International Operation Targeted KillSec Ransomware Group
Law enforcement arrested three individuals to disrupt a criminal network linked to 1,000 global attacks.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust that international police efforts are successfully reducing the threat of global ransomware attacks?
Police conducted a coordinated international operation across nine countries to dismantle the KillSec ransomware infrastructure. The initiative resulted in three arrests, including a 25-year-old man in Manchester suspected of acting as a criminal negotiator.
Why it matters
This operation aims to disrupt the negotiation and extortion infrastructure used by cybercriminals to target companies. It follows an investigation into approximately 1,000 ransomware attacks observed worldwide.
The coordinated raids targeted eight properties across Greece, Romania, Spain, and the UK. Authorities seized assets and evidence connected to the KillSec leak site, which has been active since approximately 2024.
The players
ERSOU
The Eastern Region Special Operations Unit specializes in organized crime and counter-terrorism investigations.
Joint International Crime Centre
A collaborative agency focused on coordinating multi-jurisdictional law enforcement efforts against complex criminal activity.
The details
Operation KillSwitch, a joint effort between ERSOU, the North West Regional Organised Crime Unit, and the Joint International Crime Centre, targeted the digital infrastructure used by ransomware actors. Investigators focused on the KillSec site, a dark web platform used to host stolen data and facilitate ransom negotiations between criminals and victim organizations. The suspect arrested in Levenshulme allegedly operated as a professional negotiator, managing communication between the criminal group and its targets.
Timeline
The KillSec site began operations around 2024.
Coordinated arrests occurred across Europe on September 30, 2026.
An extradition hearing for the Manchester suspect is scheduled for October 1, 2026.
The Tech Race
The operation marks an escalation in global efforts to neutralize the dark web leak sites that underpin the ransomware-as-a-service model. This strategy tracks closely with recent trends identified in the European Union Agency for Cybersecurity Threat Landscape reports regarding the infrastructure behind digital extortion.
This disruption primarily affects organizations targeted by the KillSec group, which previously facilitated extortion against at least 28 UK companies. The removal of this platform limits the ability of the associated criminal network to publish stolen data or conduct negotiations.
The takeaway
Authorities are increasingly shifting focus from individual malware variants to the human negotiators and hosting infrastructure that sustain criminal operations. Stakeholders should track future indictments and evidence disclosures to see how these arrests impact the broader ransomware ecosystem.
What happens next
The suspect in custody faces an extradition hearing at Westminster Magistrates' Court on October 1, 2026.
Further reading
For more on evolving threats, explore the latest trends in Cybersecurity.
Source note: This article includes information reported by Manchester Evening News.
Live Poll
Do you trust that international police efforts are successfully reducing the threat of global ransomware attacks?







