Disarticulated KillSec network with arrests in Spain and United Kingdom and seized 110 TB

Author: Published 5 min de lectura 8 reading

The images in this article were generated with artificial intelligence. How we publish

European security forces have disarticulated part of a network associated with the group known as KillSec: on 30 September, at least three arrests were carried out in different jurisdictions and the authorities took control of the website where the collective published stolen data. Among those arrested is a 16-year-old Spanish man, detained in the province of Alicante by the Civil Guard and the Mossos d'Esquadra; authorities in Hamburg and Eurojust coordinated the operation with support of Europol and United States teams, including the FBI in San Juan and Puerto Rico prosecutors, who have requested the extradition of one of the detainees in the United Kingdom.

Fact confirmed: the researchers claim that KillSec was engaged in the theft of data from organizations and blackmail through a leaks site on the dark web. The agents claim to have intervened at least 5 servers, placed seizure notices in the group's domains and secured around 110 terabytes of information and devices - including computer equipment, phones and cryptomoneda coins - during records in Spain, Romania, Greece and the United Kingdom. Transactions that match rescue payments have also been documented.

Disarticulated KillSec network with arrests in Spain and United Kingdom and seized 110 TB
Image generated with IA.

Technically, according to police releases, KillSec combined several usual techniques in digital extortion operations: exploitation of software vulnerabilities, abuse of poorly secured access to cloud services (e.g., poorly configured storage), purchase of credentials in criminal markets and use of affiliates who deployed malware. The group would have encrypted files with variants called KillSecurity 2.0 and 3.0 and, when it did not obtain payment, published or distributed stolen databases. The authorities also indicate that artificial intelligence was used to build and operate part of the infrastructure and to identify potential objectives, although there is little public information available at this point.

Those affected are organisations of very different type and size: authorities investigate about 1,000 suspicious incidents of which about 500 have been confirmed as successful so far; the Civil Guard numbers more than 280 the number of victims located in Spain and, in a specific case in Catalonia, the damage was estimated at almost 1 million euros. Europol and the prosecution offices point out that the group obtained "substantial payments" in cryptomonedas for these extortion.

What is proven and what remains to be confirmed: the pattern of theft and extortion, preliminary arrests and infrastructure intervention is confirmed. It is a credible estimate, supported by initial findings, that the business model also operated as Ransomware- as- a- service since mid-2024, allowing external affiliates to use the group's tools. Moreover, the exact extent of use of IA(what models, what specific functions and at what stage) and the identity and location of all the members of the network remain research; the figures of victims and amounts may vary as experts analyse the 110 TB seized.

Practical consequences: In addition to direct economic damage due to rescue and recovery, internal data leaks often involve loss of intellectual property, regulatory sanctions for data protection, reputational damage and subsequent use of information by other criminal groups (sale of credentials, fraud campaigns or targeted phishing). The fact that KillSec offered its tools to affiliates multiplies the probability of new independent incidents even after police intervention, because the variants of malware can remain in the hands of third parties.

What concrete measures should be taken by IT organisations and professionals now: 1) Immediate containment: isolate committed equipment, preserve logs and evidence for forensic investigation (do not overwrite or format). (2) Scope assessment: determine which systems and data were accessed; review accounts with privileges, exposed credentials and access to cloud services. 3) Recovery and cleaning: restore from verified backup and disconnect backups that are accessible through the network; apply patches to known vulnerabilities. 4. Fortification: Enable multi-factor authentication, review and tighten IAM policies in cloud suppliers (principle of less privilege), encryption data in rest and transit, and network segmentation to limit lateral movement. (5) Continuous detection: to deploy or strengthen EDR / SIEM, to search for commitment indicators and to take advantage of third-party threat intelligence. 6. Communication and compliance: notify the relevant authorities, inform customers where appropriate and coordinate with legal and communication teams. If you are a victim, consider recruiting specialists in response to incidents and cooperate with the authorities.

Practical tips for users and small businesses: change reused passwords, activate MFA in critical accounts (mail, cloud services, administrators), maintain up-to-date systems and applications, and store disconnected backup. They do not recommend paying bailouts generally: in addition to financing crime, there is no guarantee of data return and can create incentives for new extortion; the decision must be made with legal and technical advice.

Disarticulated KillSec network with arrests in Spain and United Kingdom and seized 110 TB
Image generated with IA.

What will the authorities do now: the prosecutors and police will continue to analyse the seized material to identify more victims, chart the money routes in cryptomonedas and locate other members - the researchers have identified operational roles as administrator, developer, negotiator and affiliate. International cooperation coordinated by Europol and Eurojust points to further legal steps and possibly further arrests or requests for extradition.

In order to deepen good practices and public resources on Ransomware response and prevention, the US cybersecurity agency guide is available. USA (CISA) on Ransomware ( https: / / www.cisa.gov / ransomware) and the Europol press room and notices related to coordinated operations ( https: / / www.europol.europa.eu / newsroom / news), where post-intervention communications and warnings are often published.

In short, the operation against KillSec shows that cross-border cooperation can disarm infrastructure and stop key individuals, but does not eliminate the risk for organizations that continue to be exposed by basic failure of configuration and access management. The operational lesson is clear: investing in digital hygiene, detection and rapid response reduces the likelihood of becoming the next victim of extortion.

Coverage

Related

More news on the same subject.