"The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide," says Europol.
Operation KillSwitch: coordination on September 30 and the participating nations
The coordinated law-enforcement action, carried out on September 30, involved authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom. Europol and Eurojust supported the operation alongside cybersecurity companies Bitdefender and Group‑IB. German authorities led the investigation, which Europol says began in 2025 and targeted roughly 1,000 suspected attacks worldwide.
Seizures: servers, the dark‑web leak site, and 110 terabytes of stolen data
Hamburg Police said their probe into the group's server infrastructure led to the identification and shutdown of five servers, including KillSec's main server and several used to store stolen data. One seized site is KillSec's dark web data leak site, hosted at https://ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion/, which now displays a seizure message.
The seizure banner reads: "The domain, servers and all associated data linked to Operation KillSwitch have been taken into control by State Criminal Police Office of Hamburg and international law enforcement agencies." Clicking that banner reportedly leads to the Operation KillSwitch website, which includes a law‑enforcement video about the ransomware gang and the arrests.
During the operation, law enforcement seized at least 110 terabytes of stolen data to prevent continued unauthorized access. Authorities also conducted eight searches in Greece, Romania, Spain, and the United Kingdom, and targeted the group's criminal proceeds as part of the action.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageAlleged personnel: a 16‑year‑old administrator and identified roles
Investigators identified suspects believed to have filled roles described as an administrator, a developer, a negotiator, and an affiliate of the cybercrime group. Europol and investigating authorities say the suspected administrator and main operator is only 16 years old. Another suspected member, described as a developer, turned 18 in August 2026 and was still a minor when some of the alleged crimes were committed.
Three suspects were provisionally arrested and eight properties were searched across Greece, Romania, Spain, and the United Kingdom. Authorities say they have also targeted the group's criminal proceeds, including attempts to trace cryptocurrency linked to the operation.
Attack profile: techniques, scale, and the use of artificial intelligence
KillSec has been active since around 2024, authorities say. The group is accused of exploiting software vulnerabilities and poorly secured edge devices and platforms to breach corporate systems and steal sensitive data. Investigators determined that around 500 of KillSec’s attacks were successful so far, while cautioning that the numbers could change as analysis of seized evidence continues.
At least 70 of the suspected attacks are linked to organizations in Germany, including 18 cases connected to Hamburg. The stolen corporate data was used to extort victims via KillSec’s dark‑web leak site, with threats that the data would be published if a ransom was not paid. Europol states that KillSec received "substantial" ransom payments from these data‑theft attacks. Investigators also discovered the group used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: expect continued forensic analysis of seized servers and data; the reported AI use to maintain infrastructure and identify targets highlights a need to examine attack automation and edge‑device hygiene in incident response.
- Policymakers and prosecutors: the cross‑border scope—ten countries plus Europol and Eurojust participation—illustrates how international coordination is being applied to both disruption and financial‑proceeds tracing, including cryptocurrency.
- Affected enterprises and procurement leaders: organizations that rely on edge devices and third‑party platforms should check whether they feature among roughly 500 suspected successful attacks and be prepared to cooperate with investigators as seized evidence is analyzed and victim lists are reconstructed.
Authorities are now examining seized computers, servers, and other data while attempting to trace KillSec's alleged criminal proceeds. Investigators say the seized evidence could reveal further victims, attacks, and people involved with the ransomware operation—a next phase that will determine how many of the roughly 1,000 suspected incidents are attributable to this group and whether additional arrests or asset recoveries follow.




