Crypto加密

FBI arrests 16-year-old suspected leader of KillSec ransomware gang

Authorities in the United States and Europe identified a 16-year-old as the suspected main operator of KillSec, a cybercrime group linked to approximately 1,000 attacks worldwide. The crackdown, designated Operation KillSwitch,…

By Selene Vasquez·October 9, 2026·二〇二六年十〇月九日·2 min read

Authorities in the United States and Europe identified a 16-year-old as the suspected main operator of KillSec, a cybercrime group linked to approximately 1,000 attacks worldwide. The crackdown, designated Operation KillSwitch, occurred on Sept. 30 and resulted in the takedown of the group's dark web leak site and key infrastructure. Europol stated that roughly 500 of the suspected attacks were successful, though that figure may change as investigators review seized evidence.

The investigation involved police searches in Greece, Romania, Spain and the United Kingdom. Three suspects were provisionally arrested during the operation. Investigators secured at least 110 terabytes of stolen data and took control of five central servers connected to KillSec's activities. The group allegedly used its leak site to threaten victims with the publication of sensitive files unless they paid ransoms. Europol reported that the group received substantial payments from some of these incidents.

KillSec has been active since around 2024. The organization reportedly exploited software vulnerabilities and poorly secured access points to infiltrate organizations. Once inside, attackers copied internal files to systems they controlled. According to Europol, the group utilized artificial intelligence to assist in constructing ransomware systems and targeting likely victims. This technology assisted in accelerating specific phases of the operation rather than replacing human involvement.

Investigators also identified other individuals involved in the operation, including a developer who turned 18 in August but was a minor when some alleged crimes occurred. Additional suspects were identified as a negotiator and an affiliate. The investigation remains ongoing, with authorities examining seized computers, servers and other evidence. Investigators are also tracking cryptocurrency and other alleged criminal proceeds to uncover additional victims or associates.

The takedown highlights the accessibility of cybercrime tools and the risks posed by unpatched systems. Europol cautioned that while KillSec's core infrastructure has been disrupted, ransomware groups often reorganize and resurface under different names. The FBI advises against paying ransom demands because payment does not guarantee data restoration. Victims are encouraged to report incidents through the FBI's Internet Crime Complaint Center at IC3.gov or their local field office.

Source · 來源

foxnews.com

Share · 分享