An international law enforcement operation has dismantled the KillSec ransomware gang, seizing its dark web data leak site and servers, arresting three suspects, and identifying a 16-year-old as the group's alleged main operator, according to Europol.
The coordinated action, carried out on September 30 and dubbed "Operation KillSwitch," involved authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom. Europol and Eurojust participated in the investigation alongside cybersecurity firms Bitdefender and Group-IB.
The takedown, first reported by BleepingComputer, marks one of the most notable ransomware disruptions to feature a juvenile suspect at the helm of a sophisticated criminal operation.
"The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide," Europol said in a statement. "Investigators identified a 16-year-old as the group's suspected main operator."
Three suspects were provisionally arrested and eight properties searched across Greece, Romania, Spain, and the United Kingdom. Authorities also moved to target the group's alleged criminal proceeds.
The investigation began in 2025 and allowed law enforcement to identify individuals suspected of serving as an administrator, developer, negotiator, and affiliate within the operation. A second suspected member, described as a developer, turned 18 in August 2026 and was still a minor when some of the alleged offenses occurred.
Hamburg Police said its examination of KillSec's server infrastructure led to the identification and shutdown of five servers, including the group's main server and several used to store stolen data. The group's dark web data leak site, which KillSec used to pressure victims with threats of public exposure, now displays a law enforcement seizure banner.
During the operation, authorities seized at least 110 terabytes of stolen data to prevent continued unauthorized access.
Investigators have so far determined that around 500 of KillSec's attacks were successful, though authorities noted that figure could change as analysis of seized evidence continues. At least 70 suspected attacks are linked to organizations in Germany, including 18 cases connected to Hamburg specifically.
KillSec has been active since approximately 2024 and is accused of exploiting software vulnerabilities and poorly secured edge devices to breach corporate networks and steal sensitive data. Europol confirmed that the group received "substantial" ransom payments through its extortion model.
Investigators also found that members of the group used artificial intelligence to help build and maintain their ransomware infrastructure and to identify potential victims — a tactic that underscores the growing role of AI-assisted tooling within cybercriminal ecosystems.
Authorities are now examining seized computers, servers, and additional data while working to trace KillSec's alleged criminal proceeds, which include cryptocurrency holdings. Officials said the seized evidence could reveal further victims, additional attacks, and other individuals connected to the operation.
The involvement of a minor as a suspected administrator will likely intensify scrutiny of how ransomware groups recruit and elevate young operators, and may complicate prosecution depending on jurisdiction — raising questions about how law enforcement frameworks adapt as cybercriminal networks increasingly draw in underage participants.