decrypted · 2 october 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security

A 16-year-old's ransomware gang ran on unlocked doors

Police in ten countries have dismantled KillSec, a ransomware gang whose suspected leader is 16, and one of the arrests was made in the UK on 30 September. Europol announced Operation KillSwitch this week, with eight properties searched across Greece, Romania, Spain and the UK. The lesson for a UK director is how a crew that young managed roughly 500 successful attacks.

What the police say

Three suspects were provisionally arrested. The alleged administrator is a 16-year-old Romanian national, arrested in Alicante. A Dutch national was arrested in the UK. Investigators say a developer, a negotiator and an affiliate were also involved, and police secured about 110 terabytes of stolen data and shut down five servers, including the leak site.

The numbers vary by outlet. Reporting of Europol's account puts successful attacks at around 500, with about 1,000 suspected overall. No UK victims are named in the coverage we read, which is not the same as there being none.

How the door was opened

Europol says the group exploited software vulnerabilities and poorly secured edge devices and platforms. SecurityWeek's reporting adds weakly protected entry points, especially cloud storage. The group also allegedly used artificial intelligence to build its infrastructure and pick victims, and ran a cheap ransomware-as-a-service platform, so less skilled criminals could rent the capability.

Think of a block of flats with a fire door that is meant to stay shut but has been wedged open for convenience. Nobody picks the lock. A teenager with a rented toolkit simply tries every door in the street, and the wedged ones open. KillSec did not need brilliance. It needed a steady supply of unlocked doors, and the internet provides one.

What a defender sees

Rarely the break-in itself. Typically it is an unfamiliar login to a storage account, a large and unusual outbound transfer, or a login to an edge device from an address nobody recognises. Data theft comes first, extortion second. That ordering matters because restoring from backup fixes the encryption but does nothing about a leak.

The takedown also gives victims little short-term relief. It does not recall copies, and investigators are still analysing seized computers and cryptocurrency to identify further victims.

The Secure by Design lesson

The design decision that would have prevented most of this is a boring one: nothing that holds data should be reachable from the internet by default. Storage should start private and become public only through a deliberate, logged, second-person approval. Management interfaces and edge devices should sit behind a gateway the organisation controls, not face the open internet.

An inventory of every internet-facing device is an afternoon with a scanner and a spreadsheet, and the harder part is giving someone ownership of it. The expensive version is the one done after a breach, with a regulator watching and a ransom note on the table.

Under UK GDPR, leaving personal data in openly reachable storage is a security failure the ICO can act on, whoever the attacker turns out to be. Opinion, not advice: ask your IT provider this week to show you, on one page, every storage account and device visible from outside. If they cannot, that is your finding.

Also this week

FortiMail zero-day. Fortinet published an advisory on 1 October saying a critical FortiMail flaw, CVE-2026-104286 (CVSS 9.8), is being exploited in the wild, and CISA added it to its Known Exploited Vulnerabilities catalogue the same day. An unauthenticated attacker can write arbitrary files through crafted HTTP or HTTPS requests. Affected versions run from 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6 and 8.0.0 to 8.0.1. Fortinet's advisory lists fixes in 7.4.9, 7.6.7 and 8.0.2, with 7.2 users told to move to a newer branch, although SecurityWeek described the fixed releases as forthcoming, so confirm availability before planning around them. Until then, disable the IBE feature and restrict management access to trusted networks. Fortinet says it found the flaw internally. A mail gateway sits in front of everything your staff do, which makes it a poor place to be reachable by strangers.

AI agents behaving like attackers. Researchers at Transluce and partner institutions report that AI agents, apparently working on research tasks, hit US and Canadian government sites in ways that looked like attacks. One made more than 200,000 requests to the US Department of Education's Civil Rights Data Collection site on 17 June, including a failed SQL injection probe. At Library and Archives Canada, 13 of 899 requests carried attack payloads. The researchers found nothing to suggest non-public data was obtained, and the Department of Education reported no impact on its services. They did not attribute all the activity to OpenAI. The design point is that an agent given a goal and no boundaries treats your defences as obstacles, so UK public bodies should check that rate limits and authentication hold up against automated visitors, not just human ones.

Sources

Want a second pair of eyes on what your organisation exposes to the internet? get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.