John Kindervag spent this week telling the industry that Zero Trust still holds against AI-assisted attacks. Plenty of teams will treat that as proof their architecture is ready. That reaction is the problem. Spanish police just arrested a 16-year-old suspected of running KillSec, a ransomware crew Eurojust ties to nearly 1,000 attacks since 2024. The group got in through poorly secured access, especially cloud storage. If your cybersecurity program is tuned for AI-era novelty, you are defending a story that flatters you.
You have spent budget cycles arguing about language models writing exploits. KillSec spent those same years copying files you already made reachable. Dark Reading put the victim count around 500 in two years. Help Net Security, citing Eurojust, put the attack count closer to a thousand. Either number is a failure of access hygiene, not a failure of some futuristic control plane.
The AI Panic Is Doing Your Threat Model Favors
Kindervag’s claim is narrowly true. Zero Trust, implemented as continuous verification of users, devices, and paths, does not magically collapse because someone pointed a chatbot at your login page. Implementation is the part most networks never finished. Fifteen years after the phrase entered every slide deck, a lot of “Zero Trust” still means a fancy VPN, a firewall rule with a hopeful comment, and a SaaS tenant that still honors a shared link from 2023.

AI-assisted attacks will get cheaper. That is already happening on the edges of phishing and recon. Treating that trend as the thing that decides whether your architecture works is a gift to every operator who still lives on guest links and standing service accounts. A 16-year-old did not need a research lab. The crew needed a cloud share you never treated as a privileged identity.
Same week, U.S. prosecutors took custody of an Iranian national extradited from Montenegro over dozens of university breaches and stolen academic intellectual property. Different motive, different flag. Same pattern: get in through access that already existed, take the data, leave the victim arguing about sophistication after the copy is gone. Nation-state theft and teen-run extortion are both downstream of accounts, tokens, and folders you can inventory this afternoon.
Your threat-protection stack looks busy while that happens. Dashboards light up. Threat detection fires on malware families you will never see in this incident. The actual loss is a bulk download from a storage identity that was supposed to be “just collaboration.”
KillSec’s Entire Business Was Your Cloud Share
Eurojust’s description is blunt enough that you should tape it to the SOC wall. KillSec got into organizations by exploiting poorly secured access, particularly access tied to cloud storage. Once inside, the group stole data, copied it to its own infrastructure, and threatened to publish. That is not a novel ransomware platform. That is a leak-site business sitting on top of your sync client.

Think about what “poorly secured cloud access” looks like on a real estate. A department share with “anyone with the link.” A former contractor still in the tenant. A sync account with a password that survived three helpdesk resets. An API token stuffed in a desktop app. Object storage with a public ACL someone set during a vendor demo. None of that needs brute-force against your perimeter. Some of it will still generate brute-force noise on a forgotten admin login, and you will tune that alert away because it “always does that.”
You already issued the credential they used
Remote management tools get the scary write-ups. Cloud folders get a shrug. Attackers have noticed. If a teenager can run a multinational leak operation on the back of access you provisioned for convenience, your cyber security program has an identity problem dressed up as a malware problem. Spain arrested three people on September 30 and seized the leak site and servers. Congratulations to the cops. Your files are still on a disk you do not control.
Defense in depth is supposed to mean the share, the identity, the device, and the egress path all have to fail before data walks out. In practice, a lot of estates put the entire bet on the first hop. After that, collaboration software is trusted infrastructure. KillSec’s alleged operators treated it as a loading dock.
Cybersecurity Hardening Starts With Who Can Open the Folder
You can argue architecture on Twitter. You cannot argue with a copied bucket. Security hardening for this pattern is boring, and that is why it works. Do the following in order, this week, with names and ticket numbers attached.
- Inventory every cloud share, sync root, guest link, and storage identity that can read more than one person’s files. Include personal accounts used for work, vendor tenants, and “temporary” project folders. If it is not in the inventory, assume it is in someone else’s.
- Kill standing anonymous and org-wide links. Convert remaining shares to named principals with expiry. If a vendor needs a folder, give them a scoped identity you can revoke without a change window.
- Put MFA and device checks on storage admins, sync service accounts, and API tokens. A password-only cloud admin is an extortion pre-positioning, even if your firewall never sees the session.
- Turn on bulk-download and mass-enumeration alerts, then prove they fire. Threat detection that cannot see 10,000 files leaving in 20 minutes is interior decorating.
- Restrict egress from endpoints and servers to unknown object-storage and personal-cloud destinations. Defense in depth here is identity plus path. One without the other is a blog post.
- Run a leak-site tabletop that starts after the copy has already left. Incident response for KillSec-style crews is notification, legal, restoration, and credential burn. Pretending you will intercept the first zip is how you lose a week.
Immediate work is the inventory, the dead links, and the bulk-download alert. Ongoing work is a quarterly access review that includes departed staff, dormant guest accounts, and tokens that never expire. Pair that with a monthly test: pick one high-value share, attempt a large pull from a non-standard location, and confirm someone got paged. If nobody did, you do not have threat detection. You have a log.
Brute-force controls still belong on the identity plane. Lockouts, step-up auth, and source reputation on admin logins cut off the noisy path. They will not save you if the quiet path is a valid guest link. Put the boring control next to the fashionable one, or skip the fashion.
Seizing the Leak Site Does Not Return Your Copy
Police in Spain took KillSec’s alleged leak site and servers. That is a good day for disruption. It is a terrible day to declare containment. Anyone who already paid, already dumped, or already mirrored the data is outside your ticket. Treat law-enforcement timing as public-relations weather. Your clock started when the share was readable.

Incident response for a cloud-share theft should assume parallel copies. Disable the identity. Rotate every token that identity could mint. Snapshot access logs before someone “cleans up.” Notify based on what left, not on whether a teenager is in custody. If your legal team is waiting for a brand-name malware sample, they are waiting for a prop.
Kindervag is not wrong that the model can survive AI-assisted attacks. He is talking past the incident you are actually going to have. The enemy who showed up this week was younger than your SIEM contract and less impressed by your Zero Trust roadmap. Build for that person. The language model can wait in line.
Frequently Asked Questions
- Does Zero Trust still matter if KillSec used ordinary cloud storage?
- Yes, if you apply it to the share, the token, and the device, not just the remote-access gateway. Kindervag’s point is about implementation. A storage identity with a permanent guest link is the opposite of verify-every-request.
- Should we treat a teenager-run crew as low risk?
- Age is not a control. Eurojust’s attack count and the leak-site model scale on access you already granted. Sophistication theater will waste the hours you need for inventory and revocation.
- If police seized the servers, is the incident over?
- No. Copies that already left are still copies. Your incident response work is identity kill, log preservation, victim notification, and proving the next bulk pull would page someone.
Sources
- 16-year-old suspected leader of KillSec ransomware group arrested
- Alleged KillSec Ransomware Mastermind a 16-Year-Old
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
- Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
- Iranian accused of hacking American universities extradited from Montenegro
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
