2026-10-02NOTABLEPolice seize KillSec's leak site and five servers; the Swiss Federal Prosecutor has pursued the group since 2025
Operation KillSwitch (KillSec takedown, September 2026)
incident · incident:operation-killswitch-killsec-takedown-2026-09
German-led, Europol- and Eurojust-coordinated operation on 2026-09-30 that took control of the KillSec leak site and five servers, secured at least 110 TB of stolen data, made three provisional arrests in Greece, Romania, Spain and the United Kingdom and identified a 16-year-old as suspected administrator; fedpol and the Swiss Office of the Attorney General took part (Polizei Hamburg, fedpol and OAG, Europol, 2026-10-01).
Aliases: Operation KillSwitch
Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Police seize KillSec's leak site and five servers; the Swiss Federal Prosecutor has pursued the group since…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: switzerland, europe
Sources cited
3
3 hosts
Defender insights
What each entry about Operation KillSwitch (KillSec takedown, September 2026) tells a defender to do, newest first.
Detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
related to
- KillSeclaw-enforcement operation that seized the group's leak site and servers
Story timeline
Hunting pivots
ATT&CK techniques (4 across 3 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- CollectionData from Cloud Storage
- ImpactData Encrypted for Impact · Financial Theft
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗
Collection TA0009
T1530Data from Cloud Storage×1
Adversaries may access data from cloud storage.
Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-10-02/operation-killswitch-killsec-takedown-fedpol-oag · ATT&CK page ↗
Entries about Operation KillSwitch (KillSec takedown, September 2026) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- KillSec×1
Where this entity is cited
Source distribution
- europol.europa.eu1 (33%)
- fedpol.admin.ch1 (33%)
- presseportal.de1 (33%)
All cited sources (3)
- europol.europa.euEuropolhttps://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
- fedpol.admin.chfedpol and the Office of the Attorney General of Switzerlandhttps://www.fedpol.admin.ch/en/newnsb/cBOoSTI5a7sc
- presseportal.dePolizei Hamburghttps://www.presseportal.de/blaulicht/pm/6337/6363236