Skip to main content
Emerging ThreatsMalware & Ransomware

Police Disrupt KillSec Ransomware Group, Arrest Suspects Worldwide

Police officers in tactical gear stand amidst computer servers and networking equipment in a dimly lit data center.

Investigators secured at least 110 terabytes of data when they took control of KillSec's leak site, part of an international operation that on September 30 led to three provisional arrests and the seizure of servers, domains and cryptocurrency wallets tied to a widespread extortion campaign.

Hamburg police and European partners led a coordinated takedown

Hamburg police said on October 1 that they led an operation involving law enforcement across several countries to disrupt KillSec. Europol coordinated with national agencies, Eurojust supported judicial cooperation, and the FBI's San Juan office and U.S. prosecutors in Puerto Rico participated in the action. The operation included eight searches in Spain, Greece, the U.K. and Romania and the shutdown of five servers, including KillSec's main server. Police placed seizure notices on five of the group's domains.

Three provisional arrests, one suspect a 16-year-old in Spain

Spanish forces detained a 16-year-old in Alicante on September 30, identifying him as one of KillSec's administrators and the group's presumed main administrator, the Guardia Civil and the Mossos d'Esquadra said in a joint statement. Officers searched a home and an office at a hotel in the province.

Two other men were arrested the same day—one in the U.K. and one in Romania—Europol told Reuters. Puerto Rico has filed an extradition request for the man arrested in the U.K. In Romania, DIICOT detained a 24-year-old on September 30, searched four homes in Bucharest and Vaslui county, and on October 1 prosecutors asked a Bucharest court to keep him in custody for 30 days. He is presumed innocent. Hamburg police described all three arrests as provisional.

Investigators have identified four functional roles within KillSec—an administrator, a developer, a negotiator and an affiliate. The suspected developer, who was a minor when some alleged offenses occurred and turned 18 in August, has been identified but not arrested, Reuters reported.

How investigators say KillSec operated

Hamburg police summarized the group's tradecraft: gaining access by exploiting software vulnerabilities and poorly secured access points—especially cloud storage—then copying sensitive internal data to servers under the group's control. KillSec named victims on a dark web leak site and threatened publication unless victims paid; where organizations did not pay, stolen files could be offered for free download.

DIICOT added that members purchased access credentials sold on the dark web, sent victims samples of their own data as proof, and threatened to sell the data to other criminal groups if no ransom was paid. Investigators also reported that the group used AI "to build and operate its infrastructure and identify potential victims," though Hamburg police provided no further detail in their statement.

Security company Rapid7 reported in 2025 that KillSec began as a hacktivist group active since at least 2021 and shifted to ransomware in October 2023. The group's ransomware, named KillSecurity 2.0 and 3.0, is designed to encrypt files; in some incidents the group extorted victims with stolen data alone. In June 2024 KillSec began offering its ransomware to affiliates in a ransomware-as-a-service model, according to Rapid7.

Scale of the campaign and evidence seized

Investigators say the probe covers about 1,000 suspected attacks worldwide, with roughly 500 identified as successful so far; Spanish police put the number of victims in Spain at more than 280. Europol said the group "obtained substantial ransom payments."

As part of the takedown, authorities secured at least 110 terabytes of data from the leak site and shut down servers used to hold stolen victim data. In Spain, officers seized computer equipment, phones and cryptocurrency wallets; an initial analysis found transactions matching ransom payments from some victims. Eurojust described the action as having "successfully shut down a ransomware group" and said the investigation will continue.

What this means for technologists, prosecutors, and affected organizations

  • Technologists and security teams: the operation highlights the role of cloud storage and access controls in several intrusions; investigators also said KillSec leveraged AI to operate and select targets—details that defenders will likely try to trace through the seized infrastructure and data.
  • Prosecutors and law enforcement: the multinational operation shows coordinated investigative and judicial steps—searches across four countries, extradition requests, seizure notices on domains and tracing of cryptocurrency. Authorities said inquiries into other possible members continue and that examining seized devices may identify more victims, attacks and suspects.
  • Affected enterprises and victims: with roughly 500 successful intrusions and hundreds of potential victims identified, organizations should expect investigators' follow-up as seized evidence is processed; Spanish authorities already traced ransom-payment transactions in seized wallets.

The action on September 30 removed KillSec's public leak site and its primary infrastructure from criminal use, but investigators have made clear the case is far from closed: authorities are still analyzing seized devices and data and tracing cryptocurrency payments, and investigators said the evidence may reveal more victims, attacks and suspects.

Original story