FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $3T +1.6%24h Vol $114B +17%Fear & Greed 72/100Alts Index 51/100
BTC.D 58.7% 0%Stable.D 9.0% -0.1%ETH.D 11.3% -0.1%Others.D 21.0% +0.2%
SAND$0.0674+58.11%•NIGHT$0.0476+24.01%•CARDS$0.2493+22.4%•APE$0.1788+21.3%•GALA$0.00266527+18.44%•ZRO$1.988+18.28%•MANA$0.1036+18.13%•SKY$0.0936+17.99%•BAT$0.1031+17.42%•WLD$0.5756+14.82%•
BR$0.6682-11.58%•SOON$0.3828-11.07%•BP$1.360-8.56%•QNT$248.63-6.75%•CAP$0.0754-6.14%•KNTQ$0.3160-5.93%•ENA$0.2450-5.4%•LIT$3.711-4.83%•JASMY$0.00551115-4.83%•JST$0.1275-4.34%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Law Enforcement Seized KillSec’s Infrastructure: Group’s Main Operator Is Believed to Be 16-year-old

      • Law enforcement agencies from four European countries detained three suspects in a case involving about 1,000 KillSec attacks.
      • During the operation, authorities seized the group’s servers and took control of its data leak site containing more than 110 TB of information.
      • Investigators believe a 16-year-old teenager is the likely main operator of KillSec.

      On September 30, 2026, as part of the international KillSwitch operation, law enforcement took control of the infrastructure of the KillSec group, which is linked to about 1,000 cyberattacks worldwide. The operation was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office. 

      In Greece, Romania, Spain, and the United Kingdom, authorities carried out eight searches and provisionally detained three suspects, while investigators consider a 16-year-old teenager the likely main operator of the group.

      Law enforcement also gained control of the KillSec ransomware leak site, where the attackers published victims’ data or threatened to release it. According to investigators, the infrastructure contained at least 110 TB of information, which is now protected from further unauthorized access.

      KillSec Stole Data From Hundreds of Organizations

      KillSec has been operating since around 2024. Members of the group exploited software vulnerabilities and poorly secured access points, including to cloud storage, to break into organizations’ systems and copy sensitive internal data.

      After that, victims were threatened with the publication of the stolen information on a darknet site. If an organization refused to pay the ransom, the files could be made available for free download. In some cases, the attackers received substantial payouts.

      So far, investigators have confirmed about 500 successful attacks out of roughly 1,000 suspected incidents. The final number may change after analysis of the seized devices and data.

      Law enforcement also found that KillSec used AI to build and maintain its ransomware infrastructure, as well as to identify potential victims.

      Minors Are Involved in the Case

      Investigations into attacks linked to KillSec in various countries began in early 2025. Investigators identified several individuals who likely performed different roles within the group: an administrator, a developer, a negotiator, and an affiliate.

      The suspected administrator and lead operator of KillSec is 16 years old. Another suspect, believed to be the developer, turned 18 in August 2026, although he may have committed some of the alleged crimes while still a minor. The investigation into other possible participants is ongoing.

      During the operation, law enforcement took control of five central servers used to manage KillSec’s activities and store stolen data. Devices and assets were also seized, and the group’s domains were redirected to a law enforcement notice about the infrastructure seizure.

      Investigators are analyzing the seized materials and tracing criminal proceeds, including cryptocurrency transactions. Law enforcement agencies from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States, as well as Europol and Eurojust, joined the investigation.

      Earlier, in June 2026, Europol, together with law enforcement from several countries, also shut down the crypto service AudiA6, which, according to investigators, was used to launder about $389 million linked to ransomware groups.

      Сообщение Law Enforcement Seized KillSec’s Infrastructure: Group’s Main Operator Is Believed to Be 16-year-old появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud