3 min read

Police dismantle ransomware gang allegedly run by a 16-year-old

Filip TRUȚĂ

October 02, 2026

Police dismantle ransomware gang allegedly run by a 16-year-old

An international operation has disrupted KillSec’s servers and data leak site, with three suspects arrested. Bitdefender supported the investigation into the group, which authorities link to around 1,000 suspected cyberattacks worldwide.

Key takeaways

  • Investigators identified a 16-year-old as KillSec’s suspected administrator and main operator
  • Operation KillSwitch leads to three provisional arrests and eight searches in four European countries
  • Authorities link the group to 1,000 suspected attacks, with roughly 500 identified as successful so far
  • Bitdefender and Group-IB support the international investigation
  • Stolen company records can put customers and employees at risk of follow-up scams

Operation KillSwitch takes down the gang’s infrastructure

The KillSec ransomware operation, accused of stealing sensitive company data and demanding payment to keep it secret, allegedly had a 16-year-old at its helm. Authorities have now seized KillSec’s leak site and secured at least 110 terabytes of data against further unauthorized access.

The coordinated action took place on Sept. 30, led by Hamburg police and prosecutors and supported by Europol and Eurojust.

Authorities searched eight properties in Greece, Romania, Spain and the United Kingdom. Hamburg police say investigators shut down five servers, including infrastructure allegedly used to store stolen files, and took control of five domains.

Bitdefender and Group-IB supported the investigation. Investigators continue to examine seized evidence and trace suspected criminal proceeds, including cryptocurrency, according to a Hamburg police announcement.

Teenagers at the center of the investigation

The suspected main operator’s age is one of the case’s striking details. Investigators also identified a suspected developer who turned 18 in August and was still a minor when some alleged offenses occurred.

Other suspects allegedly held negotiator and affiliate roles.

Authorities currently link KillSec to around 1,000 suspected attacks worldwide. Roughly 500 have been identified as successful, although the figures may change as investigators analyze the evidence.

Stealing files, then threatening to publish them

KillSec has reportedly been active since around 2024. Police say it exploited software vulnerabilities and poorly secured access points, particularly cloud storage, to obtain sensitive organizational data.

The group allegedly copied files to its own infrastructure, then threatened to publish them unless victims paid. Investigators also found evidence that members used AI to help build and operate their infrastructure and find targets.

Although KillSec is described as a ransomware group, the reported attacks highlight data theft as a source of pressure. Backups can help restore lost files, but they can’t reverse the theft of confidential information.

Why consumers should care

A company breach can become a personal security problem for its customers and employees.

Depending on the information stolen, criminals could use it to make impersonation attempts more convincing.

For example, a scammer might reference a genuine purchase while requesting payment, or pose as an employer and ask someone to “verify” their account.

How to protect yourself after a breach

  • Verify breach notices independently: Open the organization’s official website or app yourself instead of following the link in an unexpected message
  • Replace exposed passwords: Change passwords exposed in breaches and enable two-factor authentication to impede account takeover
  • Enable multifactor authentication: Protect your email, financial and other important accounts with an additional verification step
  • Question requests that use accurate personal details: Confirm payment demands or account instructions through a contact method you already trust
  • Check account activity: Review login alerts and transactions, and report unfamiliar activity promptly
  • Use a security solution on your phone and computer: Always have a trusted security solution guarding your back.

Bitdefender Digital Identity Protection scans the web for your compromised accounts, exposed passwords and other sensitive information. We alert you when we find a breach and give you the tools to prevent account compromises.

On topic:

Alleged teen ransomware hustler faces US charges after arrest in Finland

After years on the run, alleged Ryuk ransomware operator pleads guilty

Interpol crackdown shows scammers shifting to social media

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader