AUTHORITIES in nine countries have arrested three suspects accused of operating the KillSec ransomware group, which investigators say was responsible for almost 1,000 attacks worldwide. The operation was coordinated by Eurojust and Europol, with the UK represented by the Eastern Region Special Operations Unit. A 16-year-old is suspected of being KillSec’s main operator and administrator, while another suspect, a developer who recently turned 18, was allegedly a minor during some of the offences.
KillSec, active since 2024, allegedly gained access through poorly secured entry points, particularly those connected to cloud storage. The group stole data, transferred it to its own infrastructure and demanded payment by threatening to publish the files. Victims were sent samples as proof, and data was reportedly released for free download when ransoms were not paid.
Investigators also identified suspected roles including negotiator and affiliate, with members communicating through encrypted messaging services and using aliases.
The international action included eight house searches in Spain, Greece, the UK and Romania. Authorities seized five servers, KillSec-operated domains, other assets and evidence, including at least 110 terabytes of stolen data. Europol supported the investigation with activity reports, private-sector links, cryptocurrency tracing and digital-forensics expertise. The arrests and seizures reflect allegations under investigation; the supplied report does not state whether charges or convictions have been secured.