National News

Authorities take KillSec leak site offline, seize 110 TB of stolen data in Operation KillSwitch

An international law enforcement operation took the KillSec ransomware gang’s leak site and central servers offline and seized at least 110 terabytes of stolen data, disrupting an alleged campaign that investigators say targeted organizations worldwide.

Fox News reported that the takedown — called Operation KillSwitch — occurred on Sept. 30 and involved authorities from the United States and several European countries, with support from Europol and Eurojust.

According to the Fox News story, investigators linked KillSec to around 1,000 suspected attacks, about 500 of which have so far been identified as successful. Police carried out eight searches in Greece, Romania, Spain and the United Kingdom, and three suspects were provisionally arrested.

Investigators reportedly took control of five central servers connected to KillSec and seized the group’s dark web leak site, which authorities say the gang used to name victims and threaten publication of stolen files unless ransoms were paid.

Fox News said law enforcement identified a 16-year-old as KillSec’s suspected administrator and main operator. The outlet also reported that another suspected member, described as a developer, turned 18 in August and was reportedly still a minor when some of the alleged crimes occurred.

Europol told Fox News that KillSec has been active since around 2024 and that members allegedly exploited software vulnerabilities and poorly secured access points to break into organizations, copy sensitive files and then pressure victims by threatening to publish stolen data. Europol also cautioned that the current count of successful attacks could change as investigators continue reviewing seized evidence.

The Fox News article said investigators found that members of KillSec used artificial intelligence to help build and maintain ransomware infrastructure and to identify potential victims, though AI was not described as performing entire attacks on its own.

Authorities are examining seized computers, servers and other evidence and following cryptocurrency and other alleged criminal proceeds, Fox News reported, and said that work could uncover additional attacks, victims or people connected with the operation.

Fox News summarized FBI guidance included in the reporting: the agency does not support paying ransomware demands and encourages victims to report incidents to the Internet Crime Complaint Center at IC3.gov or to local FBI field offices. The outlet also relayed an FBI warning to type IC3.gov directly into a browser because scammers have created lookalike pages.

The investigation remains active, the Fox News report said.

Source: Latest & Breaking News on Fox News

Jon Ross Myers

Jon Ross Myers is the executive editor and publisher of the Mississippi News Network, Mississippi's largest digital only media company. He can be reached at editor@tippahnews.com