0x20dacb9020da…20dacb93

ConfirmedSecurity558 vB126 sat/vB3 min decode

KillSec Ransomware Dismantled in Multi-Nation Operation; Teen Arrested

European and U.S. authorities arrested four suspects and seized 110 terabytes of data in Operation KillSwitch, dismantling KillSec's ransomware infrastructure across four countries.

Spanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware Group
WitnessSpanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware GroupAI-generated

Outputs

  1. 16-year-old Romanian national arrested in Alicante on September 30 as suspected KillSec administrator

  2. Fouad Eltibrizi indicted in Puerto Rico on September 16, faces up to 10 years in prison

  3. Five servers seized and 110 terabytes of stolen data secured

  4. Approximately 1,000 attacks targeted globally, with 500 confirmed successful

  5. Eight properties searched across Spain, Greece, Romania and the UK

Spanish police on September 30 arrested a 16-year-old Romanian national in Alicante suspected of serving as the administrator of the KillSec ransomware group, as law enforcement across Europe and the United States seized five servers and secured at least 110 terabytes of stolen data in Operation KillSwitch.

Investigators also detained two suspects in their twenties in Britain and Romania. A fourth suspect, a developer who turned 18 in August and was a minor when some offences took place, has been identified but not yet apprehended, Europol said.

What does the U.S. indictment cover?

Fouad Eltibrizi, a Dutch national residing in the UK who operated under the handle "Archduke," faces federal charges in Puerto Rico. A grand jury in the District of Puerto Rico returned the indictment on September 16, charging Eltibrizi with conspiracy to access computers without authorization for financial gain, damaging protected computers, and transmitting extortion threats. UK authorities arrested him within two weeks and are holding him pending extradition. The charges carry a maximum penalty of 10 years.

U.S. prosecutors say KillSec posted a Puerto Rico breach on its leak site in March 2025, publishing samples of stolen patient data alongside a seven-day countdown. When the targeted organization did not engage, the group released roughly 180GB of data. The indictment describes similar intrusions in California, Washington State and Louisiana.

How did KillSec operate?

Active since around 2024, KillSec exploited poorly secured access points, particularly to cloud storage, to copy internal data onto systems under its own control, Europol said. KillSec named victims on a dark web leak site and pressured them to pay, releasing data for free download when ransoms were not collected.

The group ran a double-extortion scheme, encrypting servers and threatening publication where victims held backups, according to Switzerland's federal police. KillSec demanded ransoms in cryptocurrency. Swiss prosecutors have been investigating since July 2025 over attacks on Swiss firms between October 2023 and June 2025.

Investigators also determined that KillSec used artificial intelligence to build and maintain its ransomware infrastructure and to identify potential targets.

What is the scale of Operation KillSwitch?

The action targets approximately 1,000 suspected attacks worldwide, of which roughly 500 have been confirmed as successful, according to the Hamburg State Criminal Police Office and the city's public prosecutor, who led the investigation alongside the FBI's San Juan field office. Officers searched eight properties across Spain, Greece, Romania and the UK.

In the UK, where investigators have identified 28 victim companies, the Eastern Region Special Operations Unit arrested a 25-year-old at an address in Levenshulme, Manchester, suspected of negotiating with victims. Detective Sergeant John Collinson of the unit's cyber crime team said ransomware causes "significant financial losses, operational disruption and harm to public confidence."

Investigators now examine seized devices and trace proceeds, including cryptocurrency, work that Europol's European Cybercrime Centre supports with specialist crypto-tracing and digital forensics.

What comes next?

Eltibrizi faces extradition proceedings in the UK before any transfer to the U.S., while the Hamburg prosecutor's office retains operational lead on the broader European case. A seizure notice replaces KillSec's leak site, marking the first public confirmation that the group's infrastructure sits under law enforcement control. Prosecutions of the four suspects and recovery of cryptocurrency proceeds remain in early procedural stages.

via europol.europa.eu (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles