ransomware-threat-debrief

Bitdefender Threat Debrief | October 2026

Share this Share on email Share on twitter Share on linkedin Share on facebook

Operation KillSwitch Halts KillSec’s Ransomware Activity

This edition of the Bitdefender Threat Debrief covers the latest developments in the ransomware threat landscape: We have details on Operation KillSwitch, a look at how ShinyHunters’ tried to ransom a competing group, and news about which group announced the end of their ransomware operations.

As ransomware continues to evolve, our goal with this monthly Bitdefender Threat Debrief is to help you stay ahead of the curve. To do this, we combine information from openly available sources (OSINT) - things like news reports and research – with data we gather by analyzing Data Leak Sites (DLSs), websites where ransomware groups post details about their victims. We can't independently verify all these claims, but we are confident in the trends we see over time.

oct26-image1For this month's report, we analyzed data from September 1 to September 30 and recorded 790 claimed ransomware victims. This was a 30% increase vs. September 2025.

Featured Story: Operation KillSwitch Halts KillSec’s Ransomware Activity

What Happened?

On September 30, 2026, the international operation known as Operation KillSwitch, resulted in law enforcement’s seizure of KillSec’s data leak site which held more than 10 TB of data. Law enforcement also seized several of KillSec’s servers. Agencies from multiple regions, including the United States, the United Kingdom, Spain, Belgium, Switzerland, Romania, and Greece supported the takedown operation.

According to the recent publication by Europol, three KillSec members were arrested as a result; KillSec’s operator found in Spain was identified as young teen. Bitdefender began tracking Killsec in 2024 and contributed to Operation KillSwitch.

operation-kill-switch-seizure-page

How Did KillSec Catch the Attention of Law Enforcement?

KillSec started operating as a Ransomware as a Service group towards the end of the second quarter in 2024. Before emerging as a RaaS group, they also ran hacking campaigns. It’s estimated that KillSec has claimed at least 500 victims and conducted more than 1000 attacks.

Notably, the group has claimed victims in the public sector based in regions that include North America, Southern Europe, and Western Europe. KillSec’s victim demographic includes a high volume of small to mid-sized organizations. Contrary to popular belief, many of the breaches the group has conducted do not involve executing ransomware; instead, the group may scan for and exploit weaknesses in cloud platforms to identify data of interest and exfiltrate it from the victim’s system.

What is a Takedown and What Does this Mean for KillSec’s Future?

A takedown is an operation intended to seize the resources criminals use and shut down their activity. The eventual prosecution of staff and connected affiliates is a huge outcome that may result from the takedown; however, this is not always likely, especially for criminals in leadership roles who may be evasive. Operation KillSec was impactful because several KillSec Staff were identified and arrested. While some ransomware groups may collapse after a takedown, it is far more common for groups to rebrand and operate under a different moniker. Organizations should remain cognizant of this fact, regardless of outcomes that may affect KillSec or other ransomware groups in the future. The seizure of the KillSec site and servers and arrest of KillSec staff is encouraging, but it is difficult to account for other factors including hidden backup infrastructure, historical affiliate growth, and other external partnerships and resources that may remain.

What Actions are Recommended for Organizations?

Takedowns are intricate, layered processes that follow large-scale joint investigations. Organizations should not wait for law enforcement agencies to investigate before seeking additional guidance on containing or recovering from an incident. The following actions are recommended:

  • If impacted by a ransomware attack, contact law enforcement and ensure records are maintained. Victim reporting is just one way that LE can collate information on a ransomware group’s movements.
  • Remain informed about regulations and current policies concerning breach notification
  • Ensure that the digital forensic and incident response teams deployed have exercised due diligence in collecting and analyzing data relevant to the attack
  • Request and review intelligence on an ongoing basis to evaluate the threat actor’s behavior and current indicators of compromise
  • Ensure that systems are hardened-following any recovery and lessons learned phases of the incident response process to reduce opportunities for the threat actor to compromise systems again

Watch the Live Discussion

Our expert panel will cover Operation KillSwitch and other notable ransomware developments during our monthly Ctrl-Alt-Decode debrief.
Screenshot 2026-10-05 125311

Other Notable Ransomware News

Now, let’s explore the notable news and findings since the last Threat Debrief.

  • The Gentlemen rises to the top rank again: The Gentlemen has been the most active ransomware group for two of the last three months, including September 2026, when the group claimed a total of 105 victims in September. The group continues to claim victims based in regions beyond North America, including Southern Europe, South America, and Western Europe. The Gentlemen have also continued to claim victims in the manufacturing, retail, construction, technology, and healthcare industries. Known for their insistence on implementing safeguards to secure their sites, the group uses GentleCloud to protect their infrastructure against attacks and minimize opportunities to crawl their site.
  • ShinyHunters defaces Clop’s site: ShinyHunters recently compromised Clop’s dedicated data leak site after exploiting a vulnerability that allowed them to extract server logs and private keys linked to the Tor service. Clop was encouraged to contact ShinyHunters and submit a Bitcoin payment in the millions alongside an interest fee and public apology for stealing their proof of concept for campaigns leveraging Oracle E-Business Suite exploits. As a result, Clop’s victim count saw a sharp decline in September with only 2 victims claimed.
  • Citrix NetScaler vulnerability is added to the KEV catalog: Threat actors are exploiting CVE-2026-88779 to crash NetScaler ADC and Gateway devices that have logon via SAML enabled. The NetScaler ADC and Gateway devices affected include versions released prior to 14.1-73.41 and versions released prior to 13.1-64.28. NetScaler ADC 14.1-FIPS, 13.1-FIPS, and 13.1-NDcPP are also affected (versions released prior to 14.1-73.41-FIPS and prior to 13.1-37.282). Organizations using Citrix NetScaler devices with SAML enabled are advised to review the vendor documentation to ensure that the flaw is mitigated.
  • CRPx0 announces the end of their ransomware operations: The group CRPx0 updated the landing page on their data leak site with news that their infrastructure, including their source code, blog, command and control infrastructure, and negotiation platform are now for sale. Listed at $1500, this price could let criminals entering the RaaS space access a suite of tools at a low cost. According to the same post, CRPx0’s Hacking as a Service program remains available. Whether CRPx0 intends to operate under a different brand name in the near future or has joined another entity remains unclear.

Top 10 Ransomware Families

Bitdefender's Threat Debrief analyzes data from ransomware data leak sites, where groups publicize their claimed number of compromised organizations. This approach provides valuable insights into overall RaaS market activity. However, it comes with a trade-off: while it reflects attackers' self-proclaimed success, the information comes directly from criminals and may be unreliable. Additionally, this method captures the number of victims claimed, not the actual financial impact of these attacks.oct26-chart-image3

The Top 10 ransomware groups in September include The Gentlemen, Qilin, and Akira. The Gentlemen ranked first, while Qilin saw a 50% decrease in the number of victims claimed compared to the previous month.

Top 10 Most Attacked Regions

Ransomware gangs prioritize targets where they can potentially squeeze the most money out of their victims. In many cases, this means focusing on developed countries with higher projected growth rates. Threat actors may also launch strategic attacks during geopolitical conflicts or periods of social unrest.oct26-chart-image4

US victims fall significantly: While the United States continues to make up the largest demographic, fewer victims were claimed in September. Other regions saw slight decreases, and Japan ranked number 10. In September, ransomware groups claimed mostly victims in the technology industry in this region.

Top 10 Most Attacked Industries

Ransomware gangs may target organizations in critical infrastructure sectors, select other organizations that offer consumer-facing services, or attack organizations that fall into both categories. Understanding the trends and ramifications associated with specific industries, and how specialized services and clientele are impacted, is crucial for assessing risk. Here are the Top 10 industries affected by ransomware attacks.oct26-chart-image5

In September, the manufacturing industry saw a decrease in the total victim population. Education and research remained in the Top 10. Also, the transportation industry rose to the number 10 position during September.

About Bitdefender Threat Debrief

The Bitdefender Threat Debrief (BDTD) is a monthly series analyzing threat news, trends, and research from the previous month. Don’t miss the next BDTD release, subscribe to the Business Insights blog, and follow us on X. You can find all previous debriefs here.

Bitdefender provides cybersecurity solutions and advanced threat protection to hundreds of millions of endpoints worldwide. More than 180 technology brands have licensed and added Bitdefender technology to their product or service offerings. This vast OEM ecosystem complements telemetry data already collected from our business and consumer solutions. Bitdefender Labs discovers 400+ new threats each minute and validates 30 billion threat queries daily. This gives us one of the industry’s most extensive real-time views of the evolving threat landscape.

Watch and Read Ctrl Alt Decode
Watch: The Ctrl Alt Decode Live Briefing
Subscribe: The Ctrl Alt Decode Newsletter

Screenshot 2026-09-08 135120

We would like to thank Bitdefenders Stefan Hanu, Mihai Leonte, Gabriel Macovei, and Andrei Mogage for their help putting this report together.