Authorities Dismantled KillSec Ransomware Group
An international operation spanning nine countries seized infrastructure and data linked to the criminal collective.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Should law enforcement prioritize international cooperation to combat rising digital ransomware threats?
Law enforcement agencies across nine countries have arrested three suspects associated with the KillSec ransomware group. The operation resulted in the seizure of five servers and 110 terabytes of stolen data.
Why it matters
This takedown targets the operational infrastructure of a group that since 2024 has used cloud storage vulnerabilities to extort victims. The coordinated effort highlights the current scale of international cooperation required to disrupt distributed cybercrime operations.
Authorities conducted eight house searches across Spain, Greece, the United Kingdom, and Romania to secure the 110 terabytes of data. This recovery follows the seizure of five servers that hosted the group's stolen information and infrastructure.
The players
KillSec
A ransomware collective that operated since 2024, specializing in data extortion by exploiting misconfigured cloud storage.
Eurojust
An agency of the European Union that coordinates judicial and prosecutorial cooperation among member states to combat cross-border serious organized crime.
The details
The KillSec group gained unauthorized access to victim systems by targeting and exploiting poorly secured cloud storage access points. Once inside, the operators would exfiltrate sensitive files and extort organizations by threatening to release that data publicly. Authorities neutralized these capabilities by seizing the domains the group utilized to manage their operations and store the stolen assets.
Timeline
The KillSec ransomware group began operations in 2024.
Authorities conducted the international action day on October 1, 2026.
The Tech Race
This disruption follows a pattern of increasing international cooperation facilitated by institutions like Eurojust to counter decentralized ransomware groups. The operation demonstrates the effectiveness of cross-border intelligence sharing in disabling groups that rely on disparate global infrastructure.
Organizations should review their cloud storage access configurations to ensure they are not exposing data points, as these vulnerabilities served as the primary entry vector for this group. Further developments will depend on the findings from the ongoing forensic examination of the seized devices.
The takeaway
The takedown underscores the critical need for robust cloud security hygiene to prevent simple access point exploits. Investigators are now tracing financial proceeds and examining seized hardware, which may reveal additional members or previous criminal targets.
Further reading
For more on the current state of global cyber threats, visit our Cybersecurity section.
Live Poll
Should law enforcement prioritize international cooperation to combat rising digital ransomware threats?







