The images in this article were generated with artificial intelligence. How we publish
European security forces have disarticulated part of a network associated with the group known as KillSec: on 30 September, at least three arrests were carried out in different jurisdictions and the authorities took control of the website where the collective published stolen data. Among those arrested is a 16-year-old Spanish man, detained in the province of Alicante by the Civil Guard and the Mossos d'Esquadra; authorities in Hamburg and Eurojust coordinated the operation with support of Europol and United States teams, including the FBI in San Juan and Puerto Rico prosecutors, who have requested the extradition of one of the detainees in the United Kingdom.
Fact confirmed: the researchers claim that KillSec was engaged in the theft of data from organizations and blackmail through a leaks site on the dark web. The agents claim to have intervened at least 5 servers, placed seizure notices in the group's domains and secured around 110 terabytes of information and devices - including computer equipment, phones and cryptomoneda coins - during records in Spain, Romania, Greece and the United Kingdom. Transactions that match rescue payments have also been documented.

Technically, according to police releases, KillSec combined several usual techniques in digital extortion operations: exploitation of software vulnerabilities, abuse of poorly secured access to cloud services (e.g., poorly configured storage), purchase of credentials in criminal markets and use of affiliates who deployed malware. The group would have encrypted files with variants called KillSecurity 2.0 and 3.0 and, when it did not obtain payment, published or distributed stolen databases. The authorities also indicate that artificial intelligence was used to build and operate part of the infrastructure and to identify potential objectives, although there is little public information available at this point.
Those affected are organisations of very different type and size: authorities investigate about 1,000 suspicious incidents of which about 500 have been confirmed as successful so far; the Civil Guard numbers more than 280 the number of victims located in Spain and, in a specific case in Catalonia, the damage was estimated at almost 1 million euros. Europol and the prosecution offices point out that the group obtained "substantial payments" in cryptomonedas for these extortion.
What is proven and what remains to be confirmed: the pattern of theft and extortion, preliminary arrests and infrastructure intervention is confirmed. It is a credible estimate, supported by initial findings, that the business model also operated as Ransomware- as- a- service since mid-2024, allowing external affiliates to use the group's tools. Moreover, the exact extent of use of IA(what models, what specific functions and at what stage) and the identity and location of all the members of the network remain research; the figures of victims and amounts may vary as experts analyse the 110 TB seized.
Practical consequences: In addition to direct economic damage due to rescue and recovery, internal data leaks often involve loss of intellectual property, regulatory sanctions for data protection, reputational damage and subsequent use of information by other criminal groups (sale of credentials, fraud campaigns or targeted phishing). The fact that KillSec offered its tools to affiliates multiplies the probability of new independent incidents even after police intervention, because the variants of malware can remain in the hands of third parties.
What concrete measures should be taken by IT organisations and professionals now: 1) Immediate containment: isolate committed equipment, preserve logs and evidence for forensic investigation (do not overwrite or format). (2) Scope assessment: determine which systems and data were accessed; review accounts with privileges, exposed credentials and access to cloud services. 3) Recovery and cleaning: restore from verified backup and disconnect backups that are accessible through the network; apply patches to known vulnerabilities. 4. Fortification: Enable multi-factor authentication, review and tighten IAM policies in cloud suppliers (principle of less privilege), encryption data in rest and transit, and network segmentation to limit lateral movement. (5) Continuous detection: to deploy or strengthen EDR / SIEM, to search for commitment indicators and to take advantage of third-party threat intelligence. 6. Communication and compliance: notify the relevant authorities, inform customers where appropriate and coordinate with legal and communication teams. If you are a victim, consider recruiting specialists in response to incidents and cooperate with the authorities.
Practical tips for users and small businesses: change reused passwords, activate MFA in critical accounts (mail, cloud services, administrators), maintain up-to-date systems and applications, and store disconnected backup. They do not recommend paying bailouts generally: in addition to financing crime, there is no guarantee of data return and can create incentives for new extortion; the decision must be made with legal and technical advice.

What will the authorities do now: the prosecutors and police will continue to analyse the seized material to identify more victims, chart the money routes in cryptomonedas and locate other members - the researchers have identified operational roles as administrator, developer, negotiator and affiliate. International cooperation coordinated by Europol and Eurojust points to further legal steps and possibly further arrests or requests for extradition.
In order to deepen good practices and public resources on Ransomware response and prevention, the US cybersecurity agency guide is available. USA (CISA) on Ransomware ( https: / / www.cisa.gov / ransomware) and the Europol press room and notices related to coordinated operations ( https: / / www.europol.europa.eu / newsroom / news), where post-intervention communications and warnings are often published.
In short, the operation against KillSec shows that cross-border cooperation can disarm infrastructure and stop key individuals, but does not eliminate the risk for organizations that continue to be exposed by basic failure of configuration and access management. The operational lesson is clear: investing in digital hygiene, detection and rapid response reduces the likelihood of becoming the next victim of extortion.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...