Skip to main content

Press releasePublished on 1 October 2026

Cybercrime: Computer network used by ransomware group dismantled in coordinated international operation

Bern, 01.10.2026 — On 30 September, an international large-scale operation resulted in the dismantling of IT infrastructure used by the “KillSec” ransomware group. The Federal Office of Police fedpol and the Office of the Attorney General of Switzerland (OAG) were directly involved as operational and strategic partners.

Since 31 July 2025, the OAG has been conducting criminal proceedings against persons unknown on suspicion of data theft (Art. 143 Swiss Criminal Code (SCC), unauthorised access to a data processing system (Art. 143bis SCC), damage to data (Art. 144bis SCC), and extortion (Art. 156 SCC) following a series of ransomware-type cyber-attacks carried out against several Swiss companies by the ransomware group KillSec (or “KillSecurity”) between October 2023 and June 2025.

Ransomware attacks involve the perpetrators gaining unauthorised access to the victim’s computer system, copying and exfiltrating valuable data, then encrypting the servers before demanding a ransom in exchange for the decryption key. Payment of the ransom in cryptocurrency is often demanded. Like other ransomware groups, KillSec employs a type of attack known as “double extortion”: after encrypting the victim company’s servers, if the company refuses to pay the ransom, for example, because it had backed up the data before it was stolen, the perpetrators threaten to publish the data on the darknet.

In this particular case, the OAG and fedpol participated in international investigations, coordinated by Europol and Eurojust, alongside seven other countries. A takedown operation was organised by these European agencies and carried out on 30 September. The operation resulted in the arrest of three individuals, as well as the seizure of evidence and assets. Eight searches were carried out in Spain, Greece, the United Kingdom and Romania. The authorities were thereby able to recover at least 110 terabytes of stolen data. In particular, they seized five servers used by the group to store data belonging to its victims.

Given the international nature of cybercrime, close cooperation among the various partners is essential, both at national and international levels. The action was preceded by extensive investigative work conducted by fedpol under the direction of the OAG. Working closely with the cantonal police forces and the National Cyber Security Centre (NCSC), fedpol investigators gathered and analysed detailed information on the network’s modus operandi. They also coordinated the exchange of information with foreign partners, thereby contributing to the operation’s success.

The fight against cybercrime not only aims to identify the perpetrators and bring them to justice, but also to restrict their activities and dismantle their infrastructure. Seizing servers and data disrupts network operations, thereby limiting the perpetrators’ ability to pursue their criminal activities; it also allows new evidence to be gathered that may help identify cybercriminals and better understand the role and degree of involvement of the various actors.

The presumption of innocence applies to all the parties involved in these proceedings. The OAG is not in a position to provide any further information on the ongoing criminal investigation at present.

Despite the blow dealt to this cybercriminal network, investigations conducted by the OAG and fedpol are continuing. The authorities remain fully committed to identifying the perpetrators of cybercrimes, apprehending them, and, if they are located abroad and circumstances permit, securing their extradition to Switzerland, as has already been the case in several instances. They are also working to secure their criminal convictions.

The NCSC would reiterate the importance of reporting cyberattacks and filing complaints in order to enhance the effectiveness of these investigations and contribute more broadly to the fight against cybercrime. Cyberattacks are not simply a problem for strategically important companies: everyone, whether a public entity, a business or an individual, is a potential target. All individuals and organisations that are victims of a cyberattack are therefore urged to report the incident to the relevant authorities or to file a complaint directly with the police or the Public Prosecutor’s Office.

Links

Ransomware
National Cyber Security Centre