Teenagers suspected of leading KillSec ransom group arrested during international operation
An international operation arrested three suspects, including teenagers, accused of leading the KillSec ransomware group.
Eurojust and Europol coordinated authorities from nine countries in an operation that disrupted the KillSec ransomware group, blamed for almost 1,000 attacks worldwide since 2024. Investigators say a 16-year-old was the main operator and that another suspect, a developer who recently turned 18, was a minor during some alleged offenses. KillSec accessed poorly secured systems, particularly cloud storage, stole data, and extorted victims by threatening publication. The action day produced three arrests, eight house searches, seizure of five servers and KillSec domains, and recovery of at least 110 terabytes of stolen data.
- KillSec is linked to nearly 1,000 data-theft extortion attacks since 2024.
- A 16-year-old is suspected of being the group's main operator.
- Eight searches were conducted in Spain, Greece, the UK, and Romania.
- Authorities seized five servers, KillSec domains, and at least 110TB of data.
Full article605 words · extracted from databreaches.net · click to collapse
DataBreaches has reported on a group known as KillSec for almost two years. This time, we get to report on their arrest.
The European Union Agency for Criminal Justice Cooperation issued this press release today:
An international group of authorities from nine countries, coordinated by Eurojust and Europol, has successfully shut down a ransomware group responsible for almost 1 000 attacks worldwide. During the investigation, a 16-year-old was identified as the group’s main operator. The group, known as KillSec, stole sensitive data and threatened to publish the files unless a ransom was paid.
KillSec has been around since 2024. By exploiting poorly secured access points, particularly those linked to cloud storage, the group was able to gain access to organisations’ systems. Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen data public unless the victims paid a ransom. If the victims did not pay, the stolen files were made available for free download. To prove that they possessed the stolen data, victims would get sent samples. In some cases, the group received substantial ransom payments.
Authorities have identified other suspects in different roles, including administrator, developer, negotiator and affiliate. A teenager is suspected of being the group’s administrator and main operator. Other suspects include a developer who recently turned 18 and was a minor when a number of the alleged offences were committed. The group made itself known online by using aliases concealing their true identities. To communicate they used encrypted messaging services.
Eurojust coordinated judicial authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom and the United States. A joint investigation team was set up at Eurojust between authorities from Belgium, Germany, Greece and Romania. All nine authorities worked together to identify suspects, locate the group’s infrastructure and follow financial trails. The authorities came together at Eurojust to plan an international action day involving the identification of suspects and the seizure of evidence and assets. The action day was run from a coordination centre set up at Eurojust.
Europol produced reports on the group’s activities, connected investigators with private-sector partners and provided specialist support to trace cryptocurrency and examine digital evidence.
The action day resulted in the arrests of three suspects and the seizure of evidence and assets. Eight house searches were carried out in Spain, Greece, the United Kingdom and Romania. They were able to secure at least 110 terabytes of stolen data. During the investigation, authorities seized five servers used by the group to store data from its victims. Authorities also seized domains operated by KillSec.
The actions were carried out by the following authorities:
- Belgium: Public Prosecutor’s Office Brussels; Federal Computer Crime Unit
- Finland: National Bureau of Investigation
- Germany: Public Prosecutor’s Office Hamburg; Federal Criminal Police Office; Hamburg State Criminal Police Office
- Greece: Judicial authorities; Hellenic Police
- Romania: Prosecution Office attached to the High Court of Cassation and Justice, Directorate for Investigation of Organised Crime and Terrorism – Central Office; Romanian Police – Directorate for Combating Organised Crime
- Spain: Investigative Court number 20 of Barcelona; Public Prosecutor’s Office Barcelona; Mossos d’Esquadra; Guardia Civil
- Switzerland: Office of the Attorney General of Switzerland (OAG); Federal Office of Police fedpol
- United Kingdom: Eastern Region Special Operations Unit (ERSOU)
- United States: United States Attorney’s Office for the District of Puerto Rico; Federal Bureau of Investigation, San Juan Field Office
The press release confirms what DataBreaches reported in 2024: that KillSec attempted to extort victims after finding unsecured public data.
For other previous coverage on DataBreaches.net, see the Related posts below.