Written by: DarkWebSonar Research Team

On 30 September 2026, police took control of the dark web leak site run by the KillSec ransomware group. For a small security team that watches a handful of client domains, whether that site still loads matters less than whether a client, or a vendor holding a client's data, was named on it before it went dark.
Key facts
- Event: KillSec's dark web leak site was seized on 30 September 2026 in Operation KillSwitch.
- Led by: the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office, with Europol and Eurojust coordinating across ten countries.
- Seized: the leak site, the group's domains, five central servers, and at least 110 terabytes of data. Three suspects were provisionally arrested.
- DarkWebSonar's record: 293 KillSec postings naming organizations in 52 countries, from 21 March 2024 to 18 September 2026 (tracked in DarkWebSonar as Kill Security).
- Most named: the United States (33%) and India (17%); Financial Services (17%), Healthcare & Pharma (14%), and Technology & Telecom (14%).
- Why it still matters: more than eight in ten postings are over a year old, and a seized site does not recall files that were already published or sold.
What happened in Operation KillSwitch
Operation KillSwitch was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office, with Europol and Eurojust coordinating across ten countries. According to Europol, investigators took control of KillSec's leak site, redirected the group's domains to a seizure notice, brought five central servers under police control, and secured at least 110 terabytes of data. Three suspects were provisionally arrested and eight properties were searched in Greece, Romania, Spain, and the United Kingdom. Europol identifies a 16-year-old as the group's suspected main operator. A suspected developer turned 18 in August 2026.

Europol describes the case as an investigation into around 1,000 suspected attacks worldwide, of which about 500 have been identified as successful so far, a figure that may change as seized evidence is examined. Those are investigative totals. The leak-site record is smaller, and it is a record of claims rather than confirmed compromises.
What DarkWebSonar's record of KillSec postings shows
DarkWebSonar's record of KillSec postings (tracked in DarkWebSonar as Kill Security) runs from 21 March 2024 to 18 September 2026 and holds 293 postings naming organizations in 52 countries. The last posting appeared twelve days before the seizure.

KillSec (Kill Security) leak-site postings per quarter, DarkWebSonar record. A posting is the date an organization was named, not the date it was breached.
Three things in that record matter to a team with a short client list.
The site was already going quiet. The record holds 141 postings in 2024, 125 in 2025, and 27 in the first nine months of 2026, only nine of them in the six months before the takedown. Bitdefender, which supported the operation, counted 126 for 2025 and 25 for 2026, with the same final date. More than eight in ten postings are over a year old, so most of the exposure a client could have from this group sits in that older material, which is exactly the material a check done today is likely to skip.
The organizations named look like a small firm's client list. The United States accounts for 33% of postings (98) and India for 17% (49), followed by Brazil (12), then the United Kingdom, Belgium, and Australia (8 each). Financial Services is the most-named sector at 17% (50), then Healthcare & Pharma at 14% (42), Technology & Telecom at 14% (40), Professional Services at 11% (31), and Manufacturing & Construction at 8% (24). The earliest postings, in 2024, carried ransom demands of EUR 1,500 to EUR 10,000, low figures by ransomware standards. The 2026 postings include a regional pest-control company, a small consumer lender, a law firm, an online divorce-filing service, a fertility clinic group, and a veterinary hospital, alongside a US state agency and a national water utility. None of these claims is confirmed by the organization named.
Being named once is not the end of it. One large hospital group that KillSec posted in November 2024 appeared on LockBit's leak site in December 2025. A posting cannot show whether that was a second intrusion or the same data changing hands. We assess that either way the organization's exposure outlived the first posting by more than a year, and it would outlive a seized site too. Open-source reporting indicates that some KillSec affiliates also worked with LockBit, RansomHub, Qilin, and Bashe.
How KillSec got in
DarkWebSonar's visibility is the posting, not the victim network. What follows comes from the agencies and open-source reporting, not from our telemetry.

Europol says the group exploited software vulnerabilities and poorly secured access points, cloud storage in particular, copied data out, and threatened to publish it. Open-source reporting adds phishing, brute-force attacks on exposed Remote Desktop Protocol (RDP) services, and known vulnerabilities in internet-facing applications. It also indicates that a substantial share of the organizations posted suffered no network intrusion at all, only cloud storage left publicly accessible.
One further detail changes how a posting should be read: encryption was not required for an organization to be posted, and the group sold stolen data outright, with asking prices from USD 5,000 to USD 500,000. Healthcare software and IT service providers also appear among the organizations posted, and one such compromise can expose every clinic on the platform. A client can be in this story because a supplier was posted, not because the client was a target.
What small security teams should check this week
- Search the record, not the live site. In the DarkWebSonar intel feed, search each client's legal name, brands, and primary domains. The Kill Security threat actor profile lists every posting back to March 2024. Do the same for the healthcare-software and IT vendors those clients depend on.
- Treat a hit as a claim. Call the client before telling anyone else. Do not announce a breach from a posting alone.
- If a client or supplier was named, establish what was published, whether samples were sent, and which accounts, shares, and cloud buckets were in the set. Stolen files may already have been published or sold, so copies may exist outside the seized servers.
- Audit the cloud storage clients actually expose. Pay attention to the buckets and shares nobody owns: the ones left from a finished project, an acquisition, or a test that became permanent.
- Check for exposed RDP and unpatched internet-facing applications on the same pass.
- Reset credentials that could have been in a posted dataset, and look for reuse on email, VPN, and admin accounts.
- Keep watching after this check. An organization posted by KillSec can be posted again under another brand. Add the same names and domains as monitored keywords in DarkWebSonar so a new posting reaches you without a manual search. Teams that run this check as a client service can build on our guide to dark web monitoring for MSPs.
Operation KillSwitch put the leak site, five servers, and at least 110 terabytes of data under police control. It did not tell any small team whether one of its client domains was in the postings, the sales, or the downloads. That remains a name-and-domain check against what was already published, and the record to run it against is still searchable in DarkWebSonar after the leak site itself has gone dark.
Frequently asked questions
What happened to the KillSec ransomware group?
On 30 September 2026, law enforcement took control of KillSec's dark web leak site in Operation KillSwitch, led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office with Europol and Eurojust coordinating across ten countries. According to Europol, five central servers and at least 110 terabytes of data were secured and three suspects were provisionally arrested.
Is KillSec the same as Kill Security?
Yes. DarkWebSonar tracks the group's leak-site postings under the name Kill Security.
How many organizations did KillSec name on its leak site?
DarkWebSonar's record holds 293 KillSec postings naming organizations in 52 countries between 21 March 2024 and 18 September 2026. Europol describes an investigation into around 1,000 suspected attacks, of which about 500 have been identified as successful so far. A posting is a claim by the group, not a confirmed compromise.
Who did KillSec target?
In DarkWebSonar's record, the United States accounts for 33% of postings and India for 17%. Financial Services is the most-named sector (17%), followed by Healthcare & Pharma (14%), Technology & Telecom (14%), Professional Services (11%), and Manufacturing & Construction (8%). Many of the organizations named are small firms.
Does the KillSec takedown remove the data the group already published?
Not necessarily. The operation put the leak site, five servers, and at least 110 terabytes of data under police control, but stolen files may already have been published or sold, so copies may exist outside the seized servers.
How do I check whether my organization or a client was named by KillSec?
Search the organization's legal name, brands, and primary domains in the DarkWebSonar intel feed, and do the same for key suppliers. The Kill Security threat actor profile lists every posting back to March 2024. Treat a hit as a claim and confirm it with the organization before telling anyone else.
Is an organization safe now that KillSec's leak site has been seized?
A seized site does not end the exposure. One hospital group that KillSec posted in November 2024 appeared on LockBit's leak site in December 2025, and open-source reporting indicates that some KillSec affiliates also worked with other ransomware groups.
Last updated: 2026-10-05
Sources
- Europol, Teenager suspected of leading KillSec ransomware group: law enforcement seizes servers and leak site, 1 October 2026
- Bitdefender, What the KillSec Takedown Changes for Defenders, 1 October 2026
- BleepingComputer, Police dismantle KillSec ransomware gang allegedly led by 16-year-old, 1 October 2026
- DarkWebSonar record of KillSec postings, March 2024 to September 2026