On September 30, 2026, authorities in several countries took control of a leak site and infrastructure linked to the extortion group KillSec. Europol and Eurojust announced the operation the next day: three people were arrested, eight properties searched and five servers seized. Authorities say they secured at least 110 terabytes of stolen data.
A 16-year-old is suspected of being the group's main operator. That remains an allegation in an ongoing investigation. Europol links the group to around 1,000 suspected attacks, a figure that does not necessarily equal confirmed incidents or identified victims.
How the group extorted victims
According to European authorities, KillSec gained access to organizations, including through poorly secured access points linked to cloud storage. The group copied data to its own infrastructure and threatened to publish it unless a ransom was paid. The seizures disrupt part of that infrastructure; they do not prove every copy has been recovered.
What the operation seized
Investigators took control of the leak site, domains and five servers used to store data attributed to victims. They are continuing to examine devices, identify additional victims and trace suspected proceeds. Any later court outcome will depend on the evidence and national proceedings.
If your organization received a demand
Do not react hastily to a new publication claim purporting to come from KillSec. Preserve the message, payment or contact evidence, shared-storage logs and account history. Ask an incident-response team to review access and report the incident to the appropriate authorities.
Taking down a criminal website does not replace checking your own systems. Revoke compromised sessions and credentials, review external sharing, and rotate secrets from trusted devices.
How Soclyde fits
Soclyde does not prevent an intrusion into a storage platform or recover stolen files. Its vault can help teams inventory business access and organize credential rotation after an investigation.
The takeaway
Operation KillSwitch disrupted infrastructure linked to KillSec while the investigation continues. Preserve evidence and verify access before declaring an incident closed. Read the team password management guide or contact Soclyde.



