Almost everything written this week about the KillSec takedown revolves around two numbers: the 110 terabytes of stolen data secured and the main suspect's age, 16. We are interested in a third one, which was nobody's headline and decides a great deal more: joining that business as an affiliate cost $250. At the other end of the same story, the cyberattack on a Catalan organisation that opened the Mossos investigation left an estimated damage of close to one million euros.
They are not two sides of one ledger, and that is worth saying before going further: the detainee is the suspected administrator, not an affiliate who paid that $250; the million euros is the victim's damage, not anybody's revenue; and that price list had already changed by January 2025. We put them together because they measure two things that ought to be a great deal closer to each other: what it costs to try, and what it costs to take.
What happened, in the numbers of the people who signed them off
On 30 September 2026, on the action day of Operation KillSwitch —an investigation led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office, with Europol and Eurojust coordinating—, authorities took control of KillSec's infrastructure. The official tally: three arrests, eight premises searched across Spain, Greece, the United Kingdom and Romania, five central servers seized, the leak site taken over and redirected to a law-enforcement notice, and at least 110 terabytes of stolen data secured against further unauthorised access. Authorities from ten countries took part and a joint investigation team was set up at Eurojust.
The Spanish side of the case was codenamed Operation ROTOMA and belongs to the Cybercrime Department of the Guardia Civil's UCO and the cybercrime unit of the Mossos d'Esquadra's Criminal Investigation Division. It started with police cooperation with the FBI in San Juan, Puerto Rico. There were two searches in the province of Alicante: one at a home and another at an office inside a hotel establishment. Computer equipment, mobile phones, crypto wallets and anonymisation services were seized, along with transactions corresponding to ransom payments. The detainee is a 16-year-old Romanian national, named as the suspected administrator and main operator; a woman was also placed under investigation. A suspected developer who turned 18 in August 2026 was additionally identified in Spain, without arrest: some of the acts attributed to him would date from when he was a minor. The other two arrests took place in the United Kingdom and in Romania.
The thread the Mossos pulled is the one closest to home for us: they opened an investigation into a cyberattack against a Catalan organisation in early 2025, allegedly the work of this group, which got into the company's systems, stole sensitive information and tried to extort it, with an estimated damage of close to one million euros. The organisation has not been named publicly and we are not going to speculate about which it is. Across the whole case, the Guardia Civil counts more than 1,000 cyberattacks worldwide, around 500 of them successful and more than 280 victims, some of whom are reported to have paid ransoms of around 500,000 euros in cryptocurrency.
The 2024 price list: $250 and the house keeps 12 %
Group-IB, which supported the investigation with intelligence on the group's infrastructure, has tracked KillSec since 2024 and has published the mechanics of the business. The ransomware-as-a-service platform launched in June 2024, and the group recruited affiliates through its leak site and public Telegram channels. The initial locker —Windows-only at that point— was offered for a $250 entry fee, with the house keeping 12 % of each ransom: the affiliate kept 88 %. That was the launch price. By January 2025 the group was openly recruiting "skilled pentesters", demanding forum reputation or a $1,000 deposit, and had raised its own share to 20 %.
The panel lived on Tor and covered victim management, ransom negotiation and payload configuration. One operational detail says a lot about the organisation: affiliates could not generate builds on demand; each one required approval from an administrator. And one figure that matters to our reader more than all of the above: in November 2024 the group announced a locker for VMware ESXi hypervisors, able to shut down virtual machines, delete snapshots and wipe logs. It was not just going after the data: it was going after the recovery points, which is the distinction between restoring and recovering.
The other leg of the business was selling the data: from $5,000 for a single company's records up to $500,000 for what they advertised as a global insurer's data. And Europol adds a 2026 detail that was not in the 2024 script: the group used artificial intelligence tools to build and maintain its infrastructure and to select targets.
Put it together and what comes out is not a conspiracy of geniuses: it is an org chart with a price list. Roles handed out —administrator, developer, negotiator, affiliate—, a panel to manage victims, negotiate and configure the payload, a sign-up fee, a security deposit, and a commission that management raised by eight points when it suited them. It looks a lot more like a mediocre SaaS than like a film.
We are not going to make the teenager joke
He is a minor, there is a presumption of innocence and the case is open. Beyond that, the age does not measure what almost everyone is assuming it measures. It does not say the attack was sophisticated; it says how cheap the door into the trade was. And that does have a direct consequence for whoever signs off a security budget: if your mental model of the adversary is "someone with resources, who would have to really want to get in here", you are defending against a threat that stopped being the common one a while ago. What is on the other side, in the general case, is someone who paid a fee, logged into a panel with templates and worked down a list.
The four doors, and none of them is exotic
This is how they got in, according to Group-IB's analysis:
- Phishing. The same old thing, still working because it is still the cheapest thing to try.
- Brute force against RDP services exposed to the internet.
- Exploitation of known vulnerabilities in internet-facing applications.
- Publicly accessible cloud storage due to misconfiguration. And here comes the part that has been repeated least: Group-IB stresses that for a substantial share of claimed victims there was no network intrusion at all. The data was already exposed outside the network. In fact, encryption was not even a precondition for ending up on their victim list.
Europol and Eurojust use the same formula to describe it —"exploiting vulnerabilities and poorly secured access points"— and Eurojust adds the only emphasis that matters: "particularly those linked to cloud storage". There is no surprise on that list. They are the same four as always.
Put bluntly: for every two attacks suspected of it, one has already been confirmed successful, and the count can only go up —Europol warns the figure may change as the seized evidence is examined. It is not a measured success rate, nor a census of the installed base: it is what is known today about one specific actor. Even with all that margin, what it does not say is anything about the attacker's talent.
The dirty average of the 110 terabytes
This calculation is ours, not the sources', and comes with its assumptions up front. There are two public denominators and neither is the right one: the ~500 successful attacks give around 220 GB per attack; the more than 280 victims counted by the Guardia Civil give a little under 400 GB per victim. It is a dirty average for four reasons: the official figure is "at least" 110 TB; not everything stolen had to still be there on 30 September; the attacks piled up over two years while the 110 TB is one day's snapshot; and the real distribution is not even — there will be victims with a few gigabytes and some with several terabytes. But it fixes the order of magnitude, which is all we ask of it: what this kind of extortion carries off is measured in hundreds of gigabytes, not in the twenty megabytes of an attachment.
The operational question that number leaves is not about the laptop's antivirus, it is about egress: if 300 GB left your network tonight towards a destination nobody has ever seen, would you find out tomorrow, next month, or when someone calls you? You do not need a new tool to answer it: you need someone to look at the traffic you are already generating, which is the hole left when you have four EDR consoles and no alerts. With one exception Group-IB itself flags and that is worth keeping: for some of these victims nothing left their network at all, because the data was already exposed outside it. For those, the question is not egress; it is the first check on the list below.
What a seizure does not delete
KillSec ran double extortion in part of its caseload: encrypt, and on top of that threaten to publish what was taken. But not always, and the nuance matters: Group-IB notes that encryption was not a precondition for ending up on its list. It is worth holding on to one verifiable fact and going no further. The fact is this: on 30 September, when police took control, that infrastructure held at least 110 TB of stolen data. Whose it was, and whether any of it belonged to a victim who had paid for it to disappear, nobody has said and we do not know.
What can be stated with that snapshot in front of you is simpler and more uncomfortable: when a negotiation in this market includes paying for something to be deleted, that deletion is not a verifiable deliverable. There is no way to check it, no invoice that proves it, and the only moment anyone actually sees what was left on the other side's disks is when a police force seizes them. This is not a sermon about paying or not paying —each company makes that call with its lawyer and its insurer, not with us. It is an observation about what exactly you are buying when you buy silence, and we already ran into it with the "rescuers" who turned out to be the same people who had encrypted you.
There is a second consequence, less commented on. Europol says it will follow up on the seized evidence because it could surface more victims and more people involved. Translated into practice: some companies will find out they were compromised because an authority calls them, not because they detected it. If that happens to you, the question that follows is not "how did they get in?" but "what did they take and who has to be notified?". That one is answered with logs you kept beforehand, or it is not answered at all.
This week's inventory, looked at from the outside
The doors above can be audited in a few days, and most of the work is not bought, it is done. There is one condition: look from the outside, not from the inventory and not from the console. The inventory describes what you thought you had built; the internet describes what is there. We start with the one this case has shown was the most profitable.
- Every bucket, folder or share in the cloud, with its public-access flag. It is the route Eurojust explicitly points to in this case, and the one that leaves no trace at all on your network. The test is not the console screen, which shows you what you configured: it is opening the URL in a private window, with no session, and seeing what comes back.
- What answers on your public IPs. List every public address you have and check, from a connection outside the office, which ports respond. Port
3389should never answer from the internet; neither should admin panels. If somebody tells you "that is behind the firewall", the right response is not to believe them: it is to scan it from outside and show them the result. - Every published application, with its version, the date of its last patch and a name next to it. Webmail, the customer portal, the file manager, the VPN, the ticketing system. The one with no owner is the way in: not because it is worse, but because nobody reads its security advisory.
- MFA on everything facing the internet, and the question that comes after. A second factor stops credential stuffing; it does not stop someone who steals an already-authenticated session. So after "do we have MFA?" comes "what makes that session expire, and how fast?".
- And a fifth one, which is not a door but a way out. If your backups live on the same hypervisor as the thing they back up, the November 2024 ESXi locker already explained what deleting snapshots is for. A backup the attacker can reach with the credentials he came in on is not a backup: it is another one of his files.
None of this makes you invulnerable, and saying otherwise would be exactly the kind of sentence we do not write. What it does is take you off the pile of confirmed victims that fell to four generic keys. For the rest —the day they do get in— what decides the outcome is not the door: it is how long you take to see it and how much you can recover.
What we are not saying
We are not saying the operation was pointless. It was worth doing, and the credit goes to a lot of people coordinating across ten countries, which is a good deal harder than anything technical that appears here. Dmitry Volkov, CEO of Group-IB, put it this way: "Servers can be replaced in weeks; the people who build the platform and approve every attack cannot. Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end." Our honest caveat is a different one, and it does not contradict him: the leak site is down and the market is not. The $250 fee was one supplier's door, not the market's, so removing one supplier does not raise anybody's cost of entry.
Nor are we telling you that you need to stand up a security operations centre. Conflict of interest up front: we sell exactly this work, so read what follows with that suspicion in place. If your company has fifteen people, you do not need your own SOC or four consoles nobody looks at; you need the doors shut, backups somebody has actually restored at least once, and a person —yours or outsourced— who finds out if something odd happens at three in the morning on a Tuesday. And a good part of the inventory above you can run yourself this week without paying anyone, starting with the private browser window.
Sources (verified on 3 October 2026): the tally of the action —date, arrests, searches, servers, 110 TB and joint investigation team— and the description of the modus operandi come from the statements by Europol and Eurojust (01-10-2026); the count of ten participating countries and the Hamburg authorities' lead on the investigation come from Europol and Group-IB, while the Eurojust release says nine countries. Operation ROTOMA, the cooperation with the FBI in San Juan, Puerto Rico, the two Alicante searches, the material seized, the detainee's profile, the cyberattack on the Catalan organisation with its estimated damage, and the figures of 1,000 attacks, 500 successful, 280 victims and 500,000-euro ransoms come from the official Guardia Civil statement (01-10-2026). The $250 fee, the 88/12 split raised to 20 % with a $1,000 deposit in January 2025, the Tor panel, the build approval, the November 2024 ESXi locker, the data sale prices, the four initial access vectors and the share of victims with no network intrusion come from the Group-IB statement, which supported the operation and is also the source of the Dmitry Volkov quote. The caveat that the successful-attack figure may change, the June 2024 platform launch and the use of AI tools come from the coverage of those statements in Risky Business and Security Affairs. The two per-terabyte averages, reading the age as a barrier to entry, and the inventory of checks are ours, not those sources'.
What answers on your public IPs today?
If the answer comes from the inventory rather than from a scan run outside, it is not an answer. We work on cybersecurity where people actually get in —cloud storage with no open doors, exposed surface, published applications with an owner— and on managed detection and response for the part you cannot avoid: having someone read what your logs say before an authority calls you.
Talk to everyWAN