
Google’s cloud outage: Move slowly and break things anyway
Why have one bug when you can have a series of them?


Picture, if you will, the mastermind of a ransomware gang with at least 20 claimed victims so far in 2026, in at least 11 different countries, across at least 12 different industry sectors․․․
The gang in this case is KillSec, which ransomware tracking site ransomware.live describes as follows:
KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split.
As you probably already know, RaaS is ironic shorthand, derived from the legitimate term software-as-a-service (loosely referring to pay-as-you-use-them apps that live in the cloud, such as Microsoft 365).
But RaaS means ransomware-as-a-service, where a core gang takes care of producing any malware their attacks may need, running darkweb sites for blackmail and data leaks, hitting up victims for extortion payments via encrypted messaging channels, and essentially operating a cloud-based crime portal for fellow criminals who get paid on “commission.”
They quite openly recruit and refer to these fellow criminals – the ones who carry out the actual network intrusions and data thefts – as affiliates, as though they were running a legitimate franchising operation.
Typical RaaS “affiliate programs” pay out, or claim to pay out, 70% of any blackmail payments received, with the core gang lying low in the background and pocketing 30% of every successful extortion.
You can imagine those figures arising because the first RaaS gangs simply looked to successful online markets such as Apple’s iTunes and App Store, and copied the splits used there.
But KillSec, as claimed above by ransomware.live, apparently offered an 88%/12% split, instead of the traditional 70%/30%, presumably to lure successful affiliates to jump ship from other RaaS groups, or at least to sign up with KillSec as well.
Previous busts by law enforcement have revealed that many affiliates are active in multiple ransomware gangs at the same time, and that victim details, and presumably stolen data dumps, are apparently shuttled between multiple, competing criminal groups. Clearly, this makes any promises made by RaaS gangs to to suppress stolen files in return for a blackmail payment emptier than ever.
According to Europol, the EU body that helps European and other law enforcement agencies co-operate in handling multinational crimes, KillSec’s alleged mastermind has been found.
At the top of this article, when you imagined this mastermind, were you thinking of an experienced but bitterly unappreciated IT manager-turned-rogue, or perhaps of a state-sponsored actor with loyalty to a foreign government?
Or did you picture an ambitious, immoral, late-30-something screenplay mobster like Mickey Garnett, the criminal call-center manager in the over-the-top 2024 film The Beekeeper?
If so, reality looks to be quite different:
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorized access. The cybercrime group used the site to threaten organizations with the publication of stolen files unless they paid a ransom. [․․․]
The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.
Europol further claims that one of the gang’s coders only turned 18 in August 2026, reminding us just how young many alleged cybercriminals seem to be.
Recently-arrested Scattered Spider suspect Peter Stokes, for example, is 19 now [2026], and has allegedly been active in cybercrime since 2023.
Interestingly, although the Europol press release declares that the KillSec ringleader is just 16 and one of the developers 18, those suspects are described merely as “identified,” so it’s not clear whether they’re among the three suspects who were actually arrested in the operation.
KillSec seems to be the sort of ransomware gang that doesn’t bother scrambling files to derail business operations as the final phase of its attacks.
Many attackers not only steal a victim’s trophy data, but also go on to carry out more traditional ransomware criminality involving widespread file encryption, thus giving themselves double-edged blackmail leverage through both plunder and disruption.
But file-scrambling malware can be hard to write, runs the risk of being blocked by EDR software and thereby setting off alarm bells, and requires pinpoint planning to trigger simultaneously across an entire network.
Victims have also learned that the “decryption tools” sold by ransomware blackmailers are often no faster to run or easier to use than simply restoring from recent backups, even if the whole network was affected.
Sometimes, sold-at-a-high-price decryptors are a total waste of money anyway, because they don’t work at all, thanks to the fecklessness and unreliability of many cybercriminals.
As a result, many ransomware gangs deliberately skip the encryption-based file-locking stage that was a standard part of early ransomware attacks – the very behavior from which the crime acquired its jargon name, and that inspired the names of the first big-time ransomware gangs such as CryptoLocker, Locky, and TeslaCrypt.
Ransomware takedowns like this one are to be applauded, because they prove that online anti-tracking tricks such as VPNs, darkweb sites, and end-to-end encrypted communications don’t invariably mean that cybercriminals can never be caught.
Indeed, in this case, the server taken down was itself a “hidden” .onion site on the anonymity-focused Tor network, meaning that the authorities have at least some deep inner knowledge and information about the gang and its operations:
But takedowns are often just temporary respites – new operators (or as-yet-unidentified gang members) typically jump into the vacuum thus created, sometimes under the very same name in a thumb-of-the-nose to law enforcement.
And affiliates who evade detection when a bust takes place often simply move on to another gang and resume their attacks.
So, remember that:

Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Why have one bug when you can have a series of them?

Learn what SOC 2 tells you about your suppliers, as well as how to make the most of the experience if you’re thinking of going for SOC 2 in your own business.

11 years between them, but they may have millions stashed away for when they get out.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






