An international group of authorities from nine countries, coordinated by Eurojust and Europol, has successfully shut down a ransomware group responsible for almost 1 000 attacks worldwide. During the investigation, a 16-year-old was identified as the group’s main operator. The group, known as KillSec, stole sensitive data and threatened to publish the files unless a ransom was paid. KillSec has been around since 2024. By exploiting poorly secured access points, particularly those linked to cloud storage, the group was able to gain access to organisations’ systems. Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen data public unless the victims paid a ransom. If the victims did not pay, the stolen files were made available for free download. To prove that they possessed the stolen data, victims would get sent samples. In some cases, the group received substantial ransom payments. Authorities have identified other suspects in different roles, including administrator, developer, negotiator and affiliate. A teenager is suspected of being the group’s administrator and main operator. Other suspects include a developer who recently turned 18 and was a minor when a number of the alleged offences were committed. The group made itself known online by using aliases concealing their true identities. To communicate they used encrypted messaging services.