breach
Published 2026-10-01
Verified 2026-10-02

Operation KillSwitch: Europol/partners seize KillSec leak site — alleged 16yo admin; 3 arrests; ~500 successful attacks; 110TB+ blocked

UPDATE 1–2 Oct 2026 (desk): BleepingComputer (1 Oct) and SecurityWeek amplify Europol on Operation KillSwitch (German-led; action 30 Sep 2026) against KillSec ransomware. Seized dark-web leak site and servers; at least 110TB of stolen victim data taken offline; domains show Hamburg State Criminal Police / international LE seizure banner. Three suspects provisionally arrested and eight properties searched in Greece, Romania, Spain and the United Kingdom. Partners include Belgium, United States, Finland, Germany, Greece, Netherlands, Romania, Spain, Switzerland, UK, plus Europol, Eurojust, Bitdefender and Group-IB. Europol: ~1,000 suspected attacks worldwide since ~2024; investigators so far count ~500 successful attacks (about 70 linked to German orgs, including 18 Hamburg cases); prior leak-site listing ~450 victims. Alleged main operator/administrator is 16; a suspected developer turned 18 in August 2026 (still a minor for some alleged offences); negotiator and affiliate also identified. Entry often via software flaws and weakly protected edge/cloud storage; extortion via leak site. No Australian victim named in these wires. Primary wires: BleepingComputer / SecurityWeek citing Europol (1 Oct); Europol press page not stably fetchable from desk at pass time.

Product
KillSec ransomware operation (leak site / RaaS-style) — LE disruption, not a product CVE
Versions
n/a — Operation KillSwitch seizure / arrests (action 30 Sep 2026; reporting 1 Oct 2026)
Exploited in Australia?
unknown
Patch to
No product patch. Defenders: continue standard ransomware hygiene (patch internet-facing apps, harden cloud storage/edge devices, offline backups, MFA). Victims who were listed on KillSec: treat seizure as ops disruption not data recovery — assume data may still circulate; follow local breach notification duties. Watch Europol/national LE for further victim outreach.

Primary: BleepingComputer — Operation KillSwitch dismantles KillSec; alleged teen admin (1 Oct 2026) · SecurityWeek — Police shut down KillSec ransomware; alleged teen leader (1 Oct 2026)

breaches cloud