Key Highlights
- A 16-year-old Romanian boy was arrested in Alicante, identified as a key figure in the KillSec ransomware collective.
- A Dutch citizen residing in the UK has been indicted in Puerto Rico and is awaiting extradition.
- Investigators are working to track the group's illicit earnings, including cryptocurrency.
Spanish law enforcement has apprehended a 16-year-old believed to be the primary operator of the KillSec ransomware group. This arrest coincided with a broader operation across Europe, which led to the seizure of the group's servers and leak site, as well as the recovery of over 110 terabytes of stolen data, according to Europol.
The detained teenager, a Romanian national, was captured in Alicante and is suspected of fulfilling the role of administrator for the group, as stated by a Europol representative in an interview with Reuters. Additionally, two individuals in their twenties were arrested, one in the UK and another in Romania. A fourth suspect, a developer who recently turned 18 and was a minor during some of the alleged crimes, has been identified but remains at large.
Myriad: How high will Bitcoin go? Click to make your prediction.The actions taken on September 30 were part of Operation KillSwitch, spearheaded by the Hamburg State Criminal Police and the local public prosecutor. This investigation involves approximately 1,000 suspected cyberattacks globally, with around 500 confirmed as successful. Searches were conducted in properties located in Spain, Greece, Romania, and the UK.
The individual detained in the UK faces U.S. charges. Fouad Eltibrizi, a Dutch national residing in the UK and known online as Archduke, was indicted by a federal grand jury in Puerto Rico on September 16. He is accused of conspiring to unlawfully access computers for financial gain, damaging protected computers, and issuing extortion threats. He was arrested two weeks later and is now facing extradition, with a potential maximum sentence of 10 years.
Today we’re announcing Operation KillSwitch, a joint sequenced operation led by @FBISanJuan targeting the Kill Security Ransomware Group (“KillSec”). Authorities in the U.S. and Europe took control of KillSec’s leak site, securing at least 110 terabytes of data against further… pic.twitter.com/ZYvxosEPyv
— FBI Cyber Division (@FBICyberDiv) October 1, 2026
Prosecutors in the U.S. have linked KillSec to a breach in Puerto Rico that occurred in March 2025, where they posted samples of stolen patient data along with a seven-day countdown clock. When the targeted company failed to respond, approximately 180GB of data was made public. The indictment details similar breaches in California, Washington State, and Louisiana.
KillSec and Cryptocurrency
Since its inception around 2024, KillSec has exploited software vulnerabilities and insecure access points, particularly in cloud storage, to infiltrate organizational systems and extract internal data. Victims were publicly named on the group's dark web leak site and faced threats of data publication unless they complied with ransom demands, with files released for free download when payments were not made, according to Europol.
The group employed a strategy of double extortion by encrypting servers and then threatening to release data if victims opted not to pay, as noted by Switzerland's federal police. Ransom payments were frequently requested in cryptocurrency. Swiss authorities have been investigating attacks on Swiss firms that occurred between October 2023 and June 2025 since July 2025.
Additionally, investigators discovered that the group utilized AI to develop and maintain its ransomware infrastructure and to identify potential targets.
Five central servers are now under police custody, along with domains redirected to a seizure notice. Law enforcement officials are currently analyzing the seized devices and attempting to trace the group's illicit earnings, including cryptocurrency, with support from Europol's European Cybercrime Centre, which specializes in crypto-tracing and digital forensics.
In the UK, where 28 victim organizations have been identified, officers from the Eastern Region Special Operations Unit arrested a 25-year-old suspected of engaging with victims at a location in Levenshulme, Manchester. Detective Sergeant John Collinson from the unit’s cyber crime team emphasized that ransomware incurs "significant financial losses, operational disruption, and damage to public confidence."
