Europe Arrests Suspected KillSec Leader in Ransomware Probe | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Spanish and EU authorities have arrested three suspects and seized servers, domains, cryptocurrency assets, and at least 110TB of data in Operation KillSwitch, an international investigation into KillSec, a ransomware group suspected of carrying out around 1,000 attacks worldwide. Investigators identified a 16-year-old Romanian national in Spain as the group’s suspected main operator.

 

A 16-year-old suspected of serving as the main operator of the KillSec ransomware group was arrested in Alicante, Spain, as authorities across the European Union moved against an infrastructure linked to around 1,000 suspected cyberattacks worldwide. The coordinated operation, conducted on Sept. 30, 2026, resulted in three provisional arrests and eight searches across Spain, Greece, Romania, and the United Kingdom. Authorities also took control of KillSec’s leak site and secured at least 110TB of data from further unauthorized access.

The operation, led by German authorities and coordinated through Europol and Eurojust, illustrates the increasingly international structure of ransomware investigations, where identifying individuals is only one part of disrupting criminal operations.

KillSec has been active since approximately 2024 and is suspected of targeting organizations by exploiting software vulnerabilities and poorly secured access points, particularly those connected to cloud storage. Once inside an organization’s systems, the group allegedly copied sensitive information and moved it to infrastructure under its control. Victims were then listed on KillSec’s dark web leak site and threatened with the publication of stolen data unless they paid a ransom.

If a victim refused to pay, the stolen files could be made available for free download. Investigators say the group obtained substantial ransom payments, with Spanish authorities identifying cryptocurrency transactions associated with ransom payments from some victims.

The scale of the investigation remains subject to change. Authorities have so far identified around 1,000 suspected attacks, approximately 500 of which are believed to have been successful, involving more than 280 victims. The group also allegedly used AI to build and maintain parts of its ransomware infrastructure and identify potential victims, adding another layer to an operation that combined data theft, extortion, cloud exploitation, and cryptocurrency payments.

The investigation has identified suspected roles including an administrator, developer, negotiator, and affiliate.

Spanish Investigation Traced Suspected Administrator to Alicante

The Spanish investigation, known as Operation ROTOMA, began in 2025 through cooperation between the Guardia Civil and the FBI’s San Juan Field Office. Investigators from the Guardia Civil’s Central Operative Unit Cybercrime Department reportedly identified a suspected KillSec administrator living in Alicante using only a profile image. The investigation was later combined with a separate inquiry by the Mossos d’Esquadra into a suspected KillSec attack against a Catalan organization.

According to Spanish authorities, the attack involved unauthorized access to company systems, the theft of sensitive information, and an attempted extortion campaign. The estimated damage was close to €1 million (US$1.13 million). A joint investigation team between the Guardia Civil and Mossos d’Esquadra helped investigators identify the suspect, locate his residence, and establish his alleged role as one of KillSec’s main administrators. 

The suspect arrested in Alicante is a Romanian national and was 16 years old at the time of the operation. A woman was also investigated in Spain for her alleged connection to the case. Authorities searched a residence and an office located in a hotel establishment in Alicante. They seized computer equipment, mobile phones, cryptocurrency wallets, and tools associated with anonymization and information encryption.

The investigation has also identified a suspected developer who turned 18 in August 2026 and was a minor when some of the alleged offenses occurred.

Law Enforcement Targets KillSec’s Infrastructure

Operation KillSwitch focused not only on suspected members of the group but also on the infrastructure supporting its activities. Authorities brought five central servers under police control, including infrastructure allegedly used to manage the group’s operations and store stolen data. They also seized domains operated by KillSec and redirected visitors to an official law enforcement notice.

The intervention secured at least 110TB of data and gave investigators access to digital evidence that could help establish additional victims, attacks, and individuals connected to the group. Authorities are also tracing suspected criminal proceeds, including cryptocurrency assets. The seized devices and data remain under examination, meaning the scope of the investigation could expand.

The operation involved authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States. Europol and Eurojust coordinated different aspects of the international investigation, while cybersecurity companies Bitdefender and Group-IB provided technical support.

Europol’s European Cybercrime Centre supported the analysis of the group’s activities and digital evidence, while the Joint Cybercrime Action Taskforce helped coordinate law enforcement efforts. Eurojust supported judicial coordination and the execution of measures across multiple jurisdictions.



——————————————————–


Click Here For The Original Source.

.........................