Back to Newsroom
Threat Intel

Police Dismantle KillSec Ransomware Network, Arrest Four Suspects

Police across Spain, Germany, Romania and the UK arrested four suspects and seized KillSec's leak site, five servers, and over 110TB of stolen data in a coordinated takedown.

Police Dismantle KillSec Ransomware Network, Arrest Four Suspects

Law enforcement agencies in Spain, Germany, Romania and the UK have broken up the alleged core of KillSec, a ransomware-as-a-service operation blamed for roughly 1,000 attacks worldwide since 2023. Four people were arrested in a coordinated operation that also seized the group's leak site, shut down five servers, and secured more than 110 terabytes of stolen data.

What happened

Hamburg police, who led the investigation, identified a 16-year-old in Alicante, Spain, as KillSec's suspected administrator and main operator. He was arrested on October 1 following searches carried out by Spain's Guardia Civil and Mossos d'Esquadra, who seized computers, phones and cryptocurrency wallets. An early analysis reportedly matched some wallet transactions to ransom payments from victims.

Two more suspects, both in their 20s, were detained the day before in Germany and Romania. In Romania, prosecutors from DIICOT — the country's organized-crime and terrorism unit — arrested a 24-year-old on suspicion of forming a criminal group, illegal computer access, unauthorized data transfer, illegal use of hacking tools, and blackmail. A Bucharest court has ordered him held for 30 days pending further investigation; like the other suspects, he is presumed innocent.

Investigators say KillSec operated with at least four distinct roles — an administrator, a developer, a negotiator, and affiliates who carried out attacks using the group's tools. A suspected developer, who turned 18 in August, has been identified but not arrested; he was reportedly a minor when some of the alleged offenses occurred.

Eight searches were carried out across Spain, Greece, the UK and Romania. Europol and Eurojust coordinated the international effort, with support from security firms Bitdefender and Group-IB.

Why it matters

KillSec is best known as a ransomware-as-a-service (RaaS) brand: since mid-2024 it has leased its encryptor and leak-site infrastructure to affiliates, lowering the barrier to entry for less-skilled attackers. Investigators say the group gained footholds mainly through software vulnerabilities and poorly secured access points — especially cloud storage — then exfiltrated sensitive data before threatening to publish it if a ransom went unpaid. Spanish police put the confirmed victim count above 280, out of roughly 1,000 suspected targets still under review; investigators also flagged the group's use of AI to help build its infrastructure and identify potential victims.

The takedown removes the group's public leak site and core infrastructure, but Hamburg police say the investigation into other members continues, and authorities are still tracing the group's cryptocurrency proceeds. Affiliates who used KillSec's tooling independently of the arrested core may still be active.

What to do

  • Treat cloud storage and remote-access points as high-value targets: enforce MFA, rotate credentials regularly, and close off exposed buckets or shares.
  • Patch internet-facing software promptly — KillSec's access largely came from known, unpatched vulnerabilities rather than novel exploits.
  • Monitor for unusual outbound data transfers; RaaS groups like KillSec extort victims with stolen data even when encryption fails or isn't deployed.
  • Maintain offline, tested backups and an incident response plan that treats data theft, not just encryption, as the primary threat.
  • If your organization previously received a KillSec extortion threat, preserve all communications and wallet addresses — they may support ongoing prosecutions.
SHARE