Police disrupt KillSec ransomware, arrest suspected teenage leader

Spanish police announced the arrest Thursday of the 16-year-old suspected leader of the KillSec ransomware group as part of an international operation that also saw the seizure of the group’s leak site and infrastructure.
Catalan authorities, alongside the Civil Guard’s cybercrime unit, arrested the minor in the town of Alicante. According to Reuters, he is a Romanian national.
Police raided eight houses as part of the operation, in Greece, Romania, Britain and Spain, and seized five servers allegedly used to manage the group’s activities and store stolen data. Two other arrests were made, police said.
Police in the U.K. also arrested Dutch national Fouad Eltibrizi, who allegedly goes by “Archduke” online. He was indicted by a U.S. federal grand jury in the District of Puerto Rico on September 16 and charged with unauthorized computer access conspiracy, the Department of Justice said. He is awaiting extradition to the U.S.
Since it emerged in 2024, KillSec has launched around 1,000 attacks, at least half of which were successful, authorities said. The group exploited vulnerabilities, especially in cloud storage, in order to infiltrate systems and extract sensitive data. Victims were listed on the group’s leak site and extorted with the threat of the release of data.
Police in Hamburg, where the operation was based, said authorities in several countries began investigating the group in early 2025 following attacks. They were able to identify at least four suspected members and are investigating others. One suspected developer turned 18 in August, they said.
The European Cybercrime Centre, an entity created by Europol for cross-border coordination, provided insights into the group and technical support. The cybersecurity companies BitDefender and Group-IB were also involved in the investigation, as well as police in Switzerland, the U.K., U.S., Romania, Spain, Greece, the Netherlands, Finland and Belgium.
According to the cyber firm Halcyon, KillSec offered one of the most affordable ransomware-as-a-service platforms in the ecosystem. Its Tor-accessible control panel including chat functionality and custom ransomware tools allowed cybercriminals with limited technical skills to carry out attacks. Their compromise of cloud security vulnerabilities was spread among healthcare companies, government entities, financial services firms, and others.
References in this story
- Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site – Three arrests… www.europol.europa.eu On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with…
- www.justice.gov
- POL-HH: 261001-3. Teenager steht im Verdacht, KillSec-Ransomware-Gruppe angeführt zu haben - Strafverfolgungsbehörden… www.presseportal.de Hamburg (ots) - Zeit: 30.09.2026 Orte: weltweit Drei Festnahmen und acht Durchsuchungen in vier europäischen Ländern bei internationaler Operation gegen eine...
- KillSec www.halcyon.ai
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- James Reddick (@jredd66) on X twitter.com Audio and print journalist in Boston. Currently editing @therecord_media. Bylines: @capradio @mmfa @snapjudgment Previously in Cambodia @phnompenhpost



