Group-IB Global Pte Ltd

10/01/2026 | Press release | Distributed by Public on 10/01/2026 12:07

Group-IB supports international Operation KillSwitch targeting the KillSec ransomware-as-a-service group

Group-IB, a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, today announced its contribution to Operation KillSwitch, an international investigation led by the Hamburg State Criminal Police Office (Landeskriminalamt Hamburg) and the Hamburg Public Prosecutor's Office, with the support of Europol and Eurojust, into KillSec, a ransomware-as-a-service (RaaS) group linked to around 1,000 suspected attacks worldwide. On 30 September 2026, law enforcement took control of KillSec's leak site, securing at least 110 terabytes of stolen data, while three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Investigators identified a 16-year-old as the group's suspected main operator. Group-IB supported the investigation with intelligence on the group's operations, infrastructure, and key enablers.

Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States took part in the investigation. Over its course, five central servers used to manage the group's activities and store data taken from victims were brought under police control, and KillSec's domains were redirected to a law enforcement seizure notice. Investigators identified suspects believed to hold different roles within the group, including an administrator, a developer, a negotiator, and an affiliate. Around 500 of the suspected attacks have so far been identified as successful, a figure that may change as investigators examine the evidence seized.

KillSec, also tracked as Kill Security and k1llsec, is a financially motivated Ransomware-as-a-Service (RaaS) group that Group-IB first identified in 2024. Operating a dark web leak site and public Telegram channels, the group recruited affiliates to carry out attacks using its platform in exchange for a share of each ransom. Group-IB's High-Tech Crime Trends Report 2026 ranked KillSec among the ten most active ransomware groups of 2025 in Asia-Pacific, Latin America, and the Middle East.

KillSec's dark web site following its seizure by law enforcement as part of Operation KillSwitch.

From small firms to government bodies

By monitoring KillSec's leak site and Telegram channels, Group-IB identified 274 organizations publicly claimed as victims on the group's leak site. Organizations in the United States accounted for around 35% of identified victims, followed by India at 17%, with Brazil, the United Kingdom, Australia, and Colombia each accounting for around 3%. By region, North America accounted for around 35% of victims and Asia-Pacific for 30%, followed by Europe -14% and the MEA at around 10%.

KillSec's Campaign Victimology. Source: Group-IB

Financial services and healthcare were the most affected sectors, while the victim list also included government bodies and large enterprises, among them a major insurer, investment firms, and a consumer app with millions of users. Although KillSec declared hospitals off-limits in a January 2025 recruitment post, from late 2025 the group shifted its focus toward healthcare software and IT service providers, where a single compromise can expose the patient records of every clinic using the platform.

Encryption was not a precondition for a KillSec listing. The group also sold stolen data outright, with asking prices ranging from USD 5,000 for a single company's records to USD 500,000 for the data it claimed to have taken from the global insurer, making KillSec as much a data broker as a ransomware operator.

A platform built to keep

In October 2024, Group-IB researchers analyzed the KillSec 2.0 affiliate platform, a Tor-based panel used to manage victims, ransom negotiations, and payload configuration. At the time, the group's locker was a Windows-only encryptor, offered to affiliates for a USD 250 entry fee and a 12% share of each ransom. Unusually, affiliates could not generate builds on demand: each one required approval from the group's administrators. The restriction pointed to a small core team guarding its payload, and it carried over into every version Group-IB observed.

The KillSec 3.0 RaaS affiliate platform. Source: Group-IB.

The upgrades came quickly. In November 2024, KillSec announced a locker for VMware ESXi virtualization hosts, capable of shutting down virtual machines, deleting snapshots, and erasing logs, removing the recovery points victims would otherwise rely on. By January 2025, the group was openly recruiting "skilled pentesters", requiring a forum reputation or a USD 1,000 deposit, and had raised its share of each ransom to 20%. Some KillSec affiliates also worked with other RaaS programs, including LockBit, RansomHub, Qilin, and Bashe. According to Europol, investigators also uncovered how the group used AI to build and maintain its ransomware infrastructure and identify potential victims.

Affiliates favored the path of least resistance. Alongside phishing, brute-force attacks on exposed Remote Desktop Protocol (RDP) services, and exploitation of known vulnerabilities in internet-facing applications, a substantial share of claimed victims involved no network intrusion at all: data was taken from cloud storage left publicly accessible through misconfiguration.

From intelligence to disruption

Security controls stop individual attacks, but KillSec's operations depended on the small core team that developed the locker and approved each build. Group-IB's support to the investigation focused on providing intelligence on the group's operations, infrastructure, and key enablers.

"KillSec's affiliates went after the organizations people depend on most: hospitals, government bodies, and financial institutions. Closing the gaps these groups exploit is essential, but it does not end an operation like this. Servers can be replaced in weeks; the people who build the platform and approve every attack cannot. Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end. We are proud to have contributed to Operation KillSwitch, and will continue to support Europol and our law enforcement partners in the fight against cybercrime."

Dmitry Volkov

CEO of Group-IB

Group-IB recommends that organizations treat external exposure as a first-order risk:maintain a continuous inventory of internet-facing assets, including cloud storage and remote access services; enforce multi-factor authentication on remote access; prioritize patching of vulnerabilities known to be exploited in the wild; and keep offline, immutable backups, with virtualization platforms protected as critical systems. The same scrutiny should extend to software and IT service providers that hold sensitive data on an organization's behalf, while monitoring leak sites and underground markets helps organizations learn of an exposure early, rather than from a public listing.

Operation KillSwitch is the latest in a series of international operations supported by Group-IB in collaboration with law enforcement agencies including Europol, INTERPOL, and AFRIPOL. To date, Group-IB has contributed to more than 1,600 high-tech crime investigations across 60+ countries.

Group-IB Global Pte Ltd published this content on October 01, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 01, 2026 at 18:08 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]