← All posts

Security

Police Seized 110 Terabytes From KillSec. The Alleged Administrator Is 16 and the Way In Was Cloud Storage

Eurojust and Europol announced on October 1 that a nine-country operation dismantled the KillSec ransomware-as-a-service group, seizing five servers, its leak site and more than 110 terabytes of stolen data. The suspected administrator is 16, and roughly 500 successful attacks involved no novel exploit at all.

MAI
The Operation Killswitch banner from the law-enforcement takedown notice published by Hamburg police and the Hamburg public prosecutor's office, alongside the partner agency logos.

Eurojust and Europol announced on October 1 that an operation spanning nine countries has dismantled KillSec, a ransomware-as-a-service group behind roughly a thousand attempted intrusions since 2024. Police seized five servers, took over the group's dark-web leak site and five of its domains, and recovered at least 110 terabytes of stolen data. Three people were arrested the day before. The suspected administrator and main operator is 16 years old.

The takedown is the headline. The detail underneath it is the useful part: an operation that reached several hundred organisations across healthcare, government and financial services got in largely through weakly protected cloud storage, and was allegedly run by people too young to hold a driving licence.

What was seized

ItemFigure
Countries involved9, plus Europol's EC3 and Eurojust
Lead authorityPublic Prosecutor's Office Hamburg, with Hamburg police and Germany's BKA
Arrests3 — Spain, United Kingdom, Romania
House searches8 — Spain, Greece, United Kingdom, Romania
Servers seized5, including the group's main server
Domains seized5, now serving police notices
Stolen data recovered110+ TB
Suspected attacks~1,000, of which about 500 confirmed successful so far
Victims listed on the leak site~450

Bitdefender and Group-IB supported the investigation. The FBI's San Juan field office and the US Attorney's Office for the District of Puerto Rico took part, and the suspect arrested in the United Kingdom — a person in their twenties — faces an extradition request from Puerto Rico. Romania's DIICOT detained a 24-year-old. The 16-year-old was arrested in Alicante, Spain; The Record reports he is a Romanian national. A fourth suspect, the alleged developer, who turned 18 in August, was identified but not arrested and is alleged to have committed the offences while a minor. Eurojust describes the roles as administrator, developer, negotiator and affiliate — a staffing chart, for four people.

A thousand attacks and no zero-day

This blog has spent the past fortnight on the opposite kind of story: a zero-day in F5's BIG-IP, mass exploitation of Citrix NetScaler, a zero-day in a security appliance that cost Bitget $387.5 million. Those are expensive capabilities used against hard targets. KillSec is the other half of the market, and the larger half by volume.

According to the authorities, the group's method was to find software flaws and weakly protected entry points — cloud storage above all — copy the data out, and threaten to publish it. There is no indication of a novel exploit anywhere in the 500 successful attacks. The group did not need one. It needed an object store with permissions nobody had reviewed, repeated several hundred times across sectors that hold the most sensitive data there is.

That matters for how defenders spend. The organisations on KillSec's leak site were not beaten by an adversary with better tooling. They were beaten by a configuration they could have audited themselves, by a group that, on Rapid7's account, began as a hacktivist crew around 2021, moved into ransomware in October 2023 and only opened its affiliate platform in June 2024. Two years from defacements to several hundred victims is not a story about sophistication. It is a story about how little sophistication the target surface currently demands.

The age of the suspects is the policy problem

A 16-year-old administrator is not a curiosity. It is the central difficulty for anyone who hoped prosecution would deter this.

Juvenile justice systems in Spain, Romania and Germany are built around rehabilitation and short custodial limits. The alleged developer's position is sharper still: he is 18 now, but the offences are alleged to date from when he was not, which generally governs how he is tried. Whatever the seized servers show, the sentences available at the end of this are not the ones available for an adult ransomware operator.

Which means the value of Operation KillSwitch lies in the disruption rather than the punishment: five servers off the network, the leak site under police control, cryptocurrency wallets traced, the affiliate platform gone. Infrastructure seizure is the lever that works regardless of the suspects' age, and law enforcement has been leaning on it harder each year for exactly that reason.

What the 110 terabytes mean for victims

The recovered data cuts two ways, and both are worth saying plainly.

Any organisation that paid KillSec to delete its files should now assume the files were never deleted. They were on a server that is now in police custody. That is the standard outcome of a double-extortion payment, and it keeps being confirmed by takedowns rather than by anything the groups themselves say.

The other half is better news. 110 terabytes and a seized leak site give investigators a victim list longer than the roughly 450 names that were public — Spanish authorities alone have identified more than 280. Organisations that never knew they were breached are likely to hear from a national CERT in the coming weeks. If that notification arrives, the exposure is historical, and the cloud storage path that allowed it is probably still open. Reviewing object-store permissions and access logs across the 2024–2026 window is cheap, and it is the one action this case actually recommends.

Sources: Eurojust — Teenagers suspected of leading ransomware group arrested during international operation · Operation KillSwitch — law enforcement seizure notice · BleepingComputer — Police dismantle KillSec ransomware gang allegedly led by 16-year-old · SecurityWeek — Police shut down KillSec ransomware, identify alleged teen leader · The Record — Police disrupt KillSec ransomware, arrest suspected teenage leader · The Hacker News — Police arrest 16-year-old suspected of running KillSec

Keep reading