KillSec takedown: five servers and 110 TB seized, but no release says how victims will be told
On 30 September police in Europe and the US seized KillSec's leak site, five servers and at least 110 terabytes, and arrested three people, one in the UK. The official releases count attacks and servers, but none says how victims will be told.
By Parminder Kumar Sharma · · 18 min read

Five counts of KillSec, and a gap none of them fills
Five counts of KillSec's scale are in circulation after 30 September 2026, and no two of them count the same thing. Europol and the Hamburg police say around 1,000 suspected attacks, of which around 500 have so far been identified as successful. The Spanish Guardia Civil says more than 280 victims. Group-IB, a security vendor that supported the investigation, counted 274 organisations named on the leak site. The community tracker ransomware.live lists 286.
None of those is a count of your organisation, and none of the six official texts I read says how a victim will be told. Europol, Eurojust, the Hamburg police and the Guardia Civil each say the seized evidence may identify further victims. None gives a contact route, mentions a decryptor or decryption keys, or says what happens to files the group had already offered for download. The one place a victim could once check, KillSec's own leak site, now shows a police seizure notice.
That is the finding. The rest of this briefing sets out what the record states and does not, why "dismantled" is a claim about servers rather than about a business, what the dates allow anyone to say about who ran it, what the UK is shown to have done, and an ordered list for a UK organisation. It is time-stamped to the evening of 1 October 2026 (BST), the day every release appeared. Every statement about a person is an allegation. An arrest is not a conviction. The main suspect is a minor, and nobody arrested is named here.
What six official texts state, and what they leave out
Three provisional arrests, eight searches, five servers, five domains and at least 110 terabytes are the hard numbers. The table sets each question against what the texts state and what they do not. Where the texts differ, the difference is shown.
What the six official texts of 1 October 2026 state about KillSec and what they do not (Europol, Eurojust, Hamburg police, Guardia Civil, DIICOT, US Attorney's Office for Puerto Rico; translations mine)
| Question | Stated | Not stated |
|---|---|---|
| Action day | 30 September 2026, led by the Hamburg State Criminal Police Office and Public Prosecutor's Office, with ten countries, Europol and Eurojust. Bitdefender and Group-IB supported. | Whether the leak site was still posting new victims that day, or what Bitdefender contributed. |
| Arrests | Three provisional arrests: a 16-year-old in Spain, a 24-year-old in Romania, one man in the UK. Eight searches in Spain, Greece, Romania and the UK. | What the 24-year-old and the UK man are suspected of doing, the searches per country, or any charge against the 16-year-old. |
| Roles | Suspects in four roles: administrator and main operator (16), developer (turned 18 in August 2026, a minor when some offences were committed), negotiator, affiliate. One more person in Spain is under investigation, not arrested. | Whether the developer, negotiator or affiliate is in custody, or how many affiliates there were. |
| Scale | Around 1,000 suspected attacks. Around 500 identified as successful, a figure that "may change". Germany: at least 70 cases, 18 linked to Hamburg. Spain: more than 280 victims. | A count of organisations by country, apart from Germany. |
| Seized | The leak site and 5 domains, now a seizure notice. 5 central servers, including the main server and exfiltration servers. At least 110 TB "against further unauthorised access". Computers, phones and crypto wallets in Spain. | Whether every copy of the stolen data, or the locker and builder code, was reached. |
| Money | "Substantial" ransom payments in some cases (Europol). A first analysis in Spain found transactions matching ransom payments. Some victims are said to have paid around 500,000 euros in cryptocurrency (Guardia Civil). | The total paid, any amount recovered, or whether the 500,000 euros is per victim or in all. |
| Method | Vulnerabilities and poorly secured access points, especially cloud storage. Credentials bought on the dark web. Samples sent as proof. Threats to publish or sell. AI used to build infrastructure and pick victims. | Which vulnerabilities or products, or what the AI did. |
| Victims | The seized evidence "may help identify further victims". | A contact route, a notification process, a decryptor or decryption keys. |
| Continuing | "Enquiries into other possible members are continuing" (Europol). Further action is "not ruled out" (Guardia Civil). | Whether affiliates are still active, or whether the brand will return under another name. |
| The UK | The Eastern Region Special Operations Unit (ERSOU) is named. At least one UK search. One UK arrest. | Any National Crime Agency role, or a UK victim count. |
Two things in that table are worth a second look. First, the officials disagree on one date: Europol and the Hamburg police say KillSec has been active "since around 2024", Eurojust says "since 2024", and the Romanian prosecutors date a defendant's participation to October 2023. Second, the victim row is empty on purpose. Of the six texts, only the US Attorney's Office gives anyone a place to report: its release encourages "citizens to report any cyber incidents to the FBI through IC3.gov". That is a general appeal, not a notification of KillSec victims.
Five counts, five units
A count is only useful with its unit, and these are not one unit. An attack is not a victim, and a listing is not a payment. The Guardia Civil text comes closest to relating them, because it gives the 500 successful attacks and the more than 280 victims in one sentence. No other official text says how the two figures relate.
The KillSec counts in the record on 1 October 2026 and what each one counts (sources as named; the last three are not official)
| Count | Source | What it counts |
|---|---|---|
| Around 1,000 | Europol, Hamburg police, US Attorney's Office. Eurojust says "almost 1 000". | Suspected attacks worldwide. |
| Around 500 | Europol, Hamburg police | Suspected attacks so far identified as successful. May change. |
| More than 280 | Guardia Civil | Victims, given beside the 500 successful attacks. |
| At least 70, 18 of them Hamburg | Hamburg police | Cases linked to Germany, and to Hamburg. |
| 274 | Group-IB (a vendor that took part) | Organisations publicly claimed as victims on the leak site, from monitoring it and its Telegram channels. |
| 286 | ransomware.live (a community tracker) | Listings its crawler discovered between 21 March 2024 and 18 September 2026. |
| About 450 | SecurityWeek | Victims the leak site listed before the takedown. No source given, and I could not trace one. |
Some arithmetic of my own, labelled as derived. Germany's 70 cases are 7% of the 1,000 suspected attacks, and Hamburg's 18 are 25.7% of the 70, a ceiling for the Hamburg share because 70 is a minimum. The 500 successful attacks are half of the 1,000 suspected. The tracker's list, which I counted by discovery date, shows 128 listings in 2025 and 25 in 2026 up to 18 September, 12 days before the action day. That is a tracker's view of when listings appeared, not of when intrusions happened, so a quiet 2026 on the leak site says nothing certain about intrusions in 2026. On this tracker's data, nobody should read the seizure as the interruption of a campaign in full swing, and nobody should read it as proof the campaign had ended.
One more reason the counts cannot be added. Group-IB says encryption was not a precondition for a KillSec listing, and that the group also sold stolen data outright. Rapid7 reported earlier that some incidents involved stolen data alone. So a count of listings is a count of claims, whatever the group did to the victim's systems.
Who ran it: what the dates allow anyone to say
Europol says investigators "identified a 16-year-old as the group's suspected main operator". Eurojust says a teenager "is suspected of being the group's administrator and main operator". The Guardia Civil describes the arrested minor as one of the administrators in one passage and as the presumed main administrator in another. All of these are statements of suspicion about a role. None says when the 16-year-old joined, what the suspect wrote or approved, or what the suspect is charged with. An arrest is a step in a procedure, not a finding, a distinction the earlier briefing on the Dutch ShinyHunters arrest sets out at more length.
The dates are the part a reader can check. Rapid7 reported in 2025 that KillSec began as a hacktivist group active since at least 2021 and moved to ransomware in October 2023. SOCRadar dated the group's first Telegram message to October 2023. The Romanian prosecutors say a 24-year-old defendant was acting in the group in October 2023. Europol and the Hamburg police say it has been active "since around 2024", Eurojust says "since 2024", and Group-IB says it first identified the group in 2024. By arithmetic from the stated age, a person who was 16 on 30 September 2026 was 13 or 14 in October 2023, and 12 or under throughout 2021. That is derived, and no source states it.
What that does not establish matters as much. It does not show the suspicion is wrong: teenagers do run extortion operations, and the police may hold evidence that is not in a press release. It does not show who started the 2021 brand, or whether the 2021 and 2023 activity was the same people, because a name can be reused. What it does show is that "led by a 16-year-old" compresses a history in which the earliest official date attaches to someone else, and in which no source says when the main suspect took on the role. Group-IB adds that affiliates could not generate builds on demand: each needed approval from the group's administrators, plural, which Group-IB reads as a small core team guarding its payload.
What the arrests and seizures establish and what they do not (Europol, DIICOT and US Attorney's Office, 1 October 2026)
| The record establishes | It does not establish |
|---|---|
| Three people were provisionally arrested on 30 September 2026. | That any of them is guilty. Europol and the Hamburg police call the arrests provisional. |
| A 24-year-old in Romania is under criminal investigation, and on 1 October prosecutors asked a Bucharest court for 30 days of pre-trial arrest (DIICOT). | That the court granted it. The outcome is not in anything I read. |
| A US federal grand jury returned an indictment on 16 September. The man was arrested in the UK on 30 September and is pending extradition. | That the allegations are true. The release itself says an indictment is merely an allegation. |
| Investigators identified a 16-year-old as the suspected main operator. | A charge, a court date or a finding. None is in the record. |
| Police secured at least 110 TB "against further unauthorised access". | That the data is gone from every other machine. |
Dismantled, shut down, taken down: what the words cover
A comforting label is not a control. Some headlines say the gang was dismantled. The records say what was taken, and the two are not the same size. The table sets the words used against what the text behind each one covers.
The words used about the KillSec action and what the record behind each one covers (BleepingComputer, Eurojust, Europol, Hamburg police, Guardia Civil; German and Spanish translations mine)
| Word | Where it appears | What the record behind it covers |
|---|---|---|
| "Dismantled" | BleepingComputer headline | Five servers, five domains and three provisional arrests. Enquiries into other members continue. |
| "Successfully shut down a ransomware group" | Eurojust | Five servers used to store victim data and domains operated by the group. The same release says the investigation continues. |
| "Took control", "brought under police control" | Europol | The leak site, domains and five central servers. A statement about infrastructure, not about people who were not arrested. |
| "A lasting blow" | Head of the Hamburg State Criminal Police Office | An assessment, not a measurement. |
| "An important blow" | Guardia Civil | The same text adds that further action is not ruled out. |
| "Operation KillSwitch" | The operation's own name | A kill switch is one switch. The record shows arrests in three countries, searches in four, seized servers and domains, and a cryptocurrency trace. |
The diagram shows where the action landed. It reached the middle and the end of the chain: the servers that held the copied data, the site that named victims, and the money. In my reading it did not reach the first stage, because the routes in are exposures on the victims' side: cloud storage left open, remote access, unpatched internet-facing software, and credentials bought on the dark web. Those are still there until each owner closes them.
Three further things sit outside what servers can show. Affiliates. Group-IB says some KillSec affiliates also worked with other ransomware programmes, naming LockBit, RansomHub, Qilin and Bashe. The releases identify one affiliate and say enquiries into other possible members continue. An affiliate does not need the brand: the earlier briefing on Storm-2570 tracked one affiliate across four brands, with nine days between two of them. Files already published. Europol says that where a victim did not pay, the stolen files "could be made available for free download". The US Attorney's Office describes one such release: about 180 gigabytes of one victim's stolen data, put on the dark web in 2025. Seizing the leak site does not recall a file someone has already downloaded. The brand's own record. SOCRadar reported in 2024 that KillSec's main Telegram channel had been unavailable since November 2024 while the group stayed active through a backup channel and its website. The brand had already survived the loss of a channel.
Vendors say this more bluntly than the police. Group-IB's chief executive said that servers "can be replaced in weeks" and that identifying the people "is what turns a takedown from a pause into an end". Check Point's Q3 2025 report found that the dissolution of major ransomware programmes "did not reduce the overall volume of attacks" but redistributed it among smaller actors. Halcyon wrote in November 2025 that KillSec had passed 250 documented compromises with "zero law enforcement disruption", which is a useful marker for what changed on 30 September and what did not. Each of these vendors sells security services, and Group-IB took part in the operation, so read the quotations as claims by interested parties. On the narrow point about servers, the police record agrees with them. The practical point about takedowns is the one the EvilTokens briefing made: an enforcement action removes an operator's infrastructure, and everything that protects your own estate is still yours to configure.
The last friendly name is the word ransomware. None of the six official texts says that KillSec encrypted a victim's files. They describe copying data out and threatening to publish or sell it. The US indictment charges, among other things, causing damage to a protected computer, which the release does not elaborate. Vendors describe lockers for Windows and for VMware ESXi hosts, and Group-IB describes an ESXi locker capable of deleting snapshots and erasing logs. For a defender the distinction matters. Restoring from backup answers encryption. It does nothing about a threat to publish.
The UK in the record
The UK is in this record, and I will say plainly what is and is not shown. The only UK authority named in the Europol, Eurojust and Hamburg police lists, and in the US Attorney's Office release, is the Eastern Region Special Operations Unit (ERSOU). The National Crime Agency is not named in any of them. I searched for a separate statement from ERSOU or the NCA and found none by the evening of 1 October. The NCA's own cybercrime page says ransomware remains the greatest cyber serious and organised crime threat to the UK, but it says nothing about this operation.
One arrest was in the UK. The US Attorney's Office says a federal grand jury in Puerto Rico returned an indictment on 16 September, that the man was arrested in the UK on 30 September, 14 days later (derived), and that he is pending extradition. The Hacker News, citing a Europol spokesperson speaking to Reuters, says he is in his 20s. The indictment covers March to November 2025, and the examples the release gives are in Puerto Rico, California, Washington State and Louisiana. No UK victim is mentioned. This briefing does not name him. The police releases do not, and an indictment is an allegation.
What the record states about the UK on 1 October 2026 (Europol, Eurojust, US Attorney's Office; Group-IB and ransomware.live are not police sources)
| Question | Stated | Not stated |
|---|---|---|
| UK authority | ERSOU, named in four official texts. | Any NCA role, or any statement from ERSOU or the NCA. |
| UK searches | The UK is one of four countries with searches, eight in all. | How many were in the UK. |
| UK arrest | One arrest on 30 September. Indictment returned 16 September. Extradition pending. | His role in KillSec, any UK charge, or the extradition timetable. |
| UK victims | No official figure. Group-IB: the UK is around 3% of its 274 listed organisations, about 8 (derived, so 7 to 10). ransomware.live: 11 of 286 (3.8%, derived). | Which organisations, which sectors, or whether any have been told. |
The UK share is small by either count. The risk to a UK organisation may not run through a direct listing. Group-IB says that from late 2025 the group shifted toward healthcare software and IT service providers, "where a single compromise can expose the patient records of every clinic using the platform". If that is right, a UK organisation could hold data that was taken from a supplier, and no listing would carry its name. That is my inference from Group-IB's description, not a finding of any police force.
What a UK organisation should do, in order
Nothing here waits for the police to publish more. The legal points are general guidance, not legal advice. They draw on the NCSC ransomware page, which says the NCSC and UK law enforcement "do not encourage, endorse nor condone" the payment of ransom demands, and on the ICO's breach guide. I also checked the No More Ransom decryptor list on 1 October: it lists tools for other families and none for KillSec or Kill Security.
Take this with you
In the order worth doing
- Find out whether you or a supplier were named. The leak site is now a seizure notice, so ask your threat intelligence provider for its historical records, and get written answers from suppliers. Do not browse the group's sites or download leaked data yourself.
- Ask every supplier that holds your data, especially software and IT service providers, whether KillSec named or contacted them, what was taken, and how fast they would tell you. Group-IB says the group moved toward this kind of provider from late 2025.
- Treat any message that claims to come from the police, Europol or Eurojust about KillSec as unverified until you have rung the agency on a published number. No release describes a notification route, and Eurojust's own site carries a fraud alert about scammers impersonating it.
- Close the entry routes the releases name: cloud storage permissions and anything public by mistake, remote access exposed without multi-factor authentication, unpatched internet-facing applications, and accounts whose credentials appear for sale. Check each against your asset inventory.
- Test recovery as well as backups. Keep offline, immutable copies, and protect virtualisation hosts as critical systems, because Group-IB describes an ESXi locker capable of deleting snapshots and erasing logs. Then accept that backups do not answer a threat to publish, and cut the retention of data you do not need.
- Decide in advance who may declare that you are aware of a breach. If you find evidence that personal data was taken, the ICO says UK GDPR notification is due within 72 hours of becoming aware, with information allowed in phases. Report the incident to the NCSC, and use an NCSC-assured incident response provider.
- Take legal advice before any payment decision, and read the NCSC guidance for organisations considering payment. Seizing a group's servers does not say that copies are gone, so a payment buys no assurance. If someone now contacts you claiming KillSec data, treat it as an unverified claim from a party who may not be KillSec.
The question this leaves
On 1 October the Hamburg police, Europol, Eurojust and the Spanish, Romanian and US authorities told the public what they took: five servers, five domains, 110 terabytes. They did not say who the data belongs to, or who will tell them.
So the question is for your own estate. If KillSec held your data, or a supplier's, the only public list of its victims is now a police seizure notice. How would you find out, how soon, and how would you know the message was real?
Key facts
Sources
- PrimaryPress release of 1 October 2026 on Operation KillSwitch, read in full in a browser: the 16-year-old suspected main operator, three arrests, eight searches, five servers, 110 TB, 1,000 suspected attacks, 500 successful, participating authorities including ERSOUEuropolaccessed 2026-10-01
- PrimaryPress release of 1 October 2026: judicial coordination, the joint investigation team, "almost 1 000 attacks", "shut down a ransomware group", the action day coordination centreEurojustaccessed 2026-10-01
- PrimaryRelease POL-HH 261001-3 of 1 October 2026, in German: the lead investigators, five servers and five domains, the German and Hamburg case counts, the head of the LKA quotedPolizei Hamburg (via Presseportal)accessed 2026-10-01
- PrimaryRelease of 1 October 2026, in Spanish: the arrest in Spain, the more than 280 victims, the 500,000 euro ransom figure, the investigation that began in 2025, further action not ruled outGuardia Civilaccessed 2026-10-01
- PrimaryCommunique of 1 October 2026, in Romanian, read on the prosecutors' own site: the 24-year-old detained, participation from October 2023, bought credentials, the December 2025 joint investigation team, the 30-day pre-trial arrest requestDIICOT (Romania)accessed 2026-10-01
- PrimaryPress release 2026-104 of 1 October 2026: the 16 September indictment, the UK arrest on 30 September, pending extradition, the March to November 2025 conduct; read in a browser, the defendant is not named in this briefingUS Attorney's Office, District of Puerto Ricoaccessed 2026-10-01
- PrimaryThe official Operation KillSwitch page the seized domains point to: a video and a link to the Europol releaseHamburg police and prosecutorsaccessed 2026-10-01
- PrimaryPress release of 1 October 2026 by a vendor that supported the investigation: 274 listed victims, country shares, affiliate terms, ESXi locker, affiliates also working with other programmes; a claim by an interested partyGroup-IBaccessed 2026-10-01
- PrimaryResearch post of 3 June 2025 on hacktivist groups turning to ransomware: KillSec active since at least 2021, ransomware from October 2023, affiliate programme June 2024, ESXi locker November 2024Rapid7accessed 2026-10-01
- PrimaryDark web profile of 7 November 2024: first Telegram message October 2023, $250 entry and 12% share, main Telegram channel unavailable since November 2024SOCRadaraccessed 2026-10-01
- PrimaryThe State of Ransomware, Q3 2025, of 13 November 2025: KillSec among groups listing healthcare victims; the conclusion on disrupted programmes redistributing loadCheck Point Researchaccessed 2026-10-01
- PrimaryThreat actor page for KillSec, updated 13 November 2025: October 2023 emergence, over 250 documented compromises, no law enforcement disruption at that dateHalcyonaccessed 2026-10-01
- PrimaryWhat you need to know about ransomware: the position on paying, incident reporting, assured incident response providersNational Cyber Security Centreaccessed 2026-10-01
- PrimaryCybercrime page: ransomware as the greatest cyber serious and organised crime threat to the UK, and the law enforcement position on paymentNational Crime Agencyaccessed 2026-10-01
- PrimaryPersonal data breaches: a guide: the 72 hour notification duty and phased reportingInformation Commissioner's Officeaccessed 2026-10-01
- PrimaryDecryption tools list, fetched 1 October 2026 and searched for KillSec and Kill Security: no entryNo More Ransomaccessed 2026-10-01
- Reported byCommunity tracker page for KillSec: 286 listings, first discovered 21 March 2024, last 18 September 2026, 11 UK; used for counts, not as an official figureransomware.liveaccessed 2026-10-01
- Reported byNews report of 1 October 2026, read in a real browser after a curl 403: the operation name, the seizure banner quotation, the links to the official releasesBleepingComputeraccessed 2026-10-01
- Reported byNews report of 1 October 2026 that points to the primary sources; the only route to the Europol spokesperson's statements to Reuters, which I could not readThe Hacker Newsaccessed 2026-10-01
- Reported byNews report of 1 October 2026: the unsourced "roughly 450 victims" figure, shown as a disagreement with Group-IB's countSecurityWeekaccessed 2026-10-01


