CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Operation KillSwitch (KillSec takedown, September 2026)

incident · incident:operation-killswitch-killsec-takedown-2026-09

German-led, Europol- and Eurojust-coordinated operation on 2026-09-30 that took control of the KillSec leak site and five servers, secured at least 110 TB of stolen data, made three provisional arrests in Greece, Romania, Spain and the United Kingdom and identified a 16-year-old as suspected administrator; fedpol and the Swiss Office of the Attorney General took part (Polizei Hamburg, fedpol and OAG, Europol, 2026-10-01).

Aliases: Operation KillSwitch

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Police seize KillSec's leak site and five servers; the Swiss Federal Prosecutor has pursued the group since…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: switzerland, europe
Sources cited
3
3 hosts

Defender insights

What each entry about Operation KillSwitch (KillSec takedown, September 2026) tells a defender to do, newest first.

2026-10-02NOTABLEPolice seize KillSec's leak site and five servers; the Swiss Federal Prosecutor has pursued the group since 2025

Detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-10-02Operation KillSwitch: Europol-coordinated takedown of the KillSec ransomware group, with Swiss fedpol and the Federal Prosecutor's Office, who have investigated its attacks on Swiss companies since 2025
    active-threatsPolice seize KillSec's leak site and five servers; the Swiss Federal Prosecutor has pursued the group since 2025
ATT&CK techniques (4 across 3 tactics)

4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • CollectionData from Cloud Storage
  • ImpactData Encrypted for Impact · Financial Theft

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗

Entries about Operation KillSwitch (KillSec takedown, September 2026) (1)

2026-10-02 · view entry permalink →

NOTABLENATOA1

Operation KillSwitch: Europol-coordinated takedown of the KillSec ransomware group, with Swiss fedpol and the Federal Prosecutor's Office, who have investigated its attacks on Swiss companies since 2025

On 2026-09-30 law enforcement took control of the KillSec extortion group's leak site and secured at least 110 terabytes of stolen data in Operation KillSwitch, led by the Hamburg State Criminal Police Office and Public Prosecutor's Office and coordinated by Europol and Eurojust (Polizei Hamburg, 2026-10-01; fedpol and OAG, 2026-10-01). Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain and the United Kingdom; five servers, including the main server and several exfiltration servers, were taken over, and investigators identified a 16-year-old as suspected administrator and main operator, a developer, a negotiator and an affiliate (Polizei Hamburg, 2026-10-01). The authorities count about 1,000 suspected attacks worldwide, at least 70 of them in Germany, and about 500 of the 1,000 are so far identified as successful, and say the figures may change (Polizei Hamburg, 2026-10-01).

fedpol and the Office of the Attorney General took part as operational and strategic partners; since 2025-07-31 the OAG has run proceedings against persons unknown over KillSec's attacks on several Swiss companies between October 2023 and June 2025, and fedpol, with cantonal police and the NCSC, mapped the group's modus operandi before the action (fedpol and OAG, 2026-10-01). Polizei Hamburg says KillSec is said to have obtained data by exploiting software vulnerabilities and poorly secured access points to organisations' systems, in particular cloud storage, and to have copied internal data to infrastructure it controlled, listed victims on a leak site and, when a victim did not pay, could offer the files for free download; Europol adds that the group used AI to build and run its ransomware infrastructure and to identify victims (Polizei Hamburg, 2026-10-01; Europol, 2026-10-01). No source names a Swiss victim, a product or a specific vulnerability, and the seized evidence may identify further victims (Polizei Hamburg, 2026-10-01).

Exposure: organizations that were extorted by KillSec or whose data appeared on its leak site, and any organization with software vulnerabilities or poorly secured access points, in particular cloud storage, the entry points Polizei Hamburg says KillSec is said to have used (Polizei Hamburg, 2026-10-01); the NCSC says in the release that a public entity, a business or an individual can be a target (fedpol and OAG, 2026-10-01).

cyber-attacks carried out against several Swiss companies by the ransomware group KillSec (or “KillSecurity”) between October 2023 and June 2025

The authorities were thereby able to recover at least 110 terabytes of stolen data.

fedpol and the Office of the Attorney General of Switzerland 2026-10-01

Investigators also uncovered how the group used AI to build and maintain its ransomware infrastructure and identify potential victims.

Europol 2026-10-01
threat02 Oct 04:48Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • europol.europa.eu1 (33%)
  • fedpol.admin.ch1 (33%)
  • presseportal.de1 (33%)