SOCLYDE logo
Current languageEN
Cybersecurity newsRansomwareKillSecEuropol

Killsec: arrests and infrastructure seized

Operation KillSwitch led to three arrests and the seizure of infrastructure linked to KillSec, a group associated with about 1,000 suspected attacks.

By Soclyde Team

Storage drives are placed in evidence bags in an investigation room

In summary

  • On September 30, a coordinated operation seized KillSec's data leak site and related infrastructure.
  • Europol reports three arrests, eight searches and at least 110 terabytes of data secured by authorities.
  • Previously targeted organizations should preserve logs and verify any new publication claim.

Explore next

Soclyde resources

Article contents

On September 30, 2026, authorities in several countries took control of a leak site and infrastructure linked to the extortion group KillSec. Europol and Eurojust announced the operation the next day: three people were arrested, eight properties searched and five servers seized. Authorities say they secured at least 110 terabytes of stolen data.

A 16-year-old is suspected of being the group's main operator. That remains an allegation in an ongoing investigation. Europol links the group to around 1,000 suspected attacks, a figure that does not necessarily equal confirmed incidents or identified victims.

How the group extorted victims

According to European authorities, KillSec gained access to organizations, including through poorly secured access points linked to cloud storage. The group copied data to its own infrastructure and threatened to publish it unless a ransom was paid. The seizures disrupt part of that infrastructure; they do not prove every copy has been recovered.

What the operation seized

Investigators took control of the leak site, domains and five servers used to store data attributed to victims. They are continuing to examine devices, identify additional victims and trace suspected proceeds. Any later court outcome will depend on the evidence and national proceedings.

If your organization received a demand

Do not react hastily to a new publication claim purporting to come from KillSec. Preserve the message, payment or contact evidence, shared-storage logs and account history. Ask an incident-response team to review access and report the incident to the appropriate authorities.

Taking down a criminal website does not replace checking your own systems. Revoke compromised sessions and credentials, review external sharing, and rotate secrets from trusted devices.

How Soclyde fits

Soclyde does not prevent an intrusion into a storage platform or recover stolen files. Its vault can help teams inventory business access and organize credential rotation after an investigation.

The takeaway

Operation KillSwitch disrupted infrastructure linked to KillSec while the investigation continues. Preserve evidence and verify access before declaring an incident closed. Read the team password management guide or contact Soclyde.

Frequently asked questions

Has KillSec been fully dismantled?

Authorities seized its leak site, domains and five servers. Investigators are still examining data and suspects, so the operation does not prove that all related activity has ended.

How many attacks are linked to the group?

Europol refers to around 1,000 suspected attacks worldwide. This is an investigative estimate, not a final count of confirmed incidents or identified victims.

What if my organization was targeted?

Preserve logs, extortion messages and investigator correspondence. Have an incident-response team review affected systems and accounts linked to the compromised access.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading