Police disrupt KillSec ransomware, arrest suspected teenage leader

MediumThe Record·

At a glance

Severity
Medium
Used in attacks
No flaws named
Reported by
1 outlet

Spanish police announced the arrest Thursday of the 16-year-old suspected leader of the KillSec ransomware group as part of an international operation that also saw the seizure of the group’s leak site and infrastructure. 

Catalan authorities, alongside the Civil Guard’s cybercrime unit, arrested the minor in the town of Alicante. According to Reuters, he is a Romanian national. 

Police raided eight houses as part of the operation, in Greece, Romania, Britain and Spain, and seized five servers allegedly used to manage the group’s activities and store stolen data. Two other arrests were made, police said.

Police in the U.K. also arrested Dutch national Fouad Eltibrizi, who allegedly goes by “Archduke” online. He was indicted by a U.S. federal grand jury in the District of Puerto Rico on September 16 and charged with unauthorized computer access conspiracy, the Department of Justice said. He is awaiting extradition to the U.S.

Since it emerged in 2024, KillSec has launched around 1,000 attacks, at least half of which were successful, authorities said. The group exploited vulnerabilities, especially in cloud storage, in order to infiltrate systems and extract sensitive data. Victims were listed on the group’s leak site and extorted with the threat of the release of data. 

Police in Hamburg, where the operation was based, said authorities in several countries began investigating the group in early 2025 following attacks. They were able to identify at least four suspected members and are investigating others. One suspected developer turned 18 in August, they said.

The European Cybercrime Centre, an entity created by Europol for cross-border coordination, provided insights into the group and technical support. The cybersecurity companies BitDefender and Group-IB were also involved in the investigation, as well as police in Switzerland, the U.K., U.S., Romania, Spain, Greece, the Netherlands, Finland and Belgium.

According to the cyber firm Halcyon, KillSec offered one of the most affordable ransomware-as-a-service platforms in the ecosystem. Its Tor-accessible control panel including chat functionality and custom ransomware tools allowed cybercriminals with limited technical skills to carry out attacks. Their compromise of cloud security vulnerabilities was spread among healthcare companies, government entities, financial services firms, and others.

No previous article

No new articles

James Reddick

has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment.

Originally published by The Record. © The Record.

Read at therecord.media ↗Established Source

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. The Record ↗Established SourceFirst reported

    2026-10-01 15:55 UTC

Related stories