Police suspect a 16-year-old was the main operator of KillSec, a ransomware group linked to around 1,000 suspected attacks worldwide.
Authorities announced on Thursday that an international operation had seized the group’s infrastructure and made three provisional arrests. The German-led Operation KillSwitch replaced the crew’s leak site with a police seizure notice.
The available information is incredibly fragmented. Europol said the 16-year-old was “the group’s suspected main operator,” but did not explicitly say this person was arrested.
Spanish police announced the arrest of a “minor,” a Romanian national residing in Spain, but did not publicly link this arrest to the 16-year-old mentioned by Europol.
The US Department of Justice (DoJ) said UK police had arrested Dutch national Fouad Eltibrizi, whom it has charged over alleged cybercrimes in the US and Puerto Rico. It is seeking his extradition.
Eltibrizi is the only suspect officials have publicly named. Europol told The Register he was allegedly one of KillSec’s negotiators.
Authorities have not named the suspected 16-year-old operator.
Romanian police (Poliția Română) said a 24-year-old helped establish KillSec in October 2023, although other authorities date the group’s formation to 2024. Their statement did not specify whether that person was arrested.
Officials separately confirmed to The Register that a Romanian national in his twenties was arrested in Romania on suspicion of acting as a KillSec affiliate.
Europol also identified a suspected developer who turned 18 in August and was a minor when some of the alleged offenses were committed.
Spanish police referenced a woman who remains under investigation in connection to the case, but was not arrested.
The coordinated raids took place on September 30, following investigations that began in early 2025.
Ten police agencies from Europe and the US took part, with officers raiding eight properties across Greece, Romania, Spain, and the UK.
Spanish police said officers raided a home and an office in an Alicante hotel, while Poliția Română searched four homes. Neither Greece nor the UK has released information about their involvement in the operation.
Authorities secured at least 110 TB of data on KillSec’s leak site against further unauthorized access. Investigators are examining seized devices and data to identify victims, attacks, and suspects, and trace the group’s criminal proceeds.
Over the course of the investigation, police took control of five central servers used to manage the group’s activities and store victims’ data.

Security shops Bitdefender and Group-IB also supported the investigation.
KillSec uses double extortion, encrypting victims’ systems and threatening to publish stolen data unless they pay.
Group-IB recently included KillSec, also referred to as “Kill Security” and “k1llsec,” in its 2025 top 10 rankings for ransomware groups operating in APAC, LATAM, and the Middle East.
The company’s researchers said KillSec most commonly preyed on financial services and healthcare organizations, but was known to attack government entities and large enterprises.
Group-IB said KillSec also offered stolen data for sale at prices ranging from $5,000 to $500,000.
“Servers can be replaced in weeks; the people who build the platform and approve every attack cannot,” said Group-IB CEO Dmitry Volkov. “Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end.”
KillSec initially offered a Windows encryptor before adding a version capable of encrypting VMware ESXi hosts, deleting data, shutting down VMs, and removing recovery points. ®
Click Here For The Original Source.
