AI News Feed
Market watch
Cybersecurity

Police Dismantle KillSec Ransomware Gang, Identify Teenage Leader

Law enforcement dismantled the KillSec ransomware gang on Sept. 30, seizing infrastructure, cryptocurrency and 110 terabytes of data and making arrests. Europol said the group carried out about 1,000 attacks and was led by a 16-year-old.

Europol said KillSec emerged as a serious threat actor in 2024 and carried out roughly 1,000 attacks worldwide over two years, at least half of which were most likely successful. It primarily targeted small and midsize organizations in professional services, technology, healthcare and financial services. It sought victims with valuable or sensitive data and potentially weakly secured internet and cloud infrastructure. Large enterprises and government organizations also appeared among its targets, though company size did not appear to be the primary selection criterion.

Law enforcement began investigating the group in 2025 and quickly determined it comprised at least four people: the ringleader, the developer, the negotiator and an affiliate. The ringleader's identity was not publicly disclosed because the person is 16 years old. The main developer recently turned 18, but many of the crimes he committed were done when he was a minor. Europol said the investigation is still ongoing and the group could have been larger.

Group-IB analysts identified at least 274 victim organizations. Most, 35%, were in the United States, followed by India at 17%, and Brazil, the United Kingdom, Australia and Colombia at 3% each. The group primarily targeted financial services and healthcare firms, but also government organizations and large enterprises. Group-IB said victims included a major insurer, investment firms and a consumer app with millions of users.

During the operation, three people appeared to have been arrested, according to Europol, though the agency's wording was vague. The ringleader does not appear to be among them. Police confiscated 110 terabytes of data and the group's criminal proceeds, mostly cryptocurrency extorted from victim organizations. They seized five central servers and infrastructure used to manage the group's activities and store stolen data. Multiple KillSec domains were also seized and now display seizure notices. Police carried out eight house searches in Spain, Greece, Romania and the United Kingdom.

KillSec initially focused on the Windows platform. In late 2024, it released its KillSec 2.0 affiliate platform, which soon expanded to VMware ESXi virtualization hosts capable of shutting down virtual machines, deleting snapshots and erasing logs. By January 2025, the group was openly recruiting "skilled pentesters," requiring a forum reputation or a USD 1,000 deposit. It demanded 20% of each ransom from its affiliates.

Dmitry Volkov, CEO of Group-IB, said KillSec's affiliates "went after the organizations people depend on most: hospitals, government bodies, and financial institutions." He said closing the gaps these groups exploit is essential but does not end an operation like this. "Servers can be replaced in weeks; the people who build the platform and approve every attack cannot," Volkov said. "Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end. We are proud to have contributed to Operation KillSwitch, and will continue to support Europol and our law enforcement partners in the fight against cybercrime."