Operation KillSwitch: Europol and Global Partners Dismantle KillSec Ransomware Group
On September 30, a multinational law enforcement operation Operation KillSwitch successfully dismantled the notorious ransomware group KillSec, seizing its infrastructure, cryptocurrency assets, and 110TB of stolen data. Led by German authorities, the operation involved Europol, Eurojust, and agencies from 10 countries, including the U.S., U.K., and several EU nations, alongside cybersecurity firm Group-IB.
KillSec, active since 2024, executed roughly 1,000 attacks worldwide, with at least 50% believed successful. The group primarily targeted healthcare, financial services, government entities, and SMBs, exploiting weak cloud and internet security. While it focused on smaller organizations, it also breached large enterprises and government bodies, including a major insurer, investment firms, and a consumer app with millions of users. Victims were concentrated in the U.S. (35%), followed by India (17%), Brazil, the U.K., Australia, and Colombia.
Investigators identified at least four core members: a 16-year-old ringleader (identity undisclosed), a developer (who turned 18 but committed crimes as a minor), a negotiator, and an affiliate. The group’s size may have been larger, as the investigation remains ongoing. Three arrests were made during the operation, though the ringleader was not among them. Authorities conducted eight house searches across Spain, Greece, Romania, and the U.K., seizing five central servers, multiple domains, and cryptocurrency proceeds from extortion.
KillSec initially targeted Windows systems but later expanded to VMware ESXi hosts with its KillSec 2.0 affiliate platform, released in late 2024. The platform enabled affiliates to shut down virtual machines, delete snapshots, and erase logs, while the group took a 20% cut of ransom payments. By early 2025, KillSec was openly recruiting skilled penetration testers, requiring either a forum reputation or a $1,000 deposit.
The takedown marks a significant blow to one of 2025’s most active ransomware operations, particularly in Asia-Pacific, Latin America, and the Middle East. While infrastructure can be rebuilt, law enforcement’s focus on identifying and prosecuting key members aims to prevent a rapid resurgence. The operation underscores the growing collaboration between global agencies and private cybersecurity firms in combating cybercrime.
VMware TPRM report: https://www.rankiteo.com/company/vmware
KillSec TPRM report: https://www.rankiteo.com/company/group-ib
Group-IB TPRM report: https://www.rankiteo.com/company/group-ib
"id": "vmwgro1790943965",
"linkid": "vmware, group-ib",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Healthcare',
'Financial services',
'Government',
'Technology'],
'location': ['U.S.',
'India',
'Brazil',
'U.K.',
'Australia',
'Colombia'],
'size': ['Small', 'Medium', 'Large'],
'type': ['Healthcare',
'Financial services',
'Government entities',
'SMBs',
'Large enterprises']},
{'industry': 'Insurance',
'name': 'Major insurer',
'size': 'Large',
'type': 'Large enterprise'},
{'industry': 'Financial services',
'name': 'Investment firms',
'size': 'Large',
'type': 'Large enterprise'},
{'customers_affected': 'Millions',
'industry': 'Technology',
'name': 'Consumer app with millions of users',
'size': 'Large',
'type': 'Large enterprise'}],
'attack_vector': ['Exploitation of weak cloud security',
'Exploitation of weak internet security'],
'data_breach': {'data_encryption': True, 'data_exfiltration': True},
'date_publicly_disclosed': '2025-09-30',
'description': 'A multinational law enforcement operation, Operation '
'KillSwitch, successfully dismantled the KillSec ransomware '
'group, seizing its infrastructure, cryptocurrency assets, and '
'110TB of stolen data. The operation was led by German '
'authorities with involvement from Europol, Eurojust, and '
'agencies from 10 countries, alongside cybersecurity firm '
'Group-IB.',
'impact': {'data_compromised': '110TB of stolen data',
'operational_impact': ['Shutdown of virtual machines',
'Deletion of snapshots',
'Erasure of logs'],
'systems_affected': ['Windows systems', 'VMware ESXi hosts']},
'investigation_status': 'Ongoing',
'motivation': ['Financial gain', 'Extortion'],
'post_incident_analysis': {'root_causes': ['Exploitation of weak cloud and '
'internet security']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransomware_strain': 'KillSec 2.0'},
'references': [{'date_accessed': '2025-09-30',
'source': 'Operation KillSwitch Announcement'}],
'response': {'containment_measures': ['Seizure of infrastructure',
'Seizure of cryptocurrency assets'],
'law_enforcement_notified': True,
'third_party_assistance': 'Group-IB'},
'threat_actor': 'KillSec Ransomware Group',
'title': 'Operation KillSwitch: Dismantling of KillSec Ransomware Group',
'type': 'Ransomware'}