, Romania, and the United Kingdom.\n\nInitially, KillSec focused on the Windows platform, but later released its KillSec 2.0 affiliate platform, expanding into VMware ESXi virtualization hosts capable of shutting down virtual machines, deleting snapshots, erasing logs, and more. By January 2025, the group openly recruited \"skilled pentesters\" requiring a forum reputation or a USD 1,000 deposit and demanded 20% of each ransom from affiliates.\n\nDespite the group's significant impact, Operation KillSwitch's success demonstrates the importance of identifying and apprehending those behind cybercriminal activities, not just shutting down servers. The operation's contributors, including Europol, national law enforcement agencies, and cybersecurity firms like Group-IB, are proud of their contributions to bringing the KillSec gang to justice and committed to continuing the fight against cybercrime.",
  "summary": "Some people have been arrested, with servers, domains, and proceeds, confiscated, too.",
  "key_points": [
    "KillSec ransomware gang dismantled, ending 1,000 attacks worldwide",
    "16-year-old ringleader behind group, identity undisclosed",
    "Operation KillSwitch seized data, cryptocurrency, and infrastructure"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}