ThreatPaper
Weak Evidence

KillSec was responsible for almost 1,000 attacks worldwide

Assessment

Eurojust's release states the group was "responsible for almost 1 000 attacks worldwide". Europol, the Hamburg police who led the case, and the US Attorney's Office all frame the same figure as "around 1 000 suspected attacks" under investigation, of which around 500 "have so far been identified as successful", and say both figures may change as seized evidence is examined. The Catalan police put the victims at "more than 280", and leak-site postings were counted at 274 (Group-IB), 286 (ransomware.live) and close to 300 (Bitdefender). The 1,000 is an investigative caseload of suspected attacks, not a count of attacks the group is established to have carried out.

Where this claim appeared

Eurojust · 2026-10-01

https://www.eurojust.europa.eu/news/teenagers-suspected-leading-ransomware-group-arrested-during-international-operation

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Operation KillSwitch: KillSec ransomware takedown, a 16-year-old suspect and a US indictment

Think this assessment is wrong? Report an error.