www.infosecurity-magazine.com 2 Oct 2026, 09:20 UTC

Police Dismantle KillSec Ransomware Ring After 1,000 Attacks

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
KillSec

POLICE have taken down a prolific ransomware operation known as KillSec, arresting its alleged ringleader and several associates. KillSec, active since 2024, is claimed by Europol to be responsible for about 1,000 attacks, with law enforcement describing more than 500 “successful” intrusions. Operation KillSwitch, led by German police, resulted in the seizure of the group’s dark web leak site, the disruption of its data-exfiltration workflow, and the prevention of at least 110TB of stolen data from being exposed.

Police also seized five control servers, stored data from victims, and multiple domain names now redirected to a police seizure notice. Group-IB, which assisted in the operation, says 274 victims had publicly claimed incidents, dominated by the US (35%) and India (17%).

KillSec operated as a ransomware-as-a-service (RaaS) outfit, with a small core team that developed the locker and approved each build. The group exploited software vulnerabilities and insecure cloud storage access points; it used Windows and VMware ESXi virtualization lockers and, in some cases, did not encrypt at all, instead stealing and extorting data. The operation also functioned as a data broker, advertising stolen data for between $5,000 and $500,000.

Eight house searches were conducted across Spain, Greece, Romania and the UK, resulting in three provisional arrests: a 16-year-old Romanian national believed to be the administrator and main operator; a developer who turned 18 in August 2026; and others including a negotiator and an affiliate. A Dutch national living in the UK, Fouad Eltibrizi (aka Archduke), was indicted in the US on hacking and extortion charges and was arrested on 30 September.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline