Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →On 30 September 2026, authorities took control of KillSec’s leak site and domains, seized five servers, and secured at least 110 terabytes of data. The coordinated action also included three provisional arrests and eight searches across Spain, Greece, Romania, and the United Kingdom. Investigators link KillSec to about 1,000 suspected attacks worldwide, but that figure—and the roughly 500 attacks identified as successful so far—is preliminary, not a final count.
What happened to KillSec?
Authorities disrupted the group’s online infrastructure during Operation KillSwitch on 30 September 2026. Europol says police took control of the leak site and secured at least 110 terabytes of data against further unauthorized access. Eurojust reports that five servers were seized and domains were taken over. Swiss federal authorities separately say at least 110 terabytes of stolen data were recovered.
The action involved three provisional arrests and eight house searches in Spain, Greece, Romania, and the United Kingdom. Authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom, and the United States coordinated the investigation. Europol provided analytical, cryptocurrency-tracing, and digital-evidence support; Eurojust coordinated judicial authorities and the action day. Europol’s account of Operation KillSwitch and Eurojust’s announcement describe the coordinated action.
Who was arrested, and what is their legal status?
Europol and Eurojust identify a 16-year-old as the suspected main operator. Investigators also describe suspected administrator, developer, negotiator, and affiliate roles. One other suspected developer had recently turned 18 and was a minor at the time of some alleged offenses. These are investigative allegations, not findings of guilt; the authorities have not publicly identified the minors in the cited announcements.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
The three arrests were provisional. Swiss federal authorities say their investigation into suspected attacks on several Swiss companies from October 2023 to June 2025 is continuing and explicitly note that the presumption of innocence applies. An arrest or accusation does not establish that a person committed a crime.
A separate U.S. indictment
Within the coordinated action, the U.S. Department of Justice announced a separate case against Dutch national Fouad Eltibrizi, also known as Archduke. A federal grand jury in the District of Puerto Rico returned an indictment on 16 September 2026 alleging conspiracy involving unauthorized computer access, damage to protected computers, and transmission of extortionate threats. DOJ says Eltibrizi was arrested in the United Kingdom on 30 September and was awaiting extradition when the department published its release on 1 October. An indictment is an accusation, not a conviction.
According to DOJ’s summary of court documents, the indictment alleges that KillSec released approximately 180 gigabytes of one Puerto Rico victim’s data after a seven-day ransom countdown. DOJ says that, if convicted, Eltibrizi would face a maximum possible penalty of 10 years; any sentence would be determined by a judge. That statutory maximum is not a prediction of a sentence. See the DOJ announcement and its linked court document.
How many attacks and victims are involved?
| Measure | Reported figure | What it means |
|---|---|---|
| Suspected attacks worldwide | Around 1,000 | Europol’s 2026 estimate for attacks linked to the investigation; suspected, not a final verified total. Source: Europol. |
| Attacks identified as successful | Around 500 | Europol’s preliminary count at publication; the agency cautions it may change as evidence is reviewed. Source: Europol. |
| Victims and ransom payments | More than 280 victims; around €500,000 in some ransom payments | Figures reported by Spain’s Guardia Civil from its investigation, not a final independently verified tally. Investigators said an initial analysis of seized devices found evidence of ransomware-payment transactions. Source: Guardia Civil. |
| Data in the Puerto Rico case | Approximately 180 GB | DOJ’s summary of the indictment alleges this amount was released after a seven-day ransom countdown; it concerns one victim, not the group’s total data theft. Source: DOJ court-document summary. |
These numbers measure different things: suspected attacks, identified successful attacks, victims, payments, and data released in one alleged incident. They should not be treated as interchangeable. The authorities have not published a complete verified victim list, final attack or success total, consolidated loss estimate, or final court outcomes. They say they are examining seized devices and data and tracing financial proceeds, so additional victims, attacks, or participants could be identified.
Rank #3
How did KillSec allegedly extort victims?
Authorities say KillSec exploited vulnerabilities and poorly secured access points, particularly those connected with cloud storage, then copied sensitive internal data to infrastructure it controlled. The group allegedly listed victims on a dark-web leak site and threatened to publish stolen information unless they paid. Europol says files could be made available for free download when a victim did not pay. Swiss authorities characterize the method as double extortion: combining encryption with the threat to publish stolen data. Swiss federal authorities’ announcement describes the Swiss-company investigation and recovered data.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What can organizations do to reduce exposure?
Group-IB, a cybersecurity vendor that supported the investigation, recommends several general precautions. These are vendor recommendations, not controls shown to have stopped this specific operation:
Rank #4
- Maintain a current inventory of internet-facing assets, including cloud storage and remote-access services.
- Require multifactor authentication (MFA) for remote access.
- Prioritize patching vulnerabilities known to be exploited.
- Keep offline, immutable backups and make sure recovery procedures are workable.
- Assess software and IT service providers that hold or can access sensitive data.
An external drive may be one part of an offline backup plan, but an ordinary drive by itself is not necessarily immutable or a complete ransomware defense. Swiss authorities advise cyberattack victims to report incidents to relevant authorities or file a complaint with police or prosecutors.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

