Three suspects were provisionally arrested, eight searches took place in four countries, including Romania, and the authorities seized the site used by KillSec to publish stolen data. The international investigation concerns approximately 1,000 suspected attacks, of which around 500 have so far been identified as successful, and has secured at least 110 TB of data.
Authorities from ten countries, including Romania, participated in Operation KillSwitch against the infrastructure associated with the KillSec cyber group, which is being investigated for approximately 1,000 suspected attacks worldwide. On September 30, the authorities took control of the site used to publish stolen data, secured at least 110 TB of information, and carried out eight searches in Greece, Romania, Spain, and the United Kingdom. Three suspects were provisionally arrested.
In brief
Operation KillSwitch is investigating approximately 1,000 suspected attacks attributed to KillSec, of which around 500 have so far been identified by investigators as successful.
Three suspects were provisionally arrested, and eight searches took place in Greece, Romania, Spain, and the United Kingdom.
The authorities secured at least 110 TB of stolen data, seized the KillSec domains, and, during the investigation, five central servers used by the group.
The alleged administrator and main operator is 16 years old, while a suspect considered to be a developer turned 18 in August and was a minor at the time of some of the investigated acts.
Romania was also part of the joint investigation team established together with Belgium, Germany, and Greece, through the DIICOT Central Structure and the Directorate for Combating Organized Crime of the Romanian Police.KillSec is being investigated for attacks carried out approximately since 2024 against organizations whose internal data was allegedly copied and transferred to infrastructure controlled by the group. The victims were subsequently threatened with the publication of the information if they did not pay a ransom, according to Europol and Eurojust.
If payment was not made, the data could be published for download on the site operated by the group. To prove to victims that they possessed the information, KillSec members allegedly sent samples of the stolen files in some cases.
The international operation culminated on September 30 with the seizure of the site the group used for these threats. Visitors to the domains previously controlled by KillSec were redirected to a message from the authorities.
Europol states that at least 110 TB of data were secured against subsequent unauthorized access. The volume does not represent the amount of data stolen in a single attack, nor the final total number of compromised information in all the cases under investigation.
During the investigation, the authorities also seized five central servers associated with KillSec. They were used to administer the group's activities and to store data obtained from victims.
The five servers were not all confiscated during the action on September 30. Europol and Eurojust statements specify that they were seized during the investigation, while the coordinated operation additionally targeted residences, devices, assets, and online infrastructure.
The current assessment of the investigation also distinguishes between suspected attacks and those confirmed so far by investigators. The operation concerns approximately 1,000 suspected attacks worldwide, but Europol says that around 500 have so far been identified as successful.
This figure may change as the confiscated devices and information are analyzed. The authorities hope that the recovered data will allow them to identify additional victims, attacks that had not yet been associated with the group, and other people who may be involved.
The investigation is led by the Landeskriminalamt Hamburg and the Hamburg Public Prosecutor's Office. Europol lists the participation of authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States.
Eurojust coordinated judicial authorities from nine countries and organized a coordination center for the simultaneous implementation of the measures. The difference between the two lists stems from the operational and judicial roles described by the two agencies and does not in itself indicate a contradiction between the statements.
Romania had a direct role in judicial cooperation. Eurojust mentions that a joint investigation team was established between Belgium, Germany, Greece, and Romania.
For the Romanian side, the Eurojust statement identifies the Directorate for the Investigation of Organized Crime and Terrorism Offenses, Central Structure, and the Directorate for Combating Organized Crime of the Romanian Police.
Romania is also among the four states where searches were carried out as part of the coordinated action, alongside Greece, Spain, and the United Kingdom. However, the sources consulted do not specify how many of the eight searches took place in Romania, nor whether any of the three provisional arrests was carried out on Romanian territory.
The documents also do not indicate the suspects' nationality. This information should not be inferred from the countries where the searches took place or from the authorities involved.
An unusual element of the investigation is the age of some people suspected of having important roles in the group. According to the authorities, the alleged administrator and main operator of KillSec is 16 years old.
Another suspect, described as a developer, turned 18 in August 2026 and was a minor during the period when some of the investigated acts were allegedly committed. Investigators also identified people suspected of having served as a negotiator and an affiliate.
The identities of the minors are not published in the documents consulted, and the description of the roles represents the investigators' allegations and assessments. The persons concerned are suspects and benefit from the presumption of innocence.
Europol describes KillSec's method as being based mainly on exploiting vulnerabilities and insufficiently protected access points, including in cloud storage systems. Once access was obtained, the internal data was allegedly copied to infrastructure controlled by the group.
The Europol statement also says that investigators identified the use of artificial intelligence to build and maintain the ransomware infrastructure and to identify potential victims. The source does not provide sufficient technical details to establish which artificial intelligence systems were used or what proportion of KillSec's operations depended on them.
Therefore, the use of AI is an element of the investigation, but it does not justify the claim that the attacks were carried out automatically or that artificial intelligence was the group's main tool.
In addition to the infrastructure, investigators are also tracing the income allegedly obtained from ransoms. Europol provided specialized assistance in tracing cryptocurrencies and analyzing digital evidence, and the investigation into the financial flows is ongoing.
The agency also worked with the cybersecurity companies Bitdefender and Group-IB, which provided support for the investigation. The Joint Cybercrime Action Taskforce hosted by Europol contributed to coordination and information sharing among the authorities.
The operation on September 30 does not close the investigation. The confiscated devices, data, and financial information are still being analyzed, and the authorities say that the evidence may lead to the identification of new victims, attacks, and suspects.
Latest News
21:25
21:08
20:36
20:17
19:57
See more news