Authorities Arrested Three KillSec Ransomware Suspects

A multinational operation seized five servers and 110 terabytes of stolen data from the hacking group.

Updated on Oct. 1, 2026 in Cybersecurity

Bold flat-color editorial illustration of a stylized server rack in navy and cream, representing the dismantling of digital criminal infrastructure.
Authorities across nine countries arrested three suspects linked to the KillSec ransomware group, seizing servers and data to dismantle the criminal enterprise. AI Illustration. Upload story photo >

Live Poll

Should law enforcement prioritize international cooperation to combat rising digital ransomware threats?

Police from nine countries coordinated to arrest three primary suspects linked to the KillSec ransomware group. The operation included eight house searches across Europe and resulted in the seizure of five servers.

Why it matters

The group allegedly extorted victims by threatening to release stolen data publicly after exploiting insecure cloud storage. This international intervention effectively halted the group's ability to hold victim data for ransom.

The operation resulted in the seizure of 110 terabytes of stolen data and five servers. Authorities also secured domains previously utilized by the group to manage their illicit activities.

The players

KillSec

This ransomware group has operated since 2024 by extorting victims and threatening to release their stolen data.

Eurojust

This agency serves as the European Union's judicial cooperation unit and coordinated the multi-country investigation.

The details

The suspects, including a teenager identified as the group's main operator, gained system access by targeting vulnerable cloud storage access points. Authorities in nine countries conducted eight house searches in Spain, Greece, the United Kingdom, and Romania to dismantle the criminal enterprise.

Timeline

  1. The KillSec group began its operations in 2024.

The Tech Race

This disruption reflects a broader push by international authorities to combat cybercrime facilitated by misconfigured cloud storage access points. It marks a significant effort to neutralize groups that leverage automated exploits to compromise global infrastructure.

The seizure of stolen data and group domains prevents the public release of sensitive information previously held by the attackers. Victims who were targeted by the group may soon receive updates from law enforcement regarding the recovery of their compromised information.

The takeaway

Securing cloud storage with strict access controls remains the most effective defense against ransomware extortion. Organizations should treat data storage as a primary security perimeter to prevent similar vulnerabilities from being exploited.

What happens next

Authorities will continue their investigation by examining the seized devices and tracing the group's financial proceeds.

Further reading

Learn more about the latest developments in Cybersecurity.

Live Poll

Should law enforcement prioritize international cooperation to combat rising digital ransomware threats?