DKDKCISSPSearch
RansomwareDEVELOPING

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

An international law enforcement operation dubbed seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator.

DKCISSP News DeskBleepingComputer1 Oct 2026, 7:55 pm
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator.

Hamburg Police said it investigated the group's server infrastructure, which led to the identification and shutdown of five servers, including KillSec's main server and several servers allegedly used to store stolen data.

Investigators also discovered that members of the group used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.

According to data breach notification letters shared online by affected individuals, DMDC discovered “a security vulnerability in a DMDC file sharing system” on July 16, 2026, which “allowed unauthorized users to access files.” “Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII,” the letters say.

A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide.

According to Europol, the suspected administrator and main operator of KillSec is only 16 years old.

During the investigation, they seized five servers the group used to store victim data, along with domains operated by KillSec.

The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data.

KillSec has been active since around 2024 and is accused of exploiting software vulnerabilities and poorly secured edge devices and platforms to breach corporate systems and steal sensitive data.

Authorities also targeted the group’s criminal proceeds." The investigation began in 2025 and helped law enforcement identify suspects believed to be an administrator, developer, negotiator, and affiliate of the cybercrime group.

What happened

An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator.

Hamburg Police said it investigated the group's server infrastructure, which led to the identification and shutdown of five servers, including KillSec's main server and several servers allegedly used to store stolen data.

What changed

Investigators also discovered that members of the group used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.

According to data breach notification letters shared online by affected individuals, DMDC discovered “a security vulnerability in a DMDC file sharing system” on July 16, 2026, which “allowed unauthorized users to access files.” “Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII,” the letters say.

Who is affected

A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide.

According to Europol, the suspected administrator and main operator of KillSec is only 16 years old.

Why it matters

During the investigation, they seized five servers the group used to store victim data, along with domains operated by KillSec.

The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data.

Technical details

KillSec has been active since around 2024 and is accused of exploiting software vulnerabilities and poorly secured edge devices and platforms to breach corporate systems and steal sensitive data.

Response

Authorities also targeted the group’s criminal proceeds." The investigation began in 2025 and helped law enforcement identify suspects believed to be an administrator, developer, negotiator, and affiliate of the cybercrime group.

Clicking the seizure banner leads to the Operation KillSwitch website, which includes a law-enforcement video about the ransomware gang and the arrests.

What security teams should do

Investigators will examine the seized devices and data and trace the group’s financial proceeds.

Investigators say the seized evidence could reveal further victims, attacks, and people involved with the ransomware operation.

Attribution

BleepingComputer: An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator.

Help Net Security: A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide.

Help Net Security: The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

MORE IN RANSOMWARE

More cybersecurity reporting

INC Ransomware Attack: Impact, Victims, Recovery | HuntressHuntress · 1 Oct 2026, 5:30 amJapan's Keio confirms ransomware attack disrupted business systemsBleepingComputer · 29 Sept 2026, 2:26 amShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacksBleepingComputer · 27 Sept 2026, 12:33 amShinyHunters hacked Clop leak site using Grav CMS path traversal flawBleepingComputer · 26 Sept 2026, 2:27 am