NEWS

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Spanish police arrested a 16-year-old Romanian national as KillSec's alleged lead operator; Operation KillSwitch seized 5 servers and 110TB of stolen data.

Dylan H.

News Desk

October 4, 2026
8 min read
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Spanish Police Arrest Teenage Suspect in KillSec Ransomware Takedown

Police in Spain arrested a 16-year-old Romanian national in the city of Alicante on September 30, 2026, suspected of serving as the lead administrator of the KillSec ransomware group. The arrest was part of a coordinated, ten-country law enforcement action dubbed Operation KillSwitch, led by Germany's Hamburg State Criminal Police Office (LKA Hamburg) and the Hamburg Public Prosecutor's Office, with cross-border coordination from Europol's European Cybercrime Centre (EC3) and Eurojust. Investigators tied KillSec to roughly 1,000 suspected ransomware attacks worldwide over the past two years, with about 500 confirmed successful breaches and more than 280 identified victims. Alongside the teenager, authorities arrested two other suspects — one in the United Kingdom and one in Romania — while seizing five central servers, taking control of KillSec's dark web leak site, and securing an estimated 110 terabytes of stolen victim data.


Details

AttributeValue
Operation nameOperation KillSwitch
Arrest dateSeptember 30, 2026
Lead suspect16-year-old Romanian national, arrested in Alicante, Spain
Other suspectsFouad Eltibrizi ("Archduke"), Dutch national residing in the UK; a third suspect arrested in Romania
Group targetedKillSec (also tracked as KillSecurity), ransomware-as-a-service
Lead agencyHamburg State Criminal Police Office (LKA Hamburg) and Hamburg Public Prosecutor's Office
Supporting agenciesEuropol (EC3), Eurojust, Guardia Civil, Mossos d'Esquadra, DIICOT (Romania), FBI San Juan, U.S. prosecutors (Puerto Rico)
Countries involvedBelgium, Finland, Germany, Greece, Netherlands, Romania, Spain, Switzerland, UK, US (10 total)
Infrastructure seized5 central servers, leak site taken over, 5 domains redirected to seizure notices
Data securedApproximately 110 TB of stolen victim data
Property searches8, across Spain, Greece, Romania, and the UK

Who Is KillSec

KillSec began as a self-described hacktivist collective active since at least 2021 before pivoting to ransomware and data-extortion operations in October 2023. By June 2024, the group had expanded into a full ransomware-as-a-service (RaaS) operation, recruiting affiliates who were given tooling and a cut of ransom proceeds in exchange for breaching targets. KillSec's affiliates typically gained initial access through unpatched software vulnerabilities and poorly secured cloud storage buckets, stole sensitive files, and then threatened to publish the data on the group's dark web leak site unless victims paid. Investigators say the group also used AI tools to help build and maintain parts of its ransomware infrastructure. Ransom demands reportedly reached as high as €500,000 in cryptocurrency, paid through exchanges regulated under the EU's MiCA framework, which gave Europol's cybercrime unit a trail to follow. Germany was the hardest-hit country identified in the investigation, with authorities there linking at least 70 attacks to the group, 18 of them in Hamburg alone — the reason German police ended up leading the international case. One Catalan organization is reported to have suffered losses approaching €1 million from a KillSec attack in early 2025.

The Takedown

Operation KillSwitch culminated on September 30 with coordinated searches and arrests across four countries. Europol's announcement frames the case around four roles inside the group: an administrator, a developer, a negotiator, and an affiliate. In Spain, the Guardia Civil and Mossos d'Esquadra detained the 16-year-old — identified by Europol as the group's "administrator" and suspected main operator, effectively its founder — in Alicante, searching both a residence and an office at a local hotel and seizing computer equipment, phones, and cryptocurrency wallets. The arrest makes him one of the youngest suspected ransomware operators ever detained by European authorities. In the UK, Fouad Eltibrizi, who goes by the handle "Archduke" and is alleged to have acted as the group's negotiator, was arrested after being indicted on September 16, 2026 by a federal grand jury sitting in Puerto Rico on an unauthorized computer access conspiracy charge; prosecutors there, working with the FBI's San Juan field office, have filed an extradition request, and Eltibrizi faces up to 10 years in prison if convicted. A third suspect, believed to be an affiliate in his 20s, was arrested in Romania, where prosecutors asked a Bucharest court on October 1 to hold him in custody for 30 days pending further investigation; Romanian charges include forming an organized criminal group, unauthorized computer access, illegal data transfer, and blackmail. A fourth individual — a suspected developer who turned 18 in August 2026 — has been identified but not arrested, because the offenses attributed to him allegedly occurred while he was still a minor. All three arrests are described by Hamburg police as provisional, and all suspects are presumed innocent pending trial. Europol's cybercrime centre is now working to trace cryptocurrency ransom payments and is assisted by private cybersecurity firms Bitdefender and Group-IB, who supported the technical side of the investigation.

Because the alleged lead administrator is a minor, his case will likely proceed through Spain's juvenile justice system rather than adult criminal courts, and any eventual penalties would be far more limited than those facing his adult co-defendants. The case nonetheless fits a pattern investigators and researchers have flagged repeatedly in recent years: teenagers, often radicalized or recruited inside gaming and hacking Discord communities, taking on leadership roles in ransomware and extortion crews rather than acting merely as low-level affiliates. The arrest of the alleged developer — who was a minor for part of the conspiracy and only turned 18 months before the raid — underscores how difficult these cases are for prosecutors to build, since statutes covering computer intrusion, extortion, and organized crime were not written with minors running multinational RaaS operations in mind.

Impact Assessment

Impact AreaDescription
Victim exposureMore than 280 identified victims and roughly 500 confirmed successful attacks over two years, spanning multiple countries
Data at riskApproximately 110 TB of stolen data recovered by investigators; the full scope of what was already leaked or sold before seizure remains under review
Financial harmRansom demands up to €500,000 per incident; one Catalan victim organization reported losses near €1 million
Operational disruptionKillSec's leak site and ransomware-as-a-service infrastructure are offline, but affiliates who used the platform may resurface under a rebranded operation
Legal precedentHighlights gaps in prosecuting minors who occupy leadership roles in transnational cybercrime groups, complicating extradition and sentencing

Recommendations

For Organizations and IT Administrators

  • Patch internet-facing software promptly and audit cloud storage buckets for public or overly permissive access — both were KillSec's primary initial-access vectors.
  • Maintain offline, tested backups and an incident response plan that assumes data theft (not just encryption), since KillSec's model relies on extortion over leaked data rather than solely on crypto-locking files.
  • Review third-party and affiliate access to sensitive systems; RaaS operations frequently rely on affiliates with inconsistent security hygiene to gain the initial foothold.

For Security Teams

  • Monitor for indicators tied to known KillSec TTPs, including exploitation of unpatched vulnerabilities and cloud misconfiguration scanning.
  • Coordinate with legal counsel in advance on ransom payment policy and law enforcement notification procedures (Europol, FBI, or local national cybercrime units) so a response plan exists before an incident occurs.
  • Track cryptocurrency ransom demands and payment addresses; EC3's MiCA-assisted tracing in this case shows exchange-level forensics are increasingly viable for recovery and attribution.

For Parents and Educators

  • Be aware that leadership roles in ransomware and extortion groups are increasingly held by teenagers recruited through gaming and hacking-adjacent online communities, not just older, organized adult crews.
  • Treat early warning signs — unexplained cryptocurrency activity, secretive online communities, or advanced technical skills paired with unsupervised internet access — as worth a direct conversation, not just technical monitoring.

Key Takeaways

  1. A 16-year-old Romanian national was arrested in Alicante, Spain, on September 30, 2026, suspected of being KillSec's lead administrator — one of the youngest alleged ransomware operators ever detained in Europe.
  2. Operation KillSwitch involved nine countries and was led by Germany's Hamburg police, reflecting KillSec's heaviest attack concentration (70+ attacks, including 18 in Hamburg) in Germany.
  3. Investigators seized 5 servers, took over KillSec's leak site, redirected 5 domains to seizure notices, and secured approximately 110 TB of stolen data.
  4. KillSec is attributed with nearly 1,000 suspected attacks and roughly 500 confirmed breaches since pivoting from hacktivism to ransomware-as-a-service between 2023 and 2024.
  5. A second adult suspect, Fouad Eltibrizi ("Archduke"), faces a Puerto Rico federal indictment and extradition from the UK, while a third was arrested in Romania; a fourth suspected developer remains unarrested due to his age during the alleged offenses.
  6. The case highlights a growing trend of minors occupying leadership — not just entry-level affiliate — roles in transnational ransomware operations, complicating prosecution and sentencing.

Sources