International operation seizes 110 terabytes from KillSec
European authorities have seized servers belonging to the ransomware group and detained three people.
An international police operation has dismantled the infrastructure of ransomware group KillSec. Authorities say they have secured at least 110 terabytes of stolen data and five servers.
The operation took place in several countries on Wednesday and was coordinated by Europol and Eurojust. According to the Swiss federal authorities, eight searches were carried out in Spain, Greece, the United Kingdom and Romania. Three people have been detained; their involvement still has to be assessed by the court.
KillSec, also known as KillSecurity, is said to have focused on stealing and encrypting corporate data. The group then demanded ransom from its victims. If they refused, the attackers threatened to publish or resell the data on the dark web. This model is known as double extortion.
The Swiss Office of the Attorney General has been investigating attacks on several Swiss companies since July 2025. The suspicions include data theft, unauthorised access to computer systems, damage to data and extortion. The authorities emphasise that the investigation is ongoing and that the suspects are presumed innocent until a court decides otherwise.
The Romanian judiciary also reported a detention and house searches as part of the same operation. According to Romanian prosecutors, the people involved used servers and encrypted means of communication to gain access to systems, copy data and put victims under pressure. That description comes from a preliminary investigation, not from a proven finding of guilt.
The seized data could be important to the investigation into victims, payments and the division of roles within the network. At the same time, it has not been made public which companies the data came from. Nor is it clear whether all 110 terabytes can be safely returned or what personal data they contain.
The operation has shut down part of the infrastructure, but does not automatically mean that ransomware will disappear. Groups can replace servers, change names or move parts of their activities elsewhere. For companies, it therefore remains particularly important to update systems quickly, limit access rights and keep reliable backups out of attackers’ reach; these are general security measures, not a guarantee against infection.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The key facts come from an official statement by the Swiss authorities and are supplemented by Romanian reporting on the same operation. The article carefully attributes the suspicions and avoids claims about unknown victims or definitive guilt.
- confirmed The international operation took place on 30 September 2026 and targeted KillSec. — The Swiss federal authorities describe the operation and the group. source
- confirmed Three people were detained and eight searches were carried out. — This is stated in the official Swiss statement. source
- confirmed Authorities secured at least 110 terabytes of stolen data and five servers. — The Swiss authorities cite both figures. source
- confirmed KillSec used double extortion. — The official statement describes encryption, ransom demands and threats of publication. source
- confirmed A person was detained in Romania as part of the same investigation. — Digi24 refers to information from the Romanian prosecutors. source
Editor's note
The operation, the three detentions, the five servers and at least 110 terabytes of secured data were reported by Swiss authorities. The precise scale of the victims, the contents of the data and the eventual criminal responsibility remain unknown.Sources
- Cybercrime: Computer network used by ransomware group dismantled — Swiss Federal Office of Police en Office of the Attorney General
- Operațiunea Killswitch în România și alte state din UE — Digi24
More on this in Dutch media
- de Volkskrant — „killsec ransomware”
- NOS — „killsec ransomware”
- Het Parool — „killsec ransomware”