Build1 publisher2 min readPublished
Investigators say KillSec got in through weak cloud storage, unpatched software and bought logins
Investigators say KillSec, tied to about 1,000 suspected attacks, got in through software flaws, weak cloud storage and logins bought on the dark web. Those gaps sit in victims' own systems, beyond the reach of any server seizure.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Police in Spain, the U.K. and Romania arrested three people on September 30, among them a 16-year-old in Alicante province suspected of being KillSec's main administrator.
- Hamburg police say about 500 of the suspected attacks are confirmed successful so far, and Spanish police count more than 280 victims.
- Officers shut down five servers including KillSec's main server, put seizure notices on five domains and secured at least 110 TB of data.
- The suspected developer, who turned 18 in August, has been identified but not arrested.
- Puerto Rico has filed an extradition request for the man arrested in the U.K., with U.S. prosecutors and the FBI's San Juan office involved in the case.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Where the group extorted with stolen data alone, a clean restore from backup recovers the systems and leaves the threat to publish or sell the data where it was.
- exposure Targeting followed the gaps, so an organization's exposure depends on whether it has a reachable bucket, an unpatched internet-facing service or a leaked login, whatever country it operates in.
- constraint With four roles identified, an affiliate program running since June 2024 and only provisional arrests, seizing the main server cannot be read as the end of attacks using KillSec's tools.
Hamburg police describe a short chain. KillSec got in by exploiting software vulnerabilities and poorly secured access points, especially cloud storage [5]. Romania's organized crime directorate, DIICOT, adds a third route: members bought login credentials sold on the dark web [6]. Once inside, the group moved sensitive data onto its own servers, listed the victim on its leak site on the dark web and threatened to make the data public [7]. If a victim did not pay, the stolen files could be offered for free download [7]. According to Hamburg police, the group also relied on AI to set up and operate its infrastructure and to identify possible targets [8].
Each route needs a different control. A patch closes a vulnerability. It does nothing for a storage bucket whose own access settings let outsiders read it. It also does nothing for a password that still works. For that reason I'd put the bought credential first on a review list. A fully patched estate still accepts a correct login.
For KillSec, encryption was optional [9]. Its ransomware, KillSecurity 2.0 and 3.0, is built to encrypt files, but in some incidents the group extorted victims with stolen data alone [9]. DIICOT said members sent victims samples of their own data as proof and threatened to sell it to other criminal groups [10].
Hamburg's confirmed count so far comes to about half the suspected total [1]. One attack, on a Catalan organization in early 2025, did damage put at close to 1 million euros [11]. Among the items Spanish officers took were computers, phones and cryptocurrency wallets. An initial review turned up transactions that line up with ransom paid by some victims [12].
Attackers make small mistakes too: the Guardia Civil says it identified its suspect starting from a single profile image [13]. Investigators have identified suspects in four roles: administrator, developer, negotiator and affiliate [14]. Rapid7 reported in 2025 that the group began offering its ransomware to affiliates in June 2024 [15]. Affiliates are outside partners who run attacks with a group's tools [15]. That same day, two more people in their 20s were arrested, one in the U.K. and the other in Romania [16]. The write-up does not say which roles they held. Hamburg police called all three arrests provisional [17].
What to watch
- Charging or extradition filings in Puerto Rico that state which of the four roles the U.K. and Romania suspects are accused of holding.
- Any further detail from Hamburg police on how the group used AI to find potential victims.
- Whether analysis of the seized cryptocurrency wallets ties more ransom payments to named victims.