NewsCryptoSpanish Police Arrest 16-Year-Old Suspected of Leading KillSec Ransomware Group

Spanish Police Arrest 16-Year-Old Suspected of Leading KillSec Ransomware Group

Author: CryptoMeter io·

Key Takeaways

  • •Spanish police detained a 16-year-old Romanian national in Alicante who is suspected of serving as the administrator of the KillSec ransomware group, which has been linked to roughly 1,000 attacks worldwide.
  • •The coordinated operation spanned Spain, Greece, Romania and the United Kingdom, resulting in three arrests and eight searches.
  • •KillSec allegedly used double extortion, copying victims' sensitive data and demanding cryptocurrency payments while threatening to publish the stolen information if victims refused to pay.
  • •Investigators seized cryptocurrency wallets and identified transactions matching ransom payments, using permanent blockchain records to trace how ransom funds moved after payment.
  • •Authorities took control of KillSec's infrastructure, including servers containing about 110 terabytes of data, while a Puerto Rico extradition request and separate U.S. charges against a Dutch national remain pending.
Spanish Police Arrest 16-Year-Old Suspected of Leading KillSec Ransomware Group

Spanish authorities have arrested a 16-year-old Romanian national accused of acting as the main operator of KillSec, a ransomware group linked to roughly 1,000 attacks worldwide, as part of an international investigation spanning several European countries.

According to investigators, KillSec compromised targeted organizations by exploiting software vulnerabilities and poorly secured access points, with cloud storage a particular weak spot. The group allegedly copied sensitive data before demanding cryptocurrency payments, threatening to publish the stolen information if victims refused to comply — a pressure tactic known as double extortion that has become a mainstay of ransomware operations, because stolen data keeps the pressure on even when victims can restore encrypted systems from backups.

Tracing the money has become a central thread of the probe. Spanish police said officers seized cryptocurrency wallets during searches and identified transactions that appear to match ransom payments made by some victims. Because most cryptocurrency payments leave permanent records on public ledgers, seized wallets and transaction matches can show investigators where ransom funds moved after payment.

Coordinated crackdown across four countries

The operation produced three arrests and eight searches across Spain, Greece, Romania and the United Kingdom. A second suspect, arrested in Britain, faces an extradition request from Puerto Rico, where U.S. authorities have separately charged a Dutch national over alleged KillSec-related cyberattacks. A third suspect was detained in Romania. Those cross-border legal steps — the extradition request and the separate U.S. charges — remain pending and could shape where alleged KillSec members ultimately face prosecution.

Investigators have also identified a developer who turned 18 in August but was allegedly a minor when some of the suspected offenses occurred. That individual has not been arrested.

Reuters reported that the 16-year-old was detained in Alicante and is suspected of serving as KillSec's administrator. Authorities have not publicly identified the teenager.

Crypto proceeds remain under scrutiny

Spanish investigators seized computer equipment, mobile phones, cryptocurrency wallets and tools designed to conceal activity. The evidence could help authorities trace how ransom payments moved through crypto wallets and identify additional participants or assets connected to the alleged operation.

Europol said KillSec obtained substantial ransom payments from victims and also ran a leak site where it threatened to publish stolen information when organizations refused to pay.

Authorities have taken control of KillSec's infrastructure, including servers containing about 110 terabytes of data. The investigation remains ongoing as law enforcement agencies examine the group's suspected attacks, proceeds and wider network, according to CryptoMeter io.