Operation KillSwitch: KillSec ransomware takedown, a 16-year-old suspect and a US indictment
By Sethu Satheesh · 2 Oct 2026 · 21 min read
Threat Actor: KillSec (Kill Security, k1llsec) · Target: Organisations worldwide, financial services and healthcare most affected; about 500 successful attacks per investigators
Source: www.europol.europa.eu
Executive Summary
On 30 September 2026, law enforcement in a German-led investigation called Operation KillSwitch took control of the dark web leak site of KillSec (also tracked as Kill Security and k1llsec), secured at least 110 terabytes of stolen data, brought five central servers under police control, carried out eight searches in Greece, Romania, Spain and the United Kingdom, and made three provisional arrests1. The operation was led by the Hamburg State Criminal Police Office (Landeskriminalamt Hamburg) and the Hamburg Public Prosecutor's Office, with Europol and Eurojust coordinating, and was announced on 1 October 2026123. Investigators identified a 16-year-old as the group's suspected administrator and main operator; that suspect was arrested in Alicante province, Spain, by the Mossos d'Esquadra and the Guardia Civil14. ThreatPaper does not name the minor.
The same day, the US Attorney's Office for the District of Puerto Rico announced that a grand jury had indicted Fouad Eltibrizi (a/k/a "Archduke"), a Dutch national living in the United Kingdom, on 16 September 2026, and that he was arrested in the UK on 30 September and is pending extradition3. The indictment alleges that from at least March 2025 to November 2025 Eltibrizi and co-conspirators "forming what is known as the Kill Security Ransomware Group" broke into victims' systems through vulnerabilities, stole data to an exfiltration server abroad, published samples on a leak site and demanded ransom, including from a Puerto Rico company whose roughly 180 gigabytes of data, including patient data, were released after it ignored a seven-day countdown3. He is charged, not convicted, and is presumed innocent3.
Investigators describe the group's mechanism as data theft followed by extortion: exploiting software vulnerabilities and poorly secured access points, "particularly to cloud storage", copying data to infrastructure they controlled, naming victims on the leak site, and making files available for free download when a victim did not pay15. Romanian prosecutors add that members also bought access credentials sold on darknet markets and ran command-and-control servers hosted by a global cloud provider6. Vendor tracking before the takedown shows KillSec began as an Anonymous-aligned hacktivist outfit, turned to ransomware in October 2023, and launched a ransomware-as-a-service (RaaS) platform with a Windows locker in June 2024 and an ESXi locker in November 2024789.
The numbers in circulation do not measure the same thing. "Around 1,000" is the count of suspected attacks under investigation; around 500 have so far been identified as successful; the Catalan police put the victims at "more than 280"; the leak site itself carried between roughly 274 and 300 postings depending on who counted14810. The headline framings stretch further: Eurojust's release says KillSec was "responsible for almost 1 000 attacks" under a headline about "Teenagers" arrested, when only one arrestee is described in any primary source as a teenager2. The claim that the group "used AI to build and maintain its ransomware infrastructure" originates in the joint Hamburg police and Europol text and is not explained in any published source15. This paper sets out what each primary source actually says and where they disagree.
Verification of Claims
-
Claim: A 16-year-old is the suspected administrator and main operator of KillSec. → Verified (as the investigators' allegation) → Europol and the Hamburg police state that "the alleged administrator and main operator is 16 years old"15. The Catalan police note says the joint Mossos d'Esquadra and Guardia Civil investigation determined the Alicante suspect's "presumed role as principal administrator" of the group and arrested a 16-year-old there on 30 September4. This is an allegation against a minor, not a finding.
-
Claim: Fouad Eltibrizi led KillSec. → Unverified → No primary source says this. The DOJ release describes Eltibrizi and "co-conspirators" forming KillSec but assigns him no role3. Europol and Hamburg assign leadership to the 16-year-old15. Computer Weekly and Risky Business report that the UK arrest in the operation was Eltibrizi1112; Brit Brief reports, citing the Eastern Region Special Operations Unit (ERSOU), that the person arrested in Levenshulme, Manchester was a 25-year-old suspected of acting as a negotiator13. ERSOU's own statement could not be retrieved, and no primary source states that Eltibrizi is the alleged negotiator.
-
Claim: The operation involved nine countries. → Partially verified → Eurojust says "authorities from nine countries" and lists Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the UK and the US2. Europol and the Hamburg police list ten, adding the Netherlands' Centre for International Legal Assistance in Criminal Matters in Amsterdam15. The DOJ release says the Netherlands "provided valuable assistance leading up to the takedown" and does not list Finland3. Nine is the count of judicial authorities Eurojust coordinated; ten is the count of countries that took part in the investigation.
-
Claim: KillSec carried out about 1,000 attacks, about 500 of them successful. → Partially verified → Europol, the Hamburg police and DOJ all frame 1,000 as "around 1 000 suspected attacks" under investigation, and say around 500 "have so far been identified as successful", a figure that "may change"135. Eurojust drops the qualifier and calls the group "responsible for almost 1 000 attacks"2; the Catalan police and DIICOT say "more than 1,000" and "approximately 1,000"46. Bitdefender notes that the leak-site posting count is a different measure from attacks10.
-
Claim: The group used AI to build and maintain its infrastructure and identify victims. → Unverified (as to how) → The sentence appears in the Hamburg police release ("wie die Gruppe KI nutzte, um ihre Ransomware-Infrastruktur aufzubauen und zu betreiben sowie potenzielle Opfer zu identifizieren") and in Europol's English text15. Neither gives a tool, model, example or method. Eurojust, DOJ, DIICOT and the Catalan police do not mention AI at all2436. Group-IB and Bitdefender repeat it with attribution to Europol rather than from their own research810.
-
Claim: KillSec encrypted victims' systems. → Partially verified → The group advertised file-encrypting lockers: a C++ Windows locker at the June 2024 RaaS launch and an ESXi locker in November 2024, both documented by Rapid7, CYFIRMA and Group-IB from the group's own advertisements and panel789. None of the six law-enforcement releases describes encryption of any victim's systems; all describe data theft and leak-site extortion123456. Group-IB says "Encryption was not a precondition for a KillSec listing" and that a substantial share of claimed victims "involved no network intrusion at all"8.
-
Claim: KillSec has been active since around 2024. → Partially verified → Europol, Hamburg and Group-IB say "since around 2024"158. DIICOT's charging description says the Romanian suspect acted within KillSec from October 20236, matching Rapid7's date for the group's turn from hacktivism to ransomware7. Rapid7 traces the hacktivist persona to at least 20217.
-
Claim: Eltibrizi faces a maximum of 10 years in prison. → Partially verified → The DOJ release states a 10-year maximum3. The court docket shows a single-count indictment, with the pending count recorded as "18:371 CONSPIRACY"1415. The general conspiracy statute, 18 U.S.C. § 371, carries a five-year maximum; a 10-year exposure would be consistent with a conspiracy charged under the Computer Fraud and Abuse Act's own conspiracy provision instead. The indictment text is not publicly available on RECAP, so the discrepancy cannot be resolved from the public record as of 2 October 2026.
-
Claim: The leak site's last victim was posted on 18 September 2026. → Partially verified → Bitdefender Labs and ransomware.live both record 18 September as the last posting1016. Risky Business reported listings "as recently as September 27"12. The difference is unresolved.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2021 | KillSec | Persona active as an Anonymous-aligned hacktivist group conducting DDoS and defacements | 79 |
| October 2023 | KillSec | Pivot to ransomware operations; DIICOT dates the Romanian suspect's participation from this month | 67 |
| March 21, 2024 | ransomware.live | First KillSec leak-site victim discovered by the tracker | 16 |
| June 25, 2024 | KillSec | RaaS platform announced on Telegram: C++ locker, USD 250 entry, 12% commission | 9 |
| October 2024 | Group-IB | Analyses the KillSec 2.0 affiliate panel; locker is Windows-only and builds need administrator approval | 8 |
| November 2024 | KillSec | Announces an ESXi locker that shuts down VMs, deletes snapshots and erases logs | 78 |
| January 2025 | KillSec | Recruits "skilled pentesters", raises its share to 20%, declares hospitals off-limits | 8 |
| Early 2025 | KillSec / Mossos d'Esquadra | Attack on a Catalan organisation causes close to EUR 1 million in damage; Mossos open an investigation; authorities in several countries begin investigating | 14 |
| March 2025 | KillSec | Puerto Rico company listed with samples of patient data and a seven-day countdown; about 180 GB released after no response | 3 |
| March–November 2025 | Eltibrizi and co-conspirators | Charged conspiracy period | 3 |
| December 2025 | DIICOT / Belgium | Joint investigation team agreed under Eurojust; Greece and Germany join later | 6 |
| Late 2025 | KillSec | Focus shifts toward healthcare software and IT service providers | 8 |
| September 16, 2026 | Grand jury, D. Puerto Rico | Single-count indictment returned against Eltibrizi; case sealed; arrest warrant issued | 1415 |
| September 18, 2026 | KillSec | Last leak-site posting recorded by Bitdefender and ransomware.live | 1016 |
| September 30, 2026 | Hamburg LKA and partners | Action day: leak site and five domains seized, 110 TB secured, eight searches, three provisional arrests | 15 |
| September 30, 2026 | Mossos d'Esquadra / Guardia Civil | 16-year-old arrested in Alicante; home and hotel office searched | 4 |
| September 30, 2026 | DIICOT | 24-year-old detained; four searches in Bucharest and Vaslui County | 6 |
| September 30, 2026 | UK police / US District Court | Eltibrizi arrested in the UK; court grants motion to unseal the case | 314 |
| October 1, 2026 | Europol, Eurojust, DOJ, Hamburg police, Mossos, DIICOT | Coordinated announcements; DIICOT asks the Bucharest Tribunal for 30-day pre-trial arrest | 124356 |
| October 1, 2026 | Group-IB, Bitdefender | Private-sector partners publish their accounts of the group | 810 |
Operation Anatomy
How KillSec got in
The investigating authorities describe two routes: exploiting software vulnerabilities, and abusing "poorly secured access points to organisations' systems", "particularly to cloud storage" (T1190, T1530)15. DIICOT adds that members bought access credentials offered for sale on the darknet and used them to log in (T1650, T1078)6. Group-IB's monitoring of affiliate activity lists phishing, brute force against exposed Remote Desktop Protocol services and known vulnerabilities in internet-facing applications, and says a substantial share of claimed victims involved data "taken from cloud storage left publicly accessible through misconfiguration" with no network intrusion at all (T1566, T1110, T1133)8. Halcyon, a vendor, attributes exploitation of the CrushFTP authentication bypass CVE-2025-31161 to the group17; no law-enforcement source names a specific CVE.
Exfiltration and infrastructure
Once inside, members copied sensitive internal data "to infrastructure under their control"1. DOJ says the data went to "an exfiltration server abroad"3. DIICOT says the group built a technical infrastructure for unauthorised access and data transfer and successively configured command-and-control servers "hosted by a global cloud computing provider" (T1583.003)6. The Hamburg police say five relevant servers, "including the main server and several exfiltration servers", were identified and shut down5. The leak site's seized onion address was observed with a seizure banner by BleepingComputer and ransomware.live1618.
Extortion
Victims were named on the leak site with samples of their data and a deadline; DIICOT says victims were also sent samples or links to them as proof (T1657)36. If a victim did not pay, files "could be made available for free download"1. DOJ says non-payment would result in "the full publication or sale of the data"3, and Group-IB and Rapid7 both document a for-sale section with asking prices from USD 5,000 up to USD 350,000 (Rapid7) or USD 500,000 (Group-IB)78. The Catalan police say initial analysis of seized material shows ransom payments, some of around EUR 500,000 in cryptocurrency4.
The RaaS layer
From June 2024 KillSec sold affiliate access to a Tor-based panel with chat, statistics and a builder, initially for USD 250 and 12% of each ransom89. Group-IB says builds required administrator approval, which "pointed to a small core team guarding its payload"8. The advertised lockers encrypted Windows files and, from November 2024, ESXi hosts, with snapshot deletion (T1486, T1490)78. Whether those lockers were deployed against the victims in this case is not established by any primary source (see Verification item 6).
Action day
On 30 September 2026 authorities took over the leak site and five domains, redirected them to a seizure notice, and launched an operation website; the five central servers had been brought under police control over the course of the investigation15. Eurojust ran a coordination centre so measures executed simultaneously; Europol's European Cybercrime Centre traced cryptocurrency and examined digital evidence, and the Joint Cybercrime Action Taskforce handled deconfliction12. Bitdefender and Group-IB supported the investigation1810.
Loading diagram...
Accused
Fouad Eltibrizi (a/k/a "Archduke"), Dutch national residing in the United Kingdom.
- Case: United States v. Eltibrizi, 3:26-cr-00383, US District Court for the District of Puerto Rico, assigned to Judge Gina R. Mendez-Miro; prosecuted by Assistant US Attorney Julian N. Radzinschi31415.
- Charge: A single-count indictment returned 16 September 2026; the docket records the count as "18:371 CONSPIRACY"1415. DOJ describes it as "conspiracy to intentionally access a computer without authorization for financial gain, intentionally causing damage without authorization to a protected computer, and intentionally transmitting a threat to obtain information from a protected computer without authorization with the intent to extort", and states a maximum penalty of 10 years3. On the five-year maximum for § 371, see Verification item 8.
- Procedural status: Arrested in the UK on 30 September 2026; pending extradition; initial appearance before a magistrate judge in Puerto Rico to follow extradition3.
- Presumption of innocence: In DOJ's words, "An indictment is merely an allegation and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law."3
- Attribution and naming basis: Named because charged by indictment and named by DOJ. DOJ does not describe his role within the group3.
Other suspects (not named). The 16-year-old arrested in Alicante province is the alleged administrator and main operator; a woman there is under investigation in connection with the facts4. A suspected developer turned 18 in August 2026 and was a minor during some of the alleged offences; Risky Business reports he was identified in Spain but not arrested112. DIICOT detained a 24-year-old on suspicion of forming an organised criminal group, illegal access to a computer system, unauthorised data transfer, illegal operations with devices or programs, and blackmail, and sought 30 days' pre-trial arrest6; The Register reports he is suspected of acting as an affiliate19. DIICOT states that those investigated benefit from the presumption of innocence6. ThreatPaper does not name any of them.
Group name: KillSec, also Kill Security, KillSecurity and k1llsec38. "KillSec" is the investigators' and the group's own name, used in every primary source. Motivation: Financial; earlier hacktivist persona7. Sophistication: Risky Business calls KillSec "a low-to-mid tier threat actor"12. Group-IB ranked KillSec among the ten most active ransomware groups of 2025 in Asia-Pacific, Latin America and the Middle East8; its RaaS entry fee was USD 2509. Victimology: Group-IB counted 274 organisations claimed on the leak site: about 35% United States and 17% India, with financial services and healthcare most affected8. The Hamburg police say at least 70 of the suspected attacks relate to Germany, 18 of them to Hamburg5.
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org, 2 October 2026):
| ID | Technique |
|---|---|
| T1190 | Exploit Public-Facing Application — exploited software vulnerabilities13 |
| T1530 | Data from Cloud Storage — poorly secured cloud storage18 |
| T1650 | Acquire Access — credentials bought on darknet markets6 |
| T1078 | Valid Accounts — use of those credentials to log in6 |
| T1566 | Phishing — affiliate initial access, per Group-IB8 |
| T1110 | Brute Force — against exposed RDP, per Group-IB8 |
| T1133 | External Remote Services — exposed RDP as an entry point8 |
| T1583.003 | Acquire Infrastructure: Virtual Private Server — C2 servers at a global cloud provider6 |
| T1657 | Financial Theft — extortion and data sale38 |
| T1486 | Data Encrypted for Impact — advertised locker capability; use against these victims not established78 |
| T1490 | Inhibit System Recovery — advertised ESXi locker deletes snapshots8 |
| T1588.007 | Obtain Capabilities: Artificial Intelligence — asserted by investigators without detail1 |
OPSEC: Aliases to conceal identities and encrypted messaging channels for communication26. The Guardia Civil identified the Alicante suspect "starting from an image of a profile", per the Catalan police note4.
Technical Indicators
leak_site_onion_seized:
- ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id[.]onion
leak_site_onion_earlier:
- kill432ltnkqvaqntbalnsgojqqs2wz4lhnamrqjg66tq6fuvcztilyd[.]onion
law_enforcement_operation_site:
- hxxps://www[.]operation-killswitch[.]com
vendor_listed_c2_ips_unconfirmed:
- 82.147.84[.]98
- 77.91.77[.]187
- 93.123.39[.]65
vulnerability_attributed_by_vendor: CVE-2025-31161 (CrushFTP authentication bypass)
file_hashes: none disclosed
note: >
The seized onion address was observed carrying the seizure banner by
BleepingComputer and ransomware.live; the earlier "Kill Security 2.0" onion is
listed by ransomware.live and Halcyon. The three IP addresses and the CVE are
from Halcyon's threat-group profile (updated 13 November 2025), which does not
say which incident each came from; no law-enforcement source has published
network indicators or hashes. Halcyon itself states no locker hashes are
publicly available. Treat the IPs as historical and unconfirmed.Legal and Regulatory Response
Germany. The Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office led the investigation and were responsible for the server investigation; they took over five domains and published the operation website5. Hamburg's interior senator called it the second international operation in a few months in which the Hamburg LKA played a key role5.
United States. United States v. Eltibrizi, 3:26-cr-00383 (D.P.R.): indictment 16 September 2026, sealed the same day, unsealed by order of 30 September 202614. The FBI San Juan Field Office investigated; DOJ's Office of International Affairs and the International Computer Hacking and Intellectual Property prosecutor in The Hague supported3. Extradition from the UK is pending3.
Spain. Investigative Court No. 20 of Barcelona and the Barcelona prosecutor's office direct the Spanish case; the Mossos d'Esquadra and the Guardia Civil's Central Operational Unit ran a joint investigation team that began from the Catalan attack and from an FBI San Juan request for help identifying KillSec members in Spain14.
Romania. DIICOT's central structure detained a 24-year-old on 30 September and asked the Bucharest Tribunal for 30 days' pre-trial arrest on 1 October; a Romania–Belgium joint investigation team was agreed under Eurojust in December 2025, later joined by Greece and Germany6.
United Kingdom. ERSOU took part1. Its own statement could not be retrieved as of 2 October 2026; Brit Brief reports a 25-year-old was due at Westminster Magistrates' Court for an extradition hearing on 1 October13.
Other. Belgium, Finland, Greece, the Netherlands and Switzerland participated; Eurojust hosted the action-day coordination centre and Europol's EC3 and J-CAT coordinated police work12. No regulator has published a notice tied to this operation as of 2 October 2026 that this research located.
Impact Assessment
- Confirmed: At least 110 TB of data secured on the leak site; five central servers under police control; leak site and domains seized; eight searches and three provisional arrests1235. The Catalan police note gives "1.100 terabytes", which every other primary source contradicts4.
- Confirmed (as investigators' count): Around 1,000 suspected attacks under investigation; around 500 identified as successful so far; both may change135.
- Confirmed (as alleged in the indictment): A Puerto Rico company had about 180 GB of data, including patient data, released after a seven-day countdown in March 2025; the indictment also describes breaches in California, Washington State and Louisiana3.
- Reported: More than 280 victims, some of whom paid ransoms of around EUR 500,000 in cryptocurrency (Catalan police)4. At least 70 suspected attacks in Germany, 18 linked to Hamburg (Hamburg police)5. A Catalan organisation suffered close to EUR 1 million in damage4.
- Reported: Leak-site postings counted at 274 (Group-IB), close to 300 with 126 in 2025 and 25 in 2026 (Bitdefender), and 286 (ransomware.live)81016.
- Estimated: Group-IB describes KillSec as "as much a data broker as a ransomware operator", with data asking prices from USD 5,000 to USD 500,0008.
- Unknown: Total ransom revenue; how many victims paid; the AI tooling the investigators refer to; whether any victim in the charged conduct was hit with encryption; Eltibrizi's alleged role; the identity of the 25-year-old reported arrested in Manchester relative to Eltibrizi.
Lessons and Defensive Recommendations
For SOC and cloud teams:
- The dominant way in was not novel: exposed cloud storage, unpatched internet-facing software, and bought credentials168. Inventory every storage bucket and share that is reachable from the internet, including those left from finished projects, acquisitions and tests, which Bitdefender singles out10.
- Treat credential exposure on darknet markets as an intrusion precursor. DIICOT's account of KillSec buying access means a leaked VPN or RDP credential is a live risk until it is rotated6.
- Watch for bulk reads and egress from storage to unfamiliar hosts; KillSec's model needed only copying, not encryption, so ransomware detections tuned to file-encryption behaviour would not fire8.
For platform and virtualisation owners:
- The advertised ESXi locker shut down VMs and deleted snapshots8. Keep offline, immutable backups outside the hypervisor's own snapshot chain.
For healthcare and software providers:
- Group-IB says KillSec shifted in late 2025 to healthcare software and IT service providers, where one compromise exposes many clinics' patient records8. Providers holding data for others should assume they are the target and tell their customers how storage is exposed.
For leadership:
- A takedown does not close the gap that was exploited. Leak-site postings slowed sharply before action day, but the technique is common to many groups10.
- If you were a KillSec victim, contact the national authority listed in the Europol release: investigators are examining the 110 TB and say the evidence may identify further victims1.
For journalists and researchers:
- Distinguish suspected attacks, successful attacks, victims, and leak-site postings. They are four different numbers here: about 1,000, about 500, more than 280, and 274 to 30014810.
- Do not report the leader as the US defendant, or describe the arrestees as "teenagers": only one arrestee is described in a primary source as a minor.
Sources
Footnotes
-
Europol — Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34
-
Eurojust — Teenagers suspected of leading ransomware group arrested during international operation — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
US Attorney's Office, District of Puerto Rico — Dutch National Indicted and Arrested for Unauthorized Computer Access Conspiracy — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30
-
Generalitat de Catalunya, Mossos d'Esquadra — Un detingut a Alacant en una operació internacional contra el grup ransomware KillSec — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17
-
Polizei Hamburg — POL-HH: 261001-3. Teenager steht im Verdacht, KillSec-Ransomware-Gruppe angeführt zu haben — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20
-
DIICOT — Comunicat de presa 2 01.10.2026 — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21
-
Rapid7 — From Ideology to Financial Gain: Exploring the Convergence from Hacktivism to Cybercrime — 3 June 2025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
Group-IB — Group-IB supports international Operation KillSwitch targeting the KillSec ransomware-as-a-service group — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34
-
CYFIRMA — Weekly Intelligence Report, 13 Sep 2024 — 13 September 2024 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Bitdefender — Bitdefender Supported Operation KillSwitch: What the KillSec Takedown Changes for Defenders — 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
Computer Weekly — Teen hacker arrested amid KillSec cyber gang takedown — 1 October 2026 ↩
-
Risky Business News — Risky Bulletin: Authorities dismantle KillSec group, arrest members across Europe — 2 October 2026 ↩ ↩2 ↩3 ↩4
-
Brit Brief — Man, 25, arrested in Manchester over Europe-wide ransomware probe — 1 October 2026 ↩ ↩2
-
CourtListener (RECAP) — United States v. Eltibrizi, 3:26-cr-00383 (D.P.R.), docket entries 1–9 — 16–30 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
CourtListener (RECAP) — United States v. Eltibrizi, parties and pending counts — retrieved 2 October 2026 ↩ ↩2 ↩3 ↩4
-
ransomware.live — killsec group page — retrieved 2 October 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
Halcyon — KillSec threat group profile — updated 13 November 2025 ↩
-
BleepingComputer — Police dismantle KillSec ransomware gang allegedly led by 16-year-old — 1 October 2026 ↩
-
The Register — Teen suspected of running KillSec ransomware group as cops seize servers, arrest three — 2 October 2026 ↩
Related Research
On May 19-20, 2026, Europol and Eurojust's Operation Saffron took down First VPN — a bulletproof service running since 2014 and used by 25+ ransomware groups. Investigators infiltrated it, seized 33+ servers and unmasked ~506 users. The Ukrainian admin was searched and interviewed, not arrested.
Dutch police arrested a 24-year-old Amsterdam man on Sept 15, 2026 in the ShinyHunters investigation; a Rotterdam court remanded him 90 days, and the FBI called him an 'alleged leader.' A separate inquiry into two planned murders abroad is, police say, not part of the ShinyHunters case.
GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.