Spain Arrests Teen Suspected of Running KillSec Ransomware | #ransomware | #cybercrime


3 Arrested as Police Seize Leak Site and US Charges Dutch Suspect

The Spanish Civil Guard detaining a suspected KillSec hacker in the province of Alicante on Sept. 30, 2026. (Image: Europol)

Spanish authorities have arrested a 16-year-old suspected of running KillSec, a ransomware operation investigators linked to nearly 1,000 cyberattacks since 2024.

See Also: 78% of Organizations Have Already Seen AI-Enabled Attacks. Are Defenses Keeping Up?

Spain’s Civil Guard and the Catalan regional police detained the teen in the Alicante province as part of a crackdown that also resulted in arrests in the United Kingdom and Romania, officials said Thursday. Federal prosecutors in Puerto Rico unsealed charges the same day against a Dutch national that they accused of conspiring with the group.

Police in 10 countries joined an effort to disrupt KillSec’s infrastructure on Sept. 30 under Operation KillSwitch, a German-led effort that Europol said went after the group’s members and its systems. Authorities seized the darkweb site KillSec used to name and pressure victims, locking down at least 110 terabytes of stolen files.

The Spanish investigation began in 2025, when the Civil Guard started working with the FBI’s Puerto Rico office to find KillSec members who might be living in Spain. A joint team with Catalan’s regional police – which had opened its own probe after an early 2025 attack on a local organization – linked the teen to the group’s administrator role.

A federal grand jury in Puerto Rico indicted Fouad Eltibrizi on Sept. 16, a Dutch national living in the U.K. who allegedly went by “Archduke,” on charges including conspiracy to access computers without authorization, damaging a protected computer and transmitting threats with intent to extort.

Eltibrizi was arrested in the U.K. on Wednesday and is awaiting extradition. He faces up to 10 years in prison if convicted.

Prosecutors allege Eltibrizi and his co-conspirators targeted victims from at least March through November 2025. In one case, KillSec gave a Puerto Rican company seven days to pay in March 2025, then published nearly 180 gigabytes of its data on the darkweb after the firm did not respond, according to the indictment.

Romanian prosecutors with the Directorate for Investigating Organized Crime and Terrorism said they detained a 24-year-old on suspicion of offenses including blackmail and illegal access to a computer system after searching homes in Bucharest and Vaslui county.

German investigators said KillSec split its work among an administrator, a developer, a negotiator and an affiliate. The suspected developer turned 18 in August and was still a minor during some of the alleged crimes, according to Hamburg police.

KillSec typically gained entry through software vulnerabilities or insecure access to cloud storage and other systems, then copied sensitive internal data onto infrastructure it controlled, Hamburg police said. Police have confirmed about 500 of the roughly 1,000 attacks as successful, a count they said could still change.

Victims that refused to pay risked having their data released for anyone to take. Police said the group collected significant ransoms in some cases and leaned on artificial intelligence to set up and run its infrastructure and to pick targets.

Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the U.K and the U.S. took part, with support from Europol, Eurojust and cybersecurity firms Bitdefender and Group-IB.

Police also said their review of seized hardware and data, along with efforts to follow the group’s cryptocurrency, could turn up more victims and suspects.





Click Here For The Original Source.

——————————————————–

..........

.

.