On September 30, 2026, law enforcement took control of the leak site of KillSec, a ransomware-as-a-service group that investigators link to around 1,000 suspected attacks worldwide. Eurojust says authorities from nine countries worked on the case, and that the group got into victim systems through poorly secured access points, particularly those linked to cloud storage. Four primary documents describe the case from different angles, and read together they give security teams a short list of exposures to close.
What authorities say happened
Eurojust’s announcement says an international group of authorities from nine countries, coordinated by Eurojust and Europol, shut down a ransomware group responsible for almost 1,000 attacks. Investigators identified a 16-year-old as the group’s main operator. The action day produced three arrests and eight house searches in Spain, Greece, the United Kingdom and Romania. Eurojust says authorities secured at least 110 terabytes of stolen data, seized five servers the group used to store victim data, and took over domains KillSec operated.
The Hamburg police release adds the German view. The operation, named KillSwitch, was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office. Police there say at least 70 of the suspected attacks are connected to Germany, 18 of them to Hamburg, and that about 500 of the roughly 1,000 attacks identified so far were successful. Both agencies flag that the numbers may change as investigators work through the seized evidence. Hamburg also says the five servers included the main server and several exfiltration servers, and that investigators found how the group used AI to build and run its ransomware infrastructure and to identify potential victims.
Everything above describes suspects. The arrests are provisional, and the documents use the language of suspicion throughout. Eurojust says other suspects hold roles it lists as administrator, developer, negotiator and affiliate, and that the developer turned 18 recently and was a minor when some of the alleged offences took place.
How the group got in
Eurojust describes the method in plain terms. By exploiting poorly secured access points, particularly those linked to cloud storage, the group gained access to organisations’ systems. It then copied data to its own infrastructure and threatened to publish it unless the victim paid. Victims who refused had their files offered for free download, and victims who doubted the theft were sent samples as proof.
The Group-IB press release, from the security vendor that supported the investigation with intelligence on the group, fills in the entry routes. Affiliates favoured the path of least resistance, according to Group-IB. Alongside phishing, brute-force attacks on exposed Remote Desktop Protocol services and exploitation of known vulnerabilities in internet-facing applications, a substantial share of claimed victims involved no network intrusion at all. Data was taken from cloud storage left publicly accessible through misconfiguration.
That last route matters for how a defender reads the case. A ransomware group that can list a victim from an open storage bucket needs no malware on the victim’s network, which means endpoint detection has nothing to see. The only control that works against it is knowing which storage you expose, and that is an inventory problem.
Who was listed and what was sold
Group-IB counted 274 organisations that KillSec publicly claimed as victims on its leak site. Organisations in the United States made up around 35% of identified victims and India around 17%, with Brazil, the United Kingdom, Australia and Colombia at around 3% each. Financial services and healthcare were the most affected sectors, and the list also included government bodies and large enterprises.
Group-IB says KillSec declared hospitals off-limits in a January 2025 recruitment post, then from late 2025 shifted its focus toward healthcare software and IT service providers, where a single compromise can expose the patient records of every clinic using the platform. Group-IB also says encryption was not a precondition for a listing. The group sold stolen data outright, with asking prices from USD 5,000 for one company’s records to USD 500,000 for data it claimed to have taken from a global insurer. In Group-IB’s words, that made KillSec as much a data broker as a ransomware operator.
Eurojust is silent on this point, but the Hamburg release and Group-IB both say investigators uncovered how the group used AI to build and maintain its ransomware infrastructure and to identify potential victims, with Group-IB attributing the finding to Europol. None of the documents says which tools the group used or how much they helped it. The claim should be read as stated: authorities consider AI use part of the case file, and they have not published the detail.
A group that changed shape
The origin story differs between sources, and the differences are worth stating. Eurojust says KillSec has been around since 2024, and Group-IB says it first identified the group that year. Rapid7’s June 2025 research says the group has been active since at least 2021, beginning as a hacktivist outfit aligned with the Anonymous collective whose work was mainly DDoS attacks and website defacements. Rapid7 dates its pivot to ransomware to October 2023, and its move to a ransomware-as-a-service model to June 2024. Our read is that law enforcement and Group-IB describe the criminal operation, while Rapid7 traces the brand further back. None of the four documents reconciles the dates.
The service model is documented in more detail. Group-IB analysed the KillSec 2.0 affiliate platform in October 2024. At that point the Windows-only locker cost affiliates a USD 250 entry fee and a 12% share of each ransom. Affiliates could not generate builds on demand, because each build needed approval from the group’s administrators. In November 2024 KillSec announced a locker for VMware ESXi hosts, which Group-IB says could shut down virtual machines, delete snapshots and erase logs. By January 2025 the group was recruiting skilled pentesters, asking for a forum reputation or a USD 1,000 deposit, and had raised its share to 20%. Group-IB adds that some affiliates also worked with other ransomware programs, including LockBit, RansomHub, Qilin and Bashe.
Rapid7 offers one explanation for how a group could make the jump from defacements to ransomware: the public availability of leaked ransomware builders, such as LockBit 3.0, lowers the work needed to produce a payload. That is Rapid7’s assessment, and it frames the KillSec story as one example of hacktivist brands moving to financial extortion.
The case for going after the people
Group-IB’s account of the operation turns on the small core team behind the platform. It points out that builds needed administrator approval, which suggests a few people guarding the payload. Dmitry Volkov, CEO of Group-IB, put the point this way in the company’s release: “Servers can be replaced in weeks; the people who build the platform and approve every attack cannot.”
Jan Hieber, head of the Hamburg State Criminal Police Office, framed the result in terms of cooperation. In German, he called the outcome “ein nachhaltiger Schlag gegen diese kriminelle Gruppierung”, which translates roughly as a lasting blow against the group, and said cybercrime can only be fought successfully through good cooperation across borders.
The two statements make a compatible argument. Infrastructure seizures are repeatable and cheap to rebuild around, and arrests of administrators and developers are not. Whether this operation holds up depends on what investigators learn from the 110 terabytes and the seized devices, which Eurojust says may identify other victims, attacks and people involved.
What it means for the security leader
Three practical conclusions follow from the sources. First, the cloud storage route belongs on the same risk register as phishing and RDP. Group-IB lists all three as entry paths, and Eurojust singles out cloud storage. A ransomware crew that depends on exposed storage will be indifferent to how well your endpoints are patched.
Second, software and IT service providers are the new concentration risk. Group-IB’s observation that KillSec moved toward healthcare software and service providers in late 2025 describes a supplier problem: a customer can hold strong controls and still lose records held by a vendor. Our reporting on a vendor’s 2019 breach costing Labcorp $2.3M shows the legal exposure that follows. Vendor questionnaires that skip storage configuration and remote access controls miss the routes this group used.
Third, a takedown does not remove the data. Authorities say they secured at least 110 terabytes of stolen data and that other victims may yet be identified. If your organisation appeared on the leak site, or may have, expect contact from law enforcement and treat any notification obligations as live. Court outcomes also trail the crime by years, as our brief on a decade-old marketplace finally getting a guilty plea showed, so plan for a long tail. Public exposure can come from unexpected places too, as the PixelLeak screenshots posted by AI coding agents illustrated.
What to do this week
- Build a list of every internet-facing asset, including cloud storage and remote access services, and compare it to what your cloud provider reports as publicly accessible. Group-IB recommends a continuous inventory of exactly these assets.
- Require multi-factor authentication on all remote access, and close or restrict Remote Desktop Protocol exposure.
- Patch vulnerabilities known to be exploited in the wild first, and check internet-facing applications ahead of internal ones.
- Keep offline, immutable backups, and treat virtualization platforms as critical systems, since the group’s ESXi locker targeted snapshots and logs.
- Review the access that software and IT service providers have to your data, and ask each one how it secures cloud storage and remote access.
- Watch leak sites and underground markets for your organisation’s name. Group-IB says this lets you learn of an exposure early rather than from a public listing.
- Decide in advance who handles contact from law enforcement about seized data, and how it connects to your breach notification process.
The numbers in this case are provisional, and so are the arrests. The access routes are documented already, and each one can be checked today.
Source: Eurojust, Teenagers suspected of leading ransomware group arrested during international operation