Police seize KillSec leak site after arrests across Europe

Police have arrested three people in a coordinated investigation into the KillSec ransomware group, including a 16-year-old in Alicante, Spain, whom investigators suspect was the group’s main administrator. The September 30 operation also resulted in arrests in the United Kingdom and Romania, the seizure of KillSec’s leak site, the shutdown of five servers and the securing of at least 110 terabytes of data.
Hamburg police and prosecutors led the operation with Spanish law-enforcement agencies, Europol, Eurojust, U.S. prosecutors in Puerto Rico and the FBI’s San Juan office. Police conducted eight searches across Spain, Greece, the UK and Romania. Spanish officers seized computer equipment, phones and cryptocurrency wallets, and said an initial review identified transactions matching ransom payments from some victims.
Investigation maps a data-theft extortion operation
Investigators have identified suspected roles within KillSec including an administrator, developer, negotiator and affiliate. Hamburg police described the Spanish teenager as the suspected administrator and principal operator. The suspected developer, who turned 18 in August, has been identified but was not arrested. Authorities described all three arrests as provisional, while the investigation continues.
Romanian prosecutors detained a 24-year-old and searched four properties in Bucharest and Vaslui county. He is being investigated for alleged offences including forming an organised criminal group, illegal computer access, unauthorised data transfer, illegal operations involving devices or software, and blackmail. Prosecutors sought 30 days of custody; he is presumed innocent.
Police say KillSec gained entry by exploiting software vulnerabilities and poorly protected access points, particularly cloud storage. The group allegedly copied sensitive internal data to systems it controlled, named victims on a dark-web leak site and demanded payment in exchange for withholding publication. Where victims did not pay, stolen files could be made available for download.
Seized evidence could expand the case
The investigation spans about 1,000 suspected attacks worldwide, of which about 500 have so far been identified as successful. Both totals may change as authorities examine seized devices and data. Spanish police put the number of victims at more than 280, while Europol said the group obtained substantial ransom payments.
Hamburg police also said investigators uncovered the group’s use of AI to build and operate infrastructure and identify potential victims, without providing further technical detail. Romanian prosecutors said members allegedly bought access credentials on dark-web marketplaces, sent victims samples of stolen information and threatened to sell data to other criminal groups if ransoms were not paid.
Rapid7 reported in 2025 that KillSec had operated as a hacktivist group since at least 2021 before moving into ransomware in October 2023. Its KillSecurity 2.0 and 3.0 tools are designed to encrypt files, although some incidents involved data theft and extortion alone. In June 2024, the group began offering its ransomware to affiliates under a ransomware-as-a-service model.
Business implication
The takedown does not end the exposure created by stolen data or weak access controls. Businesses should prioritise securing cloud storage, patching exploitable software, controlling privileged access and preparing a response process for data-theft extortion, while recognising that seized evidence may reveal additional victims and attacks.

