The news
Police dismantled the KillSec ransomware operation on September 30, 2026, arresting three suspects, including a 16-year-old in Spain suspected of running it, and seizing the group's servers and leak site, according to Europol and reports by BleepingComputer, The Record and The Hacker News.
The action, called Operation KillSwitch, was led by German authorities, with Hamburg police and prosecutors at its center, The Hacker News reported. BleepingComputer said agencies from 10 countries took part: Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States. Europol and Eurojust supported the case, as did security firms Bitdefender and Group-IB. Officers searched eight properties in Greece, Romania, Spain and the UK.
The 16-year-old, whom Europol described as the group's suspected main operator, according to The Register, was arrested in Alicante, Spain, by Catalan police and the Civil Guard, The Record reported, adding that he is a Romanian national. A Dutch national, Fouad Eltibrizi, who allegedly used the alias Archduke, was arrested in the UK. The Record said a federal grand jury in the District of Puerto Rico indicted him on an unauthorized computer access conspiracy charge, and he is awaiting extradition. The Hacker News reported the third arrest, of a 24-year-old in Romania. The US charge is an allegation, and none of the suspects has been convicted.
Investigators also identified a suspected developer who turned 18 in August and was a minor when some of the alleged offenses took place; that person was not arrested, according to The Hacker News. In all, police identified suspects in four roles: administrator, developer, negotiator and affiliate, an outside hacker who rents the ransomware and carries out attacks.
Police shut down five servers, including KillSec's main server, took down its dark web leak site and seized at least 110 terabytes of stolen data, BleepingComputer reported. Investigators link the group to around 1,000 suspected attacks worldwide, about 500 of them successful. BleepingComputer said about 70 hit German organizations, including 18 in Hamburg; The Hacker News reported Spanish authorities identified more than 280 victims.
The numbers
- Suspects arrested
- 3
- Properties searched
- 8, in Greece, Romania, Spain and the UK
- Servers shut down
- 5
- Stolen data seized
- At least 110 terabytes
- Suspected attacks linked to KillSec
- About 1,000 (about 500 successful)
- Victims identified by Spanish authorities
- More than 280
Why CEOs should care
For CISOs, the entry point matters more than the arrests. BleepingComputer reported that KillSec broke in by exploiting software vulnerabilities and poorly secured edge devices and platforms. Those weaknesses do not disappear with the gang, and other ransomware crews use the same doors. Inventory internet-facing devices, patch them on an emergency clock, and remove any that are exposed without need.
For general counsel and CFOs at organizations KillSec hit, the seized servers may matter. Police now hold at least 110 terabytes of stolen data, which could help victims confirm what was taken and size their notification duties. None of the reports we reviewed mentioned a decryption tool, so do not count on one. If your company dealt with KillSec, contact the authorities and preserve your incident records, ransom correspondence and any payment details.
For boards, the age of the suspects is the warning. Security firm Halcyon, cited by The Record, said KillSec offered one of the most affordable ransomware-as-a-service platforms, a model in which operators rent their tools to affiliates for a cut. It said the group's Tor-based control panel, chat features and custom tools let people with limited technical skills run attacks. When a teenager can allegedly run such a service, the pool of potential attackers is large, and security budgets should be set for volume, not just sophistication.
The bigger picture
KillSec's path shows how quickly these groups evolve. Security company Rapid7 has said the group began as a hacktivist outfit, active since at least 2021, turned to ransomware in October 2023 and started offering ransomware-as-a-service to affiliates in June 2024, The Hacker News reported. Group-IB chief executive Dmitry Volkov told The Register that servers can be replaced within weeks but the people who build the platform cannot, an argument for arrests over infrastructure takedowns alone. With only three people in custody, affiliates who rented KillSec's tools may simply move to another brand.
What’s next
Watch for Eltibrizi's extradition to Puerto Rico, any juvenile proceedings in Spain, and victim notifications as investigators work through the seized data. Also watch whether KillSec, or its affiliates, resurface under a new name, as ransomware crews sometimes do after takedowns.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





