Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024, Europol and the Justice Department said Thursday.
Investigators said the alleged leader of the group is 16 years old, but declined to name them. One of the group’s accused members, Fouad Eltibrizi, was arrested Wednesday in the United Kingdom and awaits extradition to the United States, the Justice Department said.
The Dutch national, who is accused of acting as a negotiator for the group, was indicted last month in Puerto Rico and faces up to 10 years in prison for unauthorized computer access conspiracy. Europol said a suspected developer involved in the group committed multiple crimes before they turned 18 in August.
The arrests were part of “Operation KillSwitch,” a globally coordinated operation aided by 10 countries and private cybersecurity companies. Officials seized KillSec’s data-leak site and at least 110 terabytes of data, including information on the group’s criminal proceeds.
Law enforcement’s accumulated actions targeting KillSec’s infrastructure and people involved “imposed serious cost and degraded the adversary’s core capabilities,” the FBI’s Cyber Division said in a statement on X.
“We have undermined the group’s ability to rebuild, limited their operational reach and reduced the likelihood of future attacks,” the FBI added.
Europol said investigators gained control of domains and five central servers, including infrastructure the group used to manage its activities and store stolen data.
The cybercrime group, which was also known as Kill Security Ransomware Group, exploited various defects to intrude victims’ computers or cloud-based network infrastructure and steal sensitive data for extortion demands. Officials said the group obtained substantial ransom payments in some cases.
Officials from the United States and Europe searched eight residences in Spain, Greece, the United Kingdom and Romania, and investigators are looking through evidence seized during those raids to identify other potential members of the group.
Some of the group’s victims were identified by initials and the location and date of the attack in the indictment filed against Eltibrizi. This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
Three of those victims align with organizations that were listed on KillSec’s data-leak site for Instituto de Ojos, US BioTek Laboratories and Accelerated Academy.
Prosecutors accuse Eltibrizi, who allegedly participated in the conspiracy from at least March through November 2025, of placing calls as a KillSec representative in at least one of those extortion demands.
“The defendant and his co-conspirators carried out targeted intrusions against multiple companies and organizations, stealing highly sensitive information and attempting to extort their victims for substantial sums of money,” Héctor Ramírez‑Carbó, acting U.S. attorney for the District of Puerto Rico, said in a statement.
“Ransomware remains a serious and evolving threat to all sectors of our economy, from critical infrastructure to small businesses,” he added.
Latest Podcasts
Government
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Technology
New bill would create federal investigative body for AI-driven hacks
CISA outlines improvement plan for CVE program
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
Citing China, President Trump doubles down on hands-off approach to AI regulation
Threats
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Kiteworks lifts shutdown advisory after 'credible threat intelligence' from federal authorities
Policy
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
The president has called for AI leadership. Here’s the mission.
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
Originally published by CyberScoop. © CyberScoop. Written by Matt Kapko.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-01 19:44 UTC
Related stories
- Alleged KillSec Ransomware Mastermind a 16-Year-Old
Dark Reading · 2026-10-01
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
The Hacker News · 2026-10-01
- Police disrupt KillSec ransomware, arrest suspected teenage leader
The Record · 2026-10-01
- State-linked actor targets US AI policy experts in credential phishing campaigns
Cybersecurity Dive · 2026-10-01