Breaking
Cyber CrimeDeveloping Story

Teen ran KillSec ransomware, cops say

A 16-year-old led a ransomware crew that claimed about 1,000 attacks, according to European police.

··3 hours ago·5 min read
MacBook Pro turned-on
Photo by Michael Geiger on Unsplash

A ransomware operation that racked up roughly a thousand claimed intrusions was not the work of a hardened syndicate, according to European police — it was run by a 16-year-old. The takedown, dubbed Operation KillSwitch, left the group's servers in law enforcement hands and its leader publicly anonymous because of his age.

The identity of the ringleader has not been released, with police citing his status as a minor. A second key figure, the group's main developer, recently turned 18, though Europol says many of his alleged crimes were committed while he was still underage.

How the takedown unfolded

Law enforcement launched Operation KillSwitch on September 30, according to Europol. German authorities led the effort, with support from Europol and Eurojust and involvement from agencies in Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States.

Private-sector security firms also took part. Group-IB contributed intelligence on the group's activity, having described KillSec as one of the most active ransomware operations of 2025 across Asia-Pacific, Latin America, and the Middle East. The company's analysts had already mapped out at least 274 victim organizations.

The operation resulted in three apparent arrests, though Europol's language leaves room for interpretation about who exactly was detained. Based on the agency's account, the teenage ringleader does not appear to be among them. Police also carried out eight house searches across Spain, Greece, Romania, and the United Kingdom.

What police seized from KillSec

The material haul from the operation was substantial. Investigators confiscated 110 terabytes of data, five central servers, and the infrastructure the group used to run its operations and hold stolen files. Multiple domains linked to KillSec were taken over and now display the standard seizure notice.

Authorities also seized the group's criminal proceeds, described as cryptocurrency extorted from victim organizations.

"KillSec's affiliates went after the organizations people depend on most: hospitals, government bodies, and financial institutions. Closing the gaps these groups exploit is essential, but it does not end an operation like this. Servers can be replaced in weeks; the people who build the platform and approve every attack cannot. Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end. We are proud to have contributed to Operation KillSwitch, and will continue to support Europol and our law enforcement partners in the fight against cybercrime."

— Dmitry Volkov, CEO of Group-IB

A short but busy criminal run

KillSec surfaced as a threat actor at some point in 2024, Europol said. Over the next two years, it carried out roughly 1,000 attacks worldwide, at least half of which were most likely successful.

Its typical target was a small-to-midsize organization, often in professional services, technology, healthcare, or financial services. The group looked for organizations holding valuable or sensitive data, and those with potentially weak internet and cloud infrastructure. Larger enterprises and government bodies also appeared in its victim list, but company size doesn't seem to have been the deciding factor in who got hit.

Group-IB's data on the 274 identified victims shows a heavy United States concentration: 35% of them. India came next at 17%, followed by Brazil, the UK, Australia, and Colombia at 3% each. Financial services and healthcare formed the backbone of the target list, with government organizations and large enterprises also in the mix. Among the victims Group-IB points to are a major insurer, investment firms, and a consumer app with millions of users.

From Windows to virtual machines

KillSec's first focus was the Windows platform. That changed in late 2024, when the group released its KillSec 2.0 affiliate platform, which expanded into VMware ESXi virtualization hosts. That capability allowed affiliates to shut down virtual machines, delete snapshots, erase logs, and take other destructive actions.

By January 2025, the group was openly recruiting what it called "skilled pentesters," requiring either a forum reputation or a USD 1,000 deposit to join. It demanded 20% of each ransom from its affiliates.

The four-person core

Investigators began looking into KillSec in 2025, Europol said, and quickly concluded the group consisted of at least four people: the ringleader, the developer, the negotiator, and an affiliate. That assessment may understate the group's true size — the investigation is still ongoing.

The structure is a familiar one in the ransomware economy, where a small core builds and maintains the tooling while affiliates carry out the actual intrusions and split the proceeds. What's unusual here is the age of the people at the center of it.

Scale of the operation

The numbers behind KillSec and its dismantling, as reported by Europol:

  • Approximately 1,000 attacks claimed worldwide, at least half likely successful
  • 274 victim organizations identified by Group-IB
  • 35% of those victims based in the United States
  • 110 terabytes of data seized
  • Five central servers confiscated
  • Eight house searches conducted across four countries
  • USD 1,000 deposit required of would-be affiliates
  • 20% of each ransom demanded from affiliates

Where the victims were concentrated

The geographic spread of KillSec's victims reflects a group that cast a wide net but found the richest hunting in the United States. Beyond the 35% US share, India accounted for 17% of identified victims, with Brazil, the UK, Australia, and Colombia each at 3%.

Sector-wise, the pattern is consistent with what Europol describes: financial services and healthcare at the core, government organizations and large enterprises on the periphery. The victims Group-IB names — a major insurer, investment firms, and a consumer app with millions of users — fit the profile of organizations holding data that carries real value on a leak site.

What the seizure actually changes

Taking down the infrastructure is one thing; taking down the people behind it is another. The Group-IB CEO's statement makes the distinction explicit: servers can be replaced in weeks, but the individuals who build the platform and approve each attack cannot.

That framing matters for how this operation should be read. The domains are seized, the servers are in police custody, and the cryptocurrency is gone. But the investigation is ongoing, and Europol's account of the arrests is not entirely clear about who was detained. The group's most senior figure remains unidentified publicly.

For organizations that fall into KillSec's target profile — small-to-midsize firms in professional services, technology, healthcare, or financial services, particularly those with internet-facing systems — the practical lesson is the one the Group-IB statement points to: the gaps these groups exploit are what let them in. A takedown of one crew doesn't close those gaps.

#ransomware#killsec#europol#cybercrime#teenager#operation-killswitch

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories