Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
Security· 3 min read

Police dismantle KillSec, whose alleged administrator is just 16

An international police operation seized the servers of ransomware gang KillSec on 30 September 2026 and took three people into provisional custody. The person suspected of running the group is 16 years old.

A police seizure notice replacing a ransomware gang's dark web leak site, signed by European law enforcement agencies.

An operation run out of Germany

On 30 September 2026, a coordinated action with the almost-too-perfect name “Operation KillSwitch” went after the KillSec ransomware crew: leak site and servers seized, three people taken into provisional custody, eight premises searched in Greece, Romania, Spain and the United Kingdom. Ten countries took part — Germany, Belgium, Spain, the United States, Finland, Greece, the Netherlands, Romania, the United Kingdom and Switzerland — alongside Europol and Eurojust, with two security firms, Bitdefender and Group-IB, lending a hand. The investigation, opened in 2025 and led by German authorities, covers roughly a thousand suspected attacks worldwide.

Hamburg police say they worked the group’s server infrastructure, which led them to identify and switch off five servers: the main one, plus several machines used to warehouse stolen data. The leak site, hosted as a Tor hidden service, now serves a seizure notice signed by the Hamburg state criminal police office and its partner agencies — the one page on that site nobody had to pay to read.

A 16-year-old alleged administrator

According to Europol, the person suspected of being KillSec’s administrator and main operator is 16 years old. Another alleged member, described as the group’s developer, turned 18 in August 2026, which makes them a minor for part of what they are accused of. Investigators also identified individuals suspected of filling the negotiator and affiliate roles.

No names are public and nothing has been tried in court: these are suspects, three of them in provisional custody. The part that should bother you if you run a defence team is elsewhere, and it isn’t comfortable: ransomware-as-a-service has filed the technical barrier down so far that, investigators say, teenagers can end up at the controls of an extortion operation spanning ten countries. You may not be facing a shadowy syndicate so much as someone who isn’t old enough to drive to the server room.

Around 500 successful attacks, 110 terabytes seized

Of the thousand suspected attacks, investigators currently reckon about 500 landed, while warning that the number can still move as the seized evidence is analysed. At least 70 of them are tied to German organisations, 18 of those to Hamburg. During the operation, at least 110 terabytes of stolen data were seized, to cut off the access that still existed to those files.

Active since roughly 2024, KillSec is accused of exploiting software vulnerabilities along with poorly secured edge devices and platforms to get inside corporate systems and siphon off sensitive data. The extortion followed the usual script: pay up, or watch your files turn up on the leak site. Europol says the group collected substantial ransom payments but puts no figure on it; authorities are now trying to follow the money, cryptocurrency included.

AI, on the infrastructure side

Investigators also found that members of the group leaned on artificial intelligence to build and maintain their ransomware infrastructure, and to pick out potential victims. It’s one of the few parts of the announcement that describes method rather than scoreboard, and it deserves to be read for what it is: tooling, not an attack that runs itself. No ghost in the machine — just a copilot for the tedious parts of being a criminal.

All of this comes from a single piece of journalism, the Bleeping Computer article published on 1 October 2026, which draws on statements from Europol and the Hamburg police. Until a second independent source picks it up, every line above stays in the alleged column.

The seized machines, servers and storage media are still being examined, and investigators say they expect to find more victims, more attacks and more participants in there. Until that arrives, the servers that hosted the stolen data are switched off: the one immediate, checkable result of the whole operation.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.