Skip to main content

Morning Overview

A ransomware crew with 500 successful attacks was allegedly run by a 16-year-old

Eight properties across Greece, Romania, Spain and the United Kingdom were searched on September 30, three suspects were provisionally arrested, and five servers behind a ransomware brand called KillSec went dark. Investigators say the person they suspect of running the group is 16 years old, and nobody has been convicted of anything.

The legal posture shapes everything else about the case, down to the verbs. Europol’s own wording is that investigators “identified a 16-year-old as the group’s suspected main operator,” which is an accusation by police, not a finding by a court.

Arrests, not charges, and a suspect described only by age

Europol and Eurojust coordinated the action, with Hamburg police leading the work on the group’s server infrastructure, according to BleepingComputer’s report on the operation. The countries involved were Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States, with Bitdefender and Group-IB assisting. Three suspects were arrested on a provisional basis. In the sources reviewed, no formal charges against any named person have been announced, and the 16-year-old has not been named.

Eurojust’s statement, published October 1, adds that the suspects include a developer who turned 18 in August 2026 while the offences were continuing, along with a negotiator and an affiliate. Both agencies use the language of suspicion throughout. Everything attributed to the 16-year-old in this article is therefore an allegation, and the age is the charging-side detail police have chosen to release: it comes from Europol, and no court has tested it. Eurojust describes the suspects as accused of running a scheme that stole organizations’ data and threatened to publish it unless a ransom was paid, which is a description of the allegation rather than a verdict.

The 500 and the 1,000

Two different counts circulate, and they should not be merged. Europol’s public summary says the group is linked to some 1,000 attacks worldwide, and Eurojust likewise cites almost 1,000. The narrower number, around 500 successful attacks, comes from BleepingComputer’s reporting of the investigation’s findings, which states that about 500 of the group’s attacks succeeded and that roughly 70 of the victims were German organizations, 18 of them in Hamburg.

The 500 is therefore a count attributed to investigators rather than a boast by the gang. The group’s own claims ran lower at an earlier stage: a September 2025 profile by the Red Dog Security Report listed about 199 claimed victims. Counting claims on a leak site and counting successful intrusions are different exercises, and the gap between 199, 500 and 1,000 reflects different definitions as much as growth over time.

From hacktivist Telegram channel to ransomware franchise

According to the Red Dog profile, KillSec surfaced in late 2023 on Telegram with ties to the Anonymous movement and an early record of denial-of-service attacks and website defacements against government sites in India, Poland and Brazil. By mid-2024 it was running a ransomware-as-a-service model, offering affiliates log-ins, dashboards and custom lockers for Windows and VMware ESXi systems. Eurojust says the group has been active since 2024, and the BleepingComputer account says the investigation itself began in 2025, which puts roughly a year between the first police work and the day the servers were switched off.

The victims were far from the operators’ home turf. Information Age reported in 2025 that KillSec had claimed eight Australian victims since late 2024, among them the Brisbane provider Hexicor. Rapid7’s Matt Green told the publication the group “has remained highly active in 2025,” with victims historically in healthcare, finance and government.

Seized servers, 110 terabytes and a leak site

The seizures were substantial. BleepingComputer lists five servers shut down, including the main KillSec server and data-storage machines, plus the dark-web leak site. Europol says officers took control of the leak site and secured at least 110 terabytes of data against further unauthorized access, which means stolen victim files that had been sitting on criminal infrastructure are now in police hands. Eurojust adds that judicial authorities from nine countries took part and that a joint investigation team linked Belgium, Germany, Greece and Romania, the arrangement that lets prosecutors in several states share evidence and coordinate raids on a single day.

Two points remain unsettled in the public record: whether the arrested teenager will be charged in a juvenile or an adult system, and which of the nine participating countries will prosecute. Neither agency has said. The searches took place in Greece, Romania, Spain and the United Kingdom, while Hamburg police handled the server analysis, so the arrests and the evidence trail sit in different jurisdictions, and a prosecution would have to settle where the case is heard before any allegation about the group’s leadership or its attack count can be tested in court.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview