Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

Operation KillSwitch Dismantles KillSec Ransomware RaaS

International law enforcement seized KillSec's leak site, arrested three, and identified an alleged 16-year-old as the ransomware gang's leader.

Operation KillSwitch Dismantles KillSec Ransomware RaaS
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

International law enforcement seized KillSec’s data leak site and servers, arrested three people, and identified a 16-year-old in Spain as the alleged operator of the ransomware-as-a-service operation. Confirmed across BleepingComputer, The Record, SecurityWeek, and Dark Reading.

What’s confirmed

Operation KillSwitch: multi-country law enforcement action, led by Spanish authorities with international coordination.

Three arrests total. One suspect: a 16-year-old alleged to have run or controlled the KillSec operation. Spanish police confirmed this arrest.

KillSec’s data leak site taken offline and seized. Servers seized. SecurityWeek reports authorities secured at least 110 terabytes of data stolen from KillSec victims.

Operational timeline: KillSec has been active roughly two years, with approximately 500 claimed victims worldwide per reporting from multiple outlets.

What’s unconfirmed

Analysis: The group operated as a RaaS, meaning the full affiliate count and infrastructure scope remain unknown pending further law enforcement disclosure. Whether the three arrests represent the full leadership or affiliates only is not confirmed in current reporting.

Analysis: The age of the alleged leader may not fully map to operational complexity. RaaS platforms lower the barrier for participants of any age, but the extent of this individual’s actual development/operational role versus front-facing RaaS coordination is not yet established by public evidence.

Victim scope

KillSec claimed data from organizations across sectors. Specific victim identities remain unconfirmed pending law enforcement notification procedures.

Context

Enforcement actions against ransomware groups have accelerated. Spanish authorities arrested a member of the ShinyHunters data extortion group in September, with the FBI issuing a separate warning to remaining members the same week. See FBI Warns ShinyHunters Members to Surrender After Arrest. Earlier in September, a Ryuk member was sentenced to two years for $1.2M in attacks. Clop relocated its leak site following the Grav CMS compromise confirmation the week prior.

Law enforcement seizure of leak infrastructure is the operational disruption: it cuts the group’s extortion leverage, at least temporarily. Reemergence under a different name remains possible and not tracked in confirmed reporting at this time.

Found this useful? Share it.