Full Report
An international group of authorities from nine countries, coordinated by Eurojust and Europol, has successfully shut down a ransomware group responsible for almost 1 000 attacks worldwide. During the investigation, a 16-year-old was identified as the group’s main operator. The group, known as KillSec, stole sensitive data and threatened to publish the files unless a ransom was paid. KillSec has been around since 2024. By exploiting poorly secured access points, particularly those linked to cloud storage, the group was able to gain access to organisations’ systems. Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen data public unless the victims paid a ransom. If the victims did not pay, the stolen files were made available for free download. To prove that they possessed the stolen data, victims would get sent samples. In some cases, the group received substantial ransom payments. Authorities have identified other suspects in different roles, including administrator, developer, negotiator and affiliate. A teenager is suspected of being the group’s administrator and main operator. Other suspects include a developer who recently turned 18 and was a minor when a number of the alleged offences were committed. The group made itself known online by using aliases concealing their true identities. To communicate they used encrypted messaging services.
Analysis Summary
# Incident Report: International Takedown of KillSec Ransomware Group
## Executive Summary
KillSec, a ransomware-as-a-service (RaaS) group active since 2024 and led primarily by teenagers, was dismantled following an international law enforcement operation across nine countries. The group compromised nearly 1,000 organizations by exploiting insecure cloud storage access points to exfiltrate sensitive data for extortion. The operation resulted in the arrest of three key suspects, the seizure of infrastructure, and the recovery of 110 terabytes of stolen data.
## Incident Details
- **Discovery Date:** Investigation peaked October 1, 2026 (Action Day)
- **Incident Date:** Active from early 2024 to October 2026
- **Affected Organization:** Approximately 1,000 organizations worldwide
- **Sector:** Cross-sector (Multi-industry)
- **Geography:** Global (Law enforcement coordination in BE, FI, DE, GR, RO, ES, CH, UK, US)
## Timeline of Events
### Initial Access
- **Date/Time:** 2024 – 2026
- **Vector:** Exploitation of poorly secured access points.
- **Details:** The group specifically targeted vulnerabilities in cloud storage configurations to gain an initial foothold.
### Lateral Movement
- **Details:** Once initial access was achieved, the group navigated internal systems to identify and aggregate sensitive data repositories.
### Data Exfiltration/Impact
- **Details:** Data was copied to KillSec’s private infrastructure. Victims were sent samples as proof of compromise. If ransoms were not met, data was leaked for free download on public-facing sites.
### Detection & Response
- **Discovery:** Coordinated international investigation led by Eurojust and Europol, following financial trails and digital evidence.
- **Response Actions:** A Joint Investigation Team (JIT) was formed; an international "Action Day" resulted in house searches, server seizures, and arrests.
## Attack Methodology
- **Initial Access:** Exploitation of insecure cloud storage and access points.
- **Persistence:** Use of encrypted messaging services for C2 and coordination.
- **Privilege Escalation:** [Not specified in report]
- **Defense Evasion:** Use of aliases and encrypted communication channels.
- **Credential Access:** [Not specified in report]
- **Discovery:** Network scanning for misconfigured cloud instances.
- **Lateral Movement:** [Not specified in report]
- **Collection:** Aggregation of sensitive organizational files.
- **Exfiltration:** Transfer of data to attacker-controlled infrastructure.
- **Impact:** Data theft and "Name and Shame" extortion (Leaking data if no payment).
## Impact Assessment
- **Financial:** Substantial ransom payments received in some cases; significant recovery costs for 1,000 victims.
- **Data Breach:** At least 110 Terabytes (TB) of stolen data identified.
- **Operational:** Disruption of services during data theft and extortion phases.
- **Reputational:** High; group threatened public release of data to damage victim standing.
## Indicators of Compromise
- **Network indicators:** Encrypted messaging traffic (e.g., Signal/Telegram) used by threat actors for negotiation.
- **File indicators:** Stolen data samples provided to victims during extortion.
- **Behavioral indicators:** Unusual outbound data transfers to unauthorized cloud infrastructure; unauthorized access to cloud storage buckets.
## Response Actions
- **Containment:** Seizure of five central servers used to store victim data.
- **Eradication:** Takedown of domains operated by KillSec.
- **Recovery:** Law enforcement secured 110TB of data which may assist in victim notification and remediation.
## Lessons Learned
- **Key Takeaways:** Even "sophisticated" global ransomware operations can be spearheaded by minors/teenagers using widely available exploit methods.
- **Vulnerability Gap:** Cloud storage remains a primary target if not properly hardened with MFA and strict access controls.
## Recommendations
- **Cloud Security:** Implement strict IAM (Identity and Access Management) roles and ensure no cloud storage buckets are set to "public" unless necessary.
- **Multi-Factor Authentication (MFA):** Enforce phishing-resistant MFA on all remote access points and cloud consoles.
- **Data Loss Prevention (DLP):** Deploy tools to detect large-scale unauthorized data exfiltration to external infrastructure.
- **Incident Reporting:** Organizations should report compromises to local authorities (e.g., FBI, Europol) to assist in global infrastructure takedowns.