On September 30, police in Belgium, the U.S., Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the U.K. hit the ransomware crew KillSec under Operation KillSwitch. I am working from Europol's notice and the BleepingComputer write-up. Europol says investigators identified a 16-year-old as the suspected main operator, provisionally arrested three people, and searched eight properties.

Hamburg police shut five servers, including the leak site, which now shows a seizure banner. Authorities seized at least 110 terabytes of stolen data and say around 500 attacks look successful so far, including about 70 in Germany. Europol says the group used AI to help build infrastructure and pick victims.

Leak sites are how these crews apply public pressure. A seizure banner is the rare day that story is a takedown. The alleged age of the admin will drive the headline. The quieter fact is that leak-site claims and stolen-data hoards got cheap enough for teenagers until police landed. If a vendor of mine was named on KillSec, I watch official notices. I do not visit leftover mirrors to check.