Spanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware Group
Key Takeaways
- •A 16-year-old Romanian national arrested in Alicante, Spain, is suspected of serving as the administrator and main operator of the KillSec ransomware group.
- •Operation KillSwitch, led by the Hamburg State Criminal Police Office and public prosecutor, is investigating around 1,000 suspected attacks worldwide, of which about 500 have been identified as successful.
- •Authorities have taken control of five central servers, redirected the group's domains to a seizure notice, and secured at least 110 terabytes of stolen data.
- •Investigators found that KillSec used double extortion, cryptocurrency ransom demands, and artificial intelligence to build and maintain its infrastructure and identify potential victims.
- •A Dutch national resident in the UK, indicted by a federal grand jury in Puerto Rico, faces US charges carrying a maximum penalty of 10 years and potential extradition.

Spanish police have arrested a 16-year-old Romanian national in Alicante suspected of serving as the administrator and main operator of the KillSec ransomware group, part of a coordinated international operation in which authorities seized the gang's servers and leak site and secured at least 110 terabytes of stolen data, Europol said.
The teenager is suspected of acting as the group's administrator, a Europol spokesperson told Reuters. Two other people in their twenties were arrested, one in Britain and one in Romania. A fourth suspect, a developer who turned 18 in August and who was a minor when some of the offences were committed, has been identified but not arrested. Taken together, the alleged roles spanned administrator, developer and negotiator — a division of labour that runs through modern ransomware crews, which tend to split malware development, victim negotiation and day-to-day administration among specialists.
The September 30 action was part of Operation KillSwitch, an investigation led by the Hamburg State Criminal Police Office and the city's public prosecutor into around 1,000 suspected attacks worldwide, of which about 500 have so far been identified as successful. Eight properties were searched in Spain, Greece, Romania and the UK.
The suspect held in Britain faces charges in the United States. Fouad Eltibrizi, a Dutch national resident in the UK who used the handle Archduke, was indicted by a federal grand jury in Puerto Rico on September 16 over conspiracy to access computers without authorization for financial gain, damaging protected computers and transmitting extortion threats, according to the U.S. Department of Justice. He was arrested in the fortnight that followed and faces extradition, with a maximum penalty of 10 years. Whether that extradition proceeds, and whether the fourth suspect is ever taken into custody, are among the threads the September 30 action left open.
The FBI Cyber Division announced the action on X as a “joint sequenced operation” led by its San Juan field office targeting the Kill Security Ransomware Group (“KillSec”):
Today we're announcing Operation KillSwitch, a joint sequenced operation led by @FBISanJuan targeting the Kill Security Ransomware Group (“KillSec”). Authorities in the U.S. and Europe took control of KillSec's leak site, securing at least 110 terabytes of data against further… pic.twitter.com/ZYvxosEPyv
— FBI Cyber Division (@FBICyberDiv) October 1, 2026
U.S. prosecutors say KillSec posted a Puerto Rico breach on its leak site in March 2025, complete with samples of stolen patient data and a seven-day countdown. When the company did not respond, roughly 180GB of data were published. The indictment describes similar breaches in California, Washington State and Louisiana.
KillSec and crypto
KillSec has been active since around 2024, exploiting software vulnerabilities and poorly secured access points, particularly to cloud storage, to reach organizations' systems and copy internal data to infrastructure it controlled, Europol said in a statement. Victims were named on the group's dark web leak site and threatened with publication unless they paid, with files released for free download where no payment came.
The group used double extortion, encrypting servers and then threatening to publish the data if a company declined to pay on the grounds that it had backups, Switzerland's federal police said. Ransoms were often demanded in cryptocurrency. Swiss prosecutors have been investigating the group since July 2025 over attacks on Swiss companies between October 2023 and June 2025.
Investigators also found that KillSec had used artificial intelligence to build and maintain its ransomware infrastructure and to identify potential victims.
Five central servers are now under police control, and domains linked to the group have been redirected to a seizure notice. Investigators are examining seized devices and tracing the group's criminal proceeds, including cryptocurrency, work that Europol's European Cybercrime Centre supported with specialist crypto-tracing and digital forensics. Such tracing is possible because cryptocurrency payments leave records on public blockchains, allowing analysts to follow funds as they move between wallets — one reason crypto remains a focal point of ransomware investigations even after a takedown.
In the UK, where 28 victim companies have been identified, officers from the Eastern Region Special Operations Unit arrested a 25-year-old suspected of negotiating with victims at an address in Levenshulme, Manchester. “Ransomware causes significant financial losses, operational disruption and harm to public confidence,” Detective Sergeant John Collinson of the unit's cyber crime team said.