Skip to content
Brief Security & Trust ·

Police take down KillSec ransomware sites; 16-year-old suspect arrested

Police seized servers and held suspects, but the gaps KillSec used are closed only by each victim.

In brief
  • Police took KillSec's leak site and five servers and made three provisional arrests. Europol says at least 110TB of stolen data was kept from going public.
  • Europol says the group got in through software flaws and poorly secured cloud storage. Those gaps are fixed by each victim, not by arrests.

Infosecurity Magazine reported on 2 October that German-led police ran Operation KillSwitch against KillSec, a ransomware group active since 2024. Europol said it carried out at least 500 successful attacks. Police seized its leak site, five servers and some domains, keeping at least 110TB of stolen data from going public, Europol said. Eight house searches in four countries ended with three provisional arrests, including a 16-year-old believed to run the group.

Europol said KillSec got in through software flaws and poorly secured cloud storage, meaning access points that are not locked down well. Infosecurity Magazine said it sometimes stole data without locking files, then advertised it for $5,000 to $500,000. Group-IB's Dmitry Volkov said servers can be replaced within weeks, but the people who build the platform and approve attacks cannot. The sources do not say whether KillSec is still active.

Arrests target the people, yet each victim still has to close its own gaps. Data theft without locked files means backups alone do not help. Budget signers can ask: Who checks which cloud storage is open to outsiders? How fast do software fixes go live? Do we have a plan for stolen data, not just locked files?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Infosecurity Magazine.