Operation KillSwitch: Europol-coordinated takedown of the KillSec ransomware group, with Swiss fedpol and the Federal Prosecutor's Office, who have investigated its attacks on Swiss companies since 2025
Police seize KillSec's leak site and five servers; the Swiss Federal Prosecutor has pursued the group since 2025
Analysis
On 2026-09-30 law enforcement took control of the KillSec extortion group's leak site and secured at least 110 terabytes of stolen data in Operation KillSwitch, led by the Hamburg State Criminal Police Office and Public Prosecutor's Office and coordinated by Europol and Eurojust (Polizei Hamburg, 2026-10-01; fedpol and OAG, 2026-10-01). Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain and the United Kingdom; five servers, including the main server and several exfiltration servers, were taken over, and investigators identified a 16-year-old as suspected administrator and main operator, a developer, a negotiator and an affiliate (Polizei Hamburg, 2026-10-01). The authorities count about 1,000 suspected attacks worldwide, at least 70 of them in Germany, and about 500 of the 1,000 are so far identified as successful, and say the figures may change (Polizei Hamburg, 2026-10-01).
fedpol and the Office of the Attorney General took part as operational and strategic partners; since 2025-07-31 the OAG has run proceedings against persons unknown over KillSec's attacks on several Swiss companies between October 2023 and June 2025, and fedpol, with cantonal police and the NCSC, mapped the group's modus operandi before the action (fedpol and OAG, 2026-10-01). Polizei Hamburg says KillSec is said to have obtained data by exploiting software vulnerabilities and poorly secured access points to organisations' systems, in particular cloud storage, and to have copied internal data to infrastructure it controlled, listed victims on a leak site and, when a victim did not pay, could offer the files for free download; Europol adds that the group used AI to build and run its ransomware infrastructure and to identify victims (Polizei Hamburg, 2026-10-01; Europol, 2026-10-01). No source names a Swiss victim, a product or a specific vulnerability, and the seized evidence may identify further victims (Polizei Hamburg, 2026-10-01).
Exposure: organizations that were extorted by KillSec or whose data appeared on its leak site, and any organization with software vulnerabilities or poorly secured access points, in particular cloud storage, the entry points Polizei Hamburg says KillSec is said to have used (Polizei Hamburg, 2026-10-01); the NCSC says in the release that a public entity, a business or an individual can be a target (fedpol and OAG, 2026-10-01).
Cited evidence
cyber-attacks carried out against several Swiss companies by the ransomware group KillSec (or “KillSecurity”) between October 2023 and June 2025
The authorities were thereby able to recover at least 110 terabytes of stolen data.
Investigators also uncovered how the group used AI to build and maintain its ransomware infrastructure and identify potential victims.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.