Bleepingcomputer Police Dismantle KillSec Ransomware Gang Led by Teenager
Article Content
- •KillSec ransomware gang dismantled in international operation.
- •16-year-old identified as the main operator; three arrests made.
- •Authorities seized 110TB of stolen data and took control of key servers.
On October 1, 2026, law enforcement agencies, including Europol, announced the dismantling of the KillSec ransomware group, allegedly led by a 16-year-old. The operation, named 'Operation KillSwitch', resulted in three provisional arrests and the seizure of at least 110 terabytes of stolen data. The group is linked to approximately 1,000 suspected attacks globally, with around 500 confirmed successful breaches. KillSec exploited software vulnerabilities and poorly secured systems to infiltrate organizations, particularly targeting cloud storage. Investigators have identified a developer who recently turned 18, as well as a negotiator and an affiliate. The group's dark web leak site has been taken over by authorities, and its domains now display a seizure notice. The investigation began in 2025, and authorities continue to analyze seized data to trace criminal proceeds and identify additional victims.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track KillSec in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What organizations were affected?
What should organizations do now?
Is the threat from KillSec eliminated?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…