Skip to content

Security3 publishers2 min readPublished

Investigators say a 16-year-old ran KillSec, an extortion crew that exploited weakly secured cloud storage

Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.

The Watch · Security desk

Photograph accompanying Investigators say a 16-year-old ran KillSec, an extortion crew that exploited weakly secured cloud storage
Photo: europa.eu

What happened

  • Operation KillSwitch, the international investigation that identified the teenager, was led by police and prosecutors in Germany.
  • Officers made three provisional arrests and searched eight homes in Greece, Romania, Spain and the United Kingdom.
  • Investigators identified suspects acting as KillSec's administrator, developer, negotiator and affiliate.
  • Police took over KillSec's dark web leak site on Wednesday, and the group's domains now redirect to a law enforcement seizure notice.
  • Over the course of the investigation, police gained control of five core servers KillSec used to manage operations and hold stolen data.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Authorities know of about 50 more successful attacks than the leak site listed, so an organisation's absence from the site was never proof it had escaped this crew.
  • decision The entry route both accounts single out is cloud storage access that owners configure themselves, and SecurityWeek's mention of software flaws keeps patching on the same list.
  • capability Leak-site extortion with roughly 500 confirmed victims was within reach of a crew whose suspected administrator is 16 and whose developer was a minor for part of the run.

Authorities are aware of roughly 500 successful KillSec attacks, SecurityWeek reported [16]. Europol's figure for the total is roughly 1,000 suspected attacks [25]. Set against that and Eurojust's almost 1,000 [2], confirmed compromise is about half the attributed total [1]. Police secured at least 110 TB of stolen data [12]. Averaged over the known successful attacks, that is about 220 GB per victim [3].

KillSec's leverage was the threat to publish. "Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen data public unless the victims paid a ransom. If the victims did not pay, the stolen files were made available for free download," Eurojust said [5]. "To prove that they possessed the stolen data, victims would get sent samples. In some cases, the group received substantial ransom payments," the agency added [6]. Before the takedown, the leak site listed roughly 450 victims [17].

Eurojust says the group got in by exploiting poorly secured access, particularly access linked to cloud storage [4]. SecurityWeek's account also points to cloud storage, but it lists software flaws alongside weakly protected entry points [15].

Neither agency grades the crew's technical skill. The suspected administrator and main operator is 16 [1]. The developer turned 18 in August [9] and was a minor when some of the alleged offences were committed, Eurojust noted [8]. Members used aliases online and talked through encrypted messaging services [10].

Eurojust lists judicial authorities from nine countries [19]. SecurityWeek lists ten, the same nine plus the Netherlands [20] [4]. Belgium, Germany, Greece and Romania set up a joint investigation team at Eurojust [21]. Europol traced cryptocurrency and put investigators in touch with private-sector partners [22]. SecurityWeek names two firms that supported the operation, Bitdefender and Group-IB [26].

What to watch

  • Whether the continuing hunt for other KillSec members produces arrests beyond the three provisional ones made on the action day.
  • What the tracing of KillSec's proceeds, including cryptocurrency, turns up: a ransom total, or victims who paid and were never listed.
  • Victim notifications drawn from the 110 TB and five servers now in police hands.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories