Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group

Operation KillSwitch (TL-2026-2829), also tracked as Operation KillSwitch, is a high-severity ransomware operation, first published 2026-10-01. It is attributed to KillSec with high confidence, affects Multiple Internet-facing software and cloud storage (buckets and, maps to 8 MITRE ATT&CK techniques (T1190, T1489, T1490), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2829

Threat ID
TL-2026-2829
Also known as
Operation KillSwitch
Severity
HIGH
Status
MONITORING
Category
RANSOMWARE
First published
2026-10-01
Last reviewed
2026-10-01
Attribution
KillSec
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
health, finance, insurance, technology, education, government administration
Target regions
North America, Europe, Asia, Oceania
Detection rules
9
Indicators of compromise
11

Malware and tooling in Operation KillSwitch

Malware and tooling: Kill Security, killsec, killsec3, MEGAsync, Rclone - S1040

On 30 September 2026 an international law enforcement action led by the Hamburg State Criminal Police Office and Hamburg Public Prosecutor's Office, coordinated by Europol and Eurojust with Bitdefender and Group-IB support, took over the KillSec leak site and seized five central servers. KillSec, active since about 2024, stole data by exploiting software vulnerabilities and poorly secured access points (particularly cloud storage) and threatened to publish it unless victims paid.

How Operation KillSwitch works

Operation KillSwitch targeted the KillSec (also tracked as Kill Security / KillSec3) data-theft extortion and ransomware-as-a-service group. The action day was 30 September 2026 and was announced by Europol and Eurojust on 1 October 2026. Ten countries took part: Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States. Law enforcement took control of the group's leak site, which was redirected to a seizure notice, secured at least 110 TB of data against further unauthorised access, gained control of associated domains and seized five central servers. Three suspects were provisionally arrested and eight property searches were carried out in four countries (Spain, Greece, the United Kingdom and Romania per press reporting).

Investigators identified a 16-year-old as the suspected administrator and main operator. A suspected developer turned 18 in August 2026 and was a minor during part of the alleged offending; a suspected negotiator and an affiliate were also identified, and inquiries into further members are ongoing. CyberScoop reports the negotiator as a Dutch national arrested in the UK and facing extradition to the US. National investigations began in early 2025. Investigators linked KillSec to about 1,000 suspected attacks worldwide, of which about 500 were identified as successful (subject to change). Close to 300 victims were posted on the leak site: 126 in 2025 and 25 in 2026, with the last known posting on 18 September 2026.

Per Bitdefender and Europol, KillSec exploited software vulnerabilities and poorly secured access points, particularly cloud storage, copied sensitive data and threatened to publish it unless victims paid. The group reportedly used AI to build and maintain its infrastructure and to identify potential victims. Earlier open reporting describes KillSec emerging in late 2023 as a self-styled Anonymous offshoot doing DDoS and defacement against government sites (India, Poland, Brazil) before becoming a RaaS operation by mid-2024 with affiliate dashboards and custom Windows and VMware ESXi lockers (AES-256-CBC with RSA-2048 key wrapping), exfiltrating with MEGAsync and Rclone, terminating Veeam/Acronis/Sophos processes and deleting shadow copies and event logs. These secondary-source details were not confirmed by the law enforcement announcement. No CVEs or technical IOCs (IPs, domains, hashes) were published by the sources. Defender guidance from Bitdefender: patch internet-facing software first, because that is where the scanning happens, then audit cloud storage access, with attention to buckets and shares nobody owns. The takedown reduces immediate risk, but affiliates and stolen data (110 TB secured, other copies may exist) remain a residual concern.

MITRE ATT&CK techniques used in TL-2026-2829

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft

Collection

T1530 Data from Cloud Storage

Exfiltration

T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in Operation KillSwitch

  • Multiple — Internet-facing software and cloud storage (buckets and shares)
    Vulnerable versions: Unpatched or poorly secured deployments

Remediation for Operation KillSwitch

Patches

  • Apply vendor security updates to all internet-facing applications, VPNs and gateways

Immediate actions

  • Patch internet-facing software first, since that is where scanning and exploitation occur
  • Audit cloud storage access, including buckets and shares with no clear owner
  • Check whether your organization was listed on the KillSec leak site or contacted by law enforcement

Workarounds

  • Restrict public access on cloud storage and require authenticated, least-privilege access

Longer-term hardening

  • Maintain an inventory of cloud storage and assign an owner to every bucket and share
  • Monitor for bulk data egress to consumer cloud-sync services (MEGA, Rclone-based transfers)
  • Keep offline, immutable backups and protect backup agents from tampering

Timeline of Operation KillSwitch

  • KillSec emerges (approx. late 2023) as a self-styled Anonymous offshoot conducting DDoS and defacement against government sites (secondary reporting; date approximate)
  • By mid-2024 (approx.) the group operates a RaaS portal with affiliate dashboards and Windows/ESXi lockers; active as a ransomware group since about 2024
  • National investigations into KillSec begin in early 2025 (approx.)
  • Victims such as Instituto de Ojos (Puerto Rico) and US BioTek Laboratories (Washington) are hit in March 2025; 126 victims are posted to the leak site over 2025
  • Accelerated Academy (Louisiana) is among the victims reported in September 2025
  • Suspected KillSec developer turns 18 in August 2026, having been a minor during part of the alleged offending
  • Last known victim posting on the KillSec leak site (25 victims posted in 2026)
  • Operation KillSwitch action day: leak site taken over, five central servers and domains seized, at least 110 TB of data secured, three provisional arrests, eight property searches
  • Europol and Eurojust announce the takedown; a 16-year-old is named as the suspected administrator and main operator

Sources cited for Operation KillSwitch

More in ransomware

Detection coverage for TL-2026-2829

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2829 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats