ThreatPaper
Weak Evidence

KillSec victimized roughly 500 organizations

Assessment

CyberScoop's 1 October 2026 report says the group "victimized roughly 500 organizations in less than two years". The investigators' figure is narrower and provisional: Europol, the Hamburg police and the US Justice Department say that of around 1,000 suspected attacks, around 500 "have so far been identified as successful", and that the figure may change as seized evidence is examined. A successful attack is not necessarily a distinct organisation, and no investigator has published a count of victim organisations. The leak site itself listed only about 274 to 300 victims, depending on who counted.

Where this claim appeared

CyberScoop · 2026-10-01

https://cyberscoop.com/killsec-ransomware-group-arrests-operation-killswitch/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Operation KillSwitch: KillSec ransomware takedown, a 16-year-old suspect and a US indictment

Think this assessment is wrong? Report an error.