Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
AI Summary
KillSec, a ransomware group active since at least 2021, transitioned to ransomware operations in October 2023 and began offering its tools as a ransomware-as-a-service in June 2024. The group extorted victims by stealing sensitive data, threatening to publish it unless ransoms were paid, and leveraging AI for infrastructure and victim identification. In September 2026, law enforcement in Spain, Germany, the UK, Romania, and Puerto Rico arrested three suspects, including a 16-year-old suspected administrator, and seized the group's leak site, servers, domains, and over 110 TB of data. The investigation uncovered approximately 500 confirmed successful attacks out of around 1,000 suspected incidents globally, with evidence of ransom payments in cryptocurrency.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | killsec[.]onion | Details → |