Image: Group-IB
Police have seized KillSec’s leak site and core servers, while three suspects were provisionally arrested in an international operation. The group targeted organizations worldwide, particularly in financial services and healthcare, putting business and patient data at risk.
What Operation KillSwitch achieved
Group-IB, which provided intelligence to Operation KillSwitch, says investigators identified a 16-year-old as KillSec’s suspected main operator. Authorities also searched eight properties across Greece, Romania, Spain and the United Kingdom.Police took control of five central servers and redirected KillSec’s domains to a seizure notice. At least 110TB of stolen data was secured, although examining that evidence may change the current estimate of about 500 successful attacks.
Who KillSec targeted
KillSec operated a ransomware-as-a-service scheme, supplying attack tools to affiliates in return for part of each ransom. Investigators linked it to around 1,000 suspected attacks worldwide.Group-IB found 274 organizations publicly named on KillSec’s leak site. About 35% were in the United States and 17% in India, with financial services and healthcare the most affected sectors.
Victims did not always have their files encrypted. KillSec also sold stolen information directly, reportedly asking from $5,000 for one company’s records up to $500,000 for data allegedly taken from a global insurer.
Reduce exposure to similar attacks
KillSec affiliates reportedly used phishing, password-guessing attacks against exposed Remote Desktop Protocol services, and known flaws in internet-facing software. Some claimed victims suffered no network break-in because their cloud storage had mistakenly been left public.- Turn on multi-factor authentication for remote access, so a password alone is not enough to sign in.
- Inventory internet-facing systems, including remote access services and cloud storage, and check that storage is not publicly accessible.
- Prioritize fixes for vulnerabilities known to be actively exploited.
- Keep offline, unchangeable backups and protect virtualization platforms as critical systems.