Stamp amser presennol: 01/10/2026 16:18:25
OedRhybuddDienwApeliadauCeisiadauGwneud cais neu GofrestruAmlinelliad ardalSaeth i lawrSaeth i'r chwithSaeth i'r ddeSaeth i fynyDrysau AwtomatigSaeth yn ôlBusnesCalendrArian parodSaeth i lawrSaeth i'r chwithSaeth i'r ddeSaeth i fyny[Missing text '/SvgIcons/Symbols/Titles/icon-chrome' for 'Welsh (United Kingdom)']ClocCaucysylltuCyfarwyddiadauDogfenLawrlwythoLluniaduCyffurEhanguDolen allanolFacebookHoffi ar FacebookSylw ar FacebookMath ffeil diofynMath ffeil DOCMath ffeil PDFMath ffeil PPTMath ffeil XLSCyllid[Missing text '/SvgIcons/Symbols/Titles/icon-firefox' for 'Welsh (United Kingdom)']Cymorth cyntafFlickrTwyllRhoi adborthBydCi tywysIechydNam ar y clywDolen AnwythoGwybodaethInstagramIntercom[Missing text '/SvgIcons/Symbols/Titles/icon-internet-explorer' for 'Welsh (United Kingdom)']GliniadurLifftLinkedinGweithgarwch lleol[Missing text '/SvgIcons/Symbols/Titles/icon-location' for 'Welsh (United Kingdom)']UchelseinyddCownter iselPostMapPin MapAelodaethDewislenDewislen[Missing text '/SvgIcons/Symbols/Titles/icon-microsoft-edge' for 'Welsh (United Kingdom)']Pobl ar gollNam symud o gwmpasCenedligrwyddPwyntydd gogleddRadiws un milltirTrosolwgTudalennauAwyren bapurParcioPDFFfônPinterestChwaraeCadair dreigloAdnewydduRiportioCaisAilddechrau[Missing text '/SvgIcons/Symbols/Titles/icon-rotate-clockwise' for 'Welsh (United Kingdom)']Rss[Missing text '/SvgIcons/Symbols/Titles/icon-safari' for 'Welsh (United Kingdom)']ChwilioRhannuIaith arwyddionSnapchatDechrau etoYstadegauYstadegau a chyngor ar atalStopioTanysgrifioTargedTatŵsDweud wrthon ni amTicTumblrPedair awr ar hugainHoffi ar TwitterAteb ar TwitterAildrydar ar TwitterLanlwythoNam ar y golwgWhatsappCadair olwynionCymorth cadair olwynionParcio i gadair olwynionRamp i gadair olwynionTŷ bach i gadair olwynionYoutubeChwyddo mewnChwyddo allan

Cookies

We use some essential cookies to make our website work. We’d like to set additional cookies so we can remember your preferences and understand how you use our site.

You can manage your preferences and cookie settings at any time by clicking on “Customise Cookies” below. For more information on how we use cookies, please see our Cookies notice.

Accept cookies Reject cookies Customise cookies

Your cookie preferences have been saved. You can update your cookie settings at any time on the cookies page.

Your cookie preferences have been saved. You can update your cookie settings at any time on the cookies page.

Mae’n ddrwg gennym, roedd problem dechnegol. Rhowch gynnig arall arni.

Neidio i’r prif gynnwys

Neidio i’r prif lywio

rocu-header-logo-420

  • Ein gwaith ni
  • Ein rhwydwaith cenedlaethol
  • Yn ôl i Galluoedd

    • Troseddau economaidd
    • Seiberdroseddau
    • Rhwydwaith Deallusrwydd Asiantaethau’r Llywodraeth (GAIN)
    • Rheoli troseddwyr
    • Ymchwiliadau
    • Deallusrwydd
    • Tackling Organised Exploitation (TOEX)
  • Yn ôl i Newyddion

    • ERSOU supports international takedown of global ransomware network
  • Gyrfaoedd
  • Riportio

ERSOU supports international takedown of global ransomware network

Cynnwys y prif erthygl

ERSOU Newyddion
Cyhoeddwyd: 14:45 01/10/2026
Banner_ operation_ KS

Multiple arrests have been made across Europe during a coordinated operation against global ransomware networks, supported by the Eastern Region Special Operations Unit (ERSOU).

On Wednesday 30 September 2026, officers from ERSOU's Cyber Crime Unit joined law enforcement partners from nine countries to arrest key members of an alleged organised criminal gang and seize infrastructure linked to KillSec, a dark web leak site used to extort victims and publish stolen data.

Active since around 2024, KillSec is alleged to have threatened organisations with the release of stolen files unless a ransom was paid.

It is believed criminals gained access to victims’ systems by exploiting software vulnerabilities and poorly secured access points, before copying sensitive data to infrastructure under its control.

Those targeted were reportedly listed on the KillSec site and threatened with publication of their data unless payments were made.

In cases where no ransom was received, stolen files could be released for free download. KillSec is alleged to have been used to secure substantial payments with ransoms demanded in the millions.  

Dark web developer and negotiator among arrests

An international investigation, known as Operation KillSwitch, is being led by German authorities and relates to around 1,000 suspected attacks worldwide. This includes 28 victim companies across the UK.

Alongside ERSOU, the enforcement activity has involved several European law enforcement agencies, supported by Europol, Eurojust and authorities from the United States.

It took place at eight properties throughout Greece, Romania, Spain and the UK. 

Three suspects were arrested during searches, which also led to the seizure of evidence and assets.

Those detained include a suspected administrator and principal operator of KillSec, as well as an alleged developer.

ERSOU officers have led part of the investigation into a 25-year-old man, suspected of acting as a negotiator between the criminal group and its victims.

He was arrested at an address in the Levenshulme area of Manchester, in activity assisted by cyber colleagues from the North West Regional Organise Crime Unit and from the Joint International Crime Centre (JICC).

The suspect is scheduled to appear at Westminster Magistrates’ Court on Thursday 1 October for an extradition hearing.

ERSOU leading role

Detective Sergeant John Collinson from ERSOU's Cyber Crime Unit, said:

“Cyber criminals involved in ransomware attacks often believe they can hide behind technology and operate beyond the reach of law enforcement. This operation demonstrates that coordinated international action can identify those responsible and disrupt the infrastructure they rely upon. “Ransomware can have a devastating impact on organisations, causing significant financial losses, operational disruption and harm to public confidence. ERSOU has been proud to play a leading role in this investigation, and this enforcement activity sends a clear message that those involved in cyber-enabled crime will be pursued wherever they are, and that law enforcement agencies across the world are committed to working together to bring offenders to justice.”

As investigations progress across multiple countries, Europol's European Cybercrime Centre have helped coordinate intelligence and operational activity.

Five central servers have now been brought under law enforcement control, including infrastructure used to manage the group's activities and store data stolen from victims.

Authorities have also seized domains operated by KillSec and redirected visitors to a law enforcement seizure notice (image above). 

Investigators are now examining seized devices and data while tracing the group's criminal proceeds, including cryptocurrency assets.

The evidence gathered may help identify further victims, offences and individuals involved in the group's activities.

Rhannu’r dudalen hon

Llywio troedyn

Amdanom ni

  • Ein gwaith ni
  • Ein rhwydwaith cenedlaethol
  • Gyrfaoedd
  • Telerau ac amodau

Cysylltu â ni

  • Riportio

Newyddion

  • Newyddion

Iaith

  • English

© Hawlfraint 2023. Cedwir pob hawl.