KillSec mainly used double extortion, encrypting as well as stealing data
Assessment
Rapid7 wrote in June 2025 that although KillSec sometimes extorted with stolen data alone, it "appears to adopt mainly double extortion tactics, exfiltrating data in addition to encrypting it". The group did advertise lockers (a C++ Windows locker in June 2024 and an ESXi locker in November 2024, per Rapid7, CYFIRMA and Group-IB). But none of the six law-enforcement releases describes encryption of any victim's systems; all describe data copied from poorly secured systems and cloud storage, then leak-site extortion. Group-IB says "Encryption was not a precondition for a KillSec listing" and that a substantial share of claimed victims involved no network intrusion. Encryption capability is established; encryption as the main method is not.
Where this claim appeared
Rapid7 · 2025-06-03
https://www.rapid7.com/blog/post/2025/06/03/from-ideology-to-financial-gain-exploring-the-convergence-from-hacktivism-to-cybercrime/What “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Operation KillSwitch: KillSec ransomware takedown, a 16-year-old suspect and a US indictmentThink this assessment is wrong? Report an error.