Teenager Suspected of Running KillSec Ransomware Group as Police Seize Servers in International Crackdown
by Stella Mazonakis · Greek City TimesStay connected to Greek City Times for Free on Google News
Click NOW
A 16-year-old is suspected of being the main operator of the KillSec ransomware group, as an international law enforcement operation targeting the cybercrime network resulted in server seizures, arrests and searches in Greece and several other countries.
Authorities took control of KillSec’s dark web leak site on September 30 as part of Operation KillSwitch, securing at least 110 terabytes of stolen data and preventing the group from continuing to use the platform to threaten victims.
The international investigation, led by German authorities, has identified around 1,000 suspected cyberattacks worldwide, with approximately 500 believed to have been successful.
Three suspects were provisionally arrested and eight properties were searched across Greece, Romania, Spain and the United Kingdom.
The operation also targeted the group’s criminal proceeds, including cryptocurrency believed to have been generated through ransom payments.
Greek authorities involved in the operation
The Hellenic Police took part in the international investigation and coordinated action alongside law enforcement agencies from Belgium, Finland, Germany, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States.
The operation was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office, with support from Europol and Eurojust.
Private cybersecurity companies Bitdefender and Group-IB also assisted investigators.
KillSec targeted vulnerable organisations
KillSec has been active since around 2024 and allegedly gained access to organisations by exploiting software vulnerabilities and poorly secured entry points, particularly cloud storage systems.
After gaining access, the attackers copied sensitive internal data and transferred it to infrastructure controlled by the group.
Victims were then listed on KillSec’s dark web leak site and threatened with the public release of their stolen information unless they paid a ransom.
In cases where victims refused to pay, the group could publish the stolen files for free download.
Investigators say some victims paid substantial sums to prevent their data from being released.
Authorities also uncovered evidence that the group used artificial intelligence to build and maintain parts of its ransomware infrastructure and identify potential victims.
16-year-old allegedly at the centre of the operation
Investigators began examining attacks attributed to KillSec in early 2025 and identified several suspects believed to have performed different roles within the organisation.
These allegedly included an administrator, developer, negotiator and affiliate.
The suspected administrator and main operator is 16 years old.
Another suspected developer turned 18 in August 2026 and was reportedly a minor when some of the alleged offences took place.
Investigators have also identified individuals believed to have acted as a negotiator and affiliate, while enquiries into other potential members of the group remain ongoing.
Police seize servers and control leak site
The coordinated operation targeted both the suspected members of KillSec and the digital infrastructure allegedly used to carry out the attacks.
Authorities carried out eight property searches and seized electronic devices, evidence and assets.
Five central servers were brought under police control during the investigation, including infrastructure allegedly used to coordinate the group’s activities and store stolen information.
Authorities also seized control of domains operated by KillSec.
Visitors to the group’s former leak site were redirected to a law enforcement notice confirming the seizure.
Investigators are now examining the seized devices and data in an effort to identify additional victims, attacks and people involved in the operation.
They are also tracing alleged criminal proceeds, including cryptocurrency transactions.
Europol and Eurojust coordinate international investigation
As the investigation expanded across multiple countries, Europol’s European Cybercrime Centre helped connect national investigators and private-sector cybersecurity specialists.
Europol also supported efforts to trace cryptocurrency and analyse digital evidence.
The Joint Cybercrime Action Taskforce, hosted by Europol, assisted with coordination and liaison between participating authorities.
Eurojust supported the judicial coordination of the investigation, including efforts to identify suspects, locate criminal infrastructure and follow financial trails.
A coordination centre was established to ensure that law enforcement measures could be carried out simultaneously across several countries.
The investigation involved authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States.
The participation of the Hellenic Police highlights the international reach of the investigation and the role of Greece in the coordinated response to major cybercrime networks operating across borders.
Authorities are continuing to analyse the evidence seized during the operation, meaning the number of confirmed attacks, victims and individuals linked to KillSec could increase as the investigation progresses.
Stay updated with the latest news from Greece and around the world on greekcitytimes.com.
Contact our newsroom to share your updates, stories, photos, or videos. Follow GCT on Google News and Apple News.