Yaamlabs
Ransomware

KillSec taken down: what its victims should do now

Police seized KillSec's leak site, five servers and 110 TB of stolen data, and arrested three suspects. How the group got in and what victims should do next.

By Yaali. October 2, 2026, 6 min read, Ransomware, Threat intel.

Cover illustration of a row of dark server racks with one rack locked behind a glowing padlock and a switch pulled to off, with the Yaamlabs logo and the text: Police seize KillSec's leak site and servers, 110 TB of stolen data secured

On September 30, police in ten countries took over the infrastructure of KillSec, a ransomware and data extortion group active since 2024. Europol and Eurojust announced Operation KillSwitch on October 1. Investigators brought five central servers under their control, seized the group's Tor leak site and domains, and secured at least 110 terabytes of data held on them. Three people were provisionally arrested and eight homes were searched in Spain, Greece, Romania and the United Kingdom.

Investigators link KillSec to about 1,000 suspected attacks worldwide, roughly 500 of them successful so far, a figure Europol says may change. If your organisation ever received a KillSec ransom note, appeared on its leak site, or runs internet-facing file transfer servers, cloud storage or RDP (Remote Desktop Protocol), this affects you. Your stolen data is now in police hands rather than on a public site, but copies made before the seizure are outside anyone's control, and not every member is in custody.

Operation KillSwitch in numbers: 5 servers seized, at least 110 TB of data secured, 3 provisional arrests, 8 searches in four countries, about 1,000 suspected attacks of which about 500 were successful, and the suspected roles identified: administrator, developer, negotiator and affiliate

Who was arrested

The investigation was led by police and prosecutors in Hamburg, Germany, and began in early 2025. The FBI's San Juan field office in Puerto Rico led the US side, and Bitdefender and Group-IB supplied technical support.

Spain's Guardia Civil and the Catalan police arrested a 16-year-old Romanian national in Alicante whom Europol describes as the suspected administrator and main operator. Two other suspects, both reported to be in their twenties, were arrested in the UK and in Romania. Investigators have also identified a suspected developer who turned 18 in August 2026, plus a suspected negotiator and a suspected affiliate, and say inquiries into other members continue.

The UK arrest is Fouad Eltibrizi, a Dutch national who allegedly used the name "Archduke". A federal grand jury in the District of Puerto Rico indicted him on September 16 on a charge of conspiracy to commit unauthorized computer access, which carries up to 10 years in prison. Prosecutors allege he made extortion calls on KillSec's behalf. Prosecutors describe a Puerto Rico company that received a seven-day ransom deadline in March 2025 and had about 180 GB of its data published when it did not pay. He awaits extradition to the US.

How KillSec got in

KillSec ran as ransomware as a service (RaaS): the core team rented its tools to affiliates, who carried out the intrusions and shared the ransom. Group-IB reports an entry fee of $250 for the locker, and the group ran a Tor-based panel where affiliates managed victims, negotiations and payloads. Group-IB says the group added a locker for VMware ESXi, the hypervisor that runs many companies' virtual servers, in November 2024.

Europol's summary of the tradecraft is short: the group exploited software vulnerabilities and poorly secured access points, especially cloud storage, copied sensitive data, and threatened to publish it on its leak site. Group-IB lists four entry routes:

  • phishing emails
  • brute-force password guessing against RDP exposed to the internet
  • known vulnerabilities in internet-facing applications
  • cloud storage misconfigured to allow public access

One example: in 2025 KillSec publicly claimed data theft through CVE-2025-31161, an authentication bypass in the CrushFTP file transfer server with a CVSS score of 9.8. A race condition in the S3-compatible AWS4-HMAC login check lets an attacker sign in as an existing user without a password.

Europol also says the group used AI to build and maintain its infrastructure and to choose victims. Financial services and healthcare were the most affected sectors, and Group-IB says KillSec later shifted toward software and IT providers serving hospitals. Organisations in the US made up about 35% of identified victims.

Public counts of leak-site victims differ: Group-IB counted 274, Bitdefender about 300, and SecurityWeek reported about 450 listed before the takedown. All are below the 500 successful attacks investigators cite, so some victims never appeared on the site.

KillSec's four entry routes with a fix and a check for each, and four steps for handling a KillSec extortion email that arrives after the takedown

If you were a KillSec victim

None of the announcements so far describes a victim lookup or a decryption tool. Investigators say they are still analysing the seized devices and data and say this could identify further victims. Do not wait to be contacted:

  1. Report the incident if you have not. In the US, file at ic3.gov and name KillSec, and add the dates, ransom note and any wallet addresses. In Europe, report to your national police cybercrime unit. An open report gives investigators a way to reach you as they work through the 110 TB.
  2. Assume the stolen data is still out there. The seizure stops further access through KillSec's own servers. It does not remove copies downloaded from the leak site before September 30. Your breach notification duties and any credential resets still apply.
  3. Keep your evidence. Ransom notes, negotiation chat logs, emails with full headers and any payment records may now matter to a prosecution.

If an extortion email still arrives

The suspected developer, negotiator and affiliate named by Europol are not all among the three arrested, so threats may still come. They may also come from people who simply reuse the KillSec name.

  1. Do not pay or reply on your own. The leak site is under police control, so the sender would have to publish somewhere else, and any data they hold may have been copied before September 30 anyway.
  2. Ask for proof that matches your environment: file names and paths you can check against your own systems.
  3. Search for the entry routes above in your own logs. On Windows hosts with RDP open, look in the Security log for bursts of failed logons (event ID 4625) followed by a success (event ID 4624, logon type 10) from the same outside address.
  4. Forward the email with its full headers to the agency you reported to.

Close the routes KillSec used

These fixes apply whether or not KillSec ever touched you. Investigators say inquiries into other members continue, and the same routes serve any other group.

  • CrushFTP: run 10.8.4 or later, or 11.3.1 or later. Review the user list for accounts nobody created and check outbound transfers in the period before you patched.
  • RDP: remove it from the internet. Put it behind a VPN or gateway with MFA (multi-factor authentication), and set an account lockout policy so password guessing stops after a few tries.
  • Phishing: require MFA on email as well as remote access, and review recent sign-ins for any user who clicked a phishing link.
  • Cloud storage: turn on S3 Block Public Access at the AWS account level, disable "Allow Blob anonymous access" on Azure storage accounts, and enforce public access prevention on Google Cloud Storage. Bitdefender's advice is to start with buckets and shares nobody owns: leftovers from finished projects, storage inherited in acquisitions, and test environments that became permanent.
  • ESXi: keep management interfaces off user networks and keep at least one backup copy that ESXi admin credentials cannot delete.

All four routes are found by scanning and guessing. The suspected administrator is 16, and Europol says AI helped the group build its infrastructure and pick targets, so assume the next group finds the same exposure just as cheaply and run the same scans against yourself every month.

Our attack surface management work finds exposed services and storage before someone else does, and cloud and Kubernetes security reviews the bucket and account settings above. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: The Record, CyberScoop, Computer Weekly, The Hacker News, SecurityWeek, Security Affairs, BankInfoSecurity, Risky Business News, Group-IB, Bitdefender, Arete on CrushFTP, NVD CVE-2025-31161.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.