Home
Blog
KillSec cyber-blackmail suspects busted, darkweb site seized

KillSec cyber-blackmail suspects busted, darkweb site seized

Paul Ducklin
10/04/2026
Share this article:

Use your imagination

Picture, if you will, the mastermind of a ransomware gang with at least 20 claimed victims so far in 2026, in at least 11 different countries, across at least 12 different industry sectors․․․

The gang in this case is KillSec, which ransomware tracking site ransomware.live describes as follows:

KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split.

As you probably already know, RaaS is ironic shorthand, derived from the legitimate term software-as-a-service (loosely referring to pay-as-you-use-them apps that live in the cloud, such as Microsoft 365).

But RaaS means ransomware-as-a-service, where a core gang takes care of producing any malware their attacks may need, running darkweb sites for blackmail and data leaks, hitting up victims for extortion payments via encrypted messaging channels, and essentially operating a cloud-based crime portal for fellow criminals who get paid on “commission.”

They quite openly recruit and refer to these fellow criminals – the ones who carry out the actual network intrusions and data thefts – as affiliates, as though they were running a legitimate franchising operation.

Typical RaaS “affiliate programs” pay out, or claim to pay out, 70% of any blackmail payments received, with the core gang lying low in the background and pocketing 30% of every successful extortion.

You can imagine those figures arising because the first RaaS gangs simply looked to successful online markets such as Apple’s iTunes and App Store, and copied the splits used there.

But KillSec, as claimed above by ransomware.live, apparently offered an 88%/12% split, instead of the traditional 70%/30%, presumably to lure successful affiliates to jump ship from other RaaS groups, or at least to sign up with KillSec as well.

Previous busts by law enforcement have revealed that many affiliates are active in multiple ransomware gangs at the same time, and that victim details, and presumably stolen data dumps, are apparently shuttled between multiple, competing criminal groups. Clearly, this makes any promises made by RaaS gangs to to suppress stolen files in return for a blackmail payment emptier than ever.

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber

Back to reality

According to Europol, the EU body that helps European and other law enforcement agencies co-operate in handling multinational crimes, KillSec’s alleged mastermind has been found.

At the top of this article, when you imagined this mastermind, were you thinking of an experienced but bitterly unappreciated IT manager-turned-rogue, or perhaps of a state-sponsored actor with loyalty to a foreign government?

Or did you picture an ambitious, immoral, late-30-something screenplay mobster like Mickey Garnett, the criminal call-center manager in the over-the-top 2024 film The Beekeeper?

If so, reality looks to be quite different:

On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorized access. The cybercrime group used the site to threaten organizations with the publication of stolen files unless they paid a ransom. [․․․]

The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.

Europol further claims that one of the gang’s coders only turned 18 in August 2026, reminding us just how young many alleged cybercriminals seem to be.

Recently-arrested Scattered Spider suspect Peter Stokes, for example, is 19 now [2026], and has allegedly been active in cybercrime since 2023.

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber

Interestingly, although the Europol press release declares that the KillSec ringleader is just 16 and one of the developers 18, those suspects are described merely as “identified,” so it’s not clear whether they’re among the three suspects who were actually arrested in the operation.

Ransomware without encryption

KillSec seems to be the sort of ransomware gang that doesn’t bother scrambling files to derail business operations as the final phase of its attacks.

Many attackers not only steal a victim’s trophy data, but also go on to carry out more traditional ransomware criminality involving widespread file encryption, thus giving themselves double-edged blackmail leverage through both plunder and disruption.

But file-scrambling malware can be hard to write, runs the risk of being blocked by EDR software and thereby setting off alarm bells, and requires pinpoint planning to trigger simultaneously across an entire network.

Victims have also learned that the “decryption tools” sold by ransomware blackmailers are often no faster to run or easier to use than simply restoring from recent backups, even if the whole network was affected.

Sometimes, sold-at-a-high-price decryptors are a total waste of money anyway, because they don’t work at all, thanks to the fecklessness and unreliability of many cybercriminals.

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber

As a result, many ransomware gangs deliberately skip the encryption-based file-locking stage that was a standard part of early ransomware attacks – the very behavior from which the crime acquired its jargon name, and that inspired the names of the first big-time ransomware gangs such as CryptoLocker, Locky, and TeslaCrypt.

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber

What to do?

Ransomware takedowns like this one are to be applauded, because they prove that online anti-tracking tricks such as VPNs, darkweb sites, and end-to-end encrypted communications don’t invariably mean that cybercriminals can never be caught.

Indeed, in this case, the server taken down was itself a “hidden” .onion site on the anonymity-focused Tor network, meaning that the authorities have at least some deep inner knowledge and information about the gang and its operations:

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber

But takedowns are often just temporary respites – new operators (or as-yet-unidentified gang members) typically jump into the vacuum thus created, sometimes under the very same name in a thumb-of-the-nose to law enforcement.

And affiliates who evade detection when a bust takes place often simply move on to another gang and resume their attacks.

So, remember that:

  • Cybersecurity prevention is always better than cure, not least because stolen data can never be considered safe from disclosure. Even if your attackers genuinely intend to delete your data after getting their payoff, many of them have shown that they have very poor operational security themselves, so who knows who else has already got your data anyway?
  • Prepare for the worst no matter how strongly you think you’ve protected your data. If you do get breached, you need to react quickly and decisively. It’s not enough just to kick the crooks out, because you also need to figure out what they did while they were in, given that they may have opened up holes for themselves to use in the future, or to sell on to other attackers. You may also need to front up to the regulators, your customers, and the media, so decide in advance how you will divide up those important human-facing tasks.
  • Listen to our Exploits versus Entropy podcast for entertainingly good-humored but actionable advice on how to improve your operational resilience without drowning in technology or buying “more tools, more tools.”
  • Remember that you don’t have to do it all yourself. Stay on top of cyberthreats without distracting staff from your core business. Sign up with SolCyber to do it for you, human style.

Listen to the TALES FROM THE SOC podcast:
Exploits versus Entropy

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber

If the media player above doesn’t work in your browser, try clicking here to listen in a new browser tab.

Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

KillSec cyber-blackmail suspects busted, darkweb site seized - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!


Paul Ducklin
Paul Ducklin
10/04/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

15065