Skip to content
TECH CEO Daily

KillSec ransomware takedown: police arrest 16-year-old suspected leader, seize 5 servers

Operation KillSwitch, led by German authorities, seized KillSec's servers, leak site and at least 110 TB of stolen data; the group is linked to about 1,000 suspected attacks.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Police arrested three KillSec suspects on September 30, including a 16-year-old in Spain suspected of running the group.
  • 2Officers seized five servers, the leak site and at least 110 terabytes of stolen data in Operation KillSwitch.
  • 3Investigators link KillSec to about 1,000 suspected attacks worldwide, roughly 500 of them successful.

The news

Police dismantled the KillSec ransomware operation on September 30, 2026, arresting three suspects, including a 16-year-old in Spain suspected of running it, and seizing the group's servers and leak site, according to Europol and reports by BleepingComputer, The Record and The Hacker News.

The action, called Operation KillSwitch, was led by German authorities, with Hamburg police and prosecutors at its center, The Hacker News reported. BleepingComputer said agencies from 10 countries took part: Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States. Europol and Eurojust supported the case, as did security firms Bitdefender and Group-IB. Officers searched eight properties in Greece, Romania, Spain and the UK.

The 16-year-old, whom Europol described as the group's suspected main operator, according to The Register, was arrested in Alicante, Spain, by Catalan police and the Civil Guard, The Record reported, adding that he is a Romanian national. A Dutch national, Fouad Eltibrizi, who allegedly used the alias Archduke, was arrested in the UK. The Record said a federal grand jury in the District of Puerto Rico indicted him on an unauthorized computer access conspiracy charge, and he is awaiting extradition. The Hacker News reported the third arrest, of a 24-year-old in Romania. The US charge is an allegation, and none of the suspects has been convicted.

Investigators also identified a suspected developer who turned 18 in August and was a minor when some of the alleged offenses took place; that person was not arrested, according to The Hacker News. In all, police identified suspects in four roles: administrator, developer, negotiator and affiliate, an outside hacker who rents the ransomware and carries out attacks.

Police shut down five servers, including KillSec's main server, took down its dark web leak site and seized at least 110 terabytes of stolen data, BleepingComputer reported. Investigators link the group to around 1,000 suspected attacks worldwide, about 500 of them successful. BleepingComputer said about 70 hit German organizations, including 18 in Hamburg; The Hacker News reported Spanish authorities identified more than 280 victims.

The numbers

Suspects arrested
3
Properties searched
8, in Greece, Romania, Spain and the UK
Servers shut down
5
Stolen data seized
At least 110 terabytes
Suspected attacks linked to KillSec
About 1,000 (about 500 successful)
Victims identified by Spanish authorities
More than 280

Why CEOs should care

For CISOs, the entry point matters more than the arrests. BleepingComputer reported that KillSec broke in by exploiting software vulnerabilities and poorly secured edge devices and platforms. Those weaknesses do not disappear with the gang, and other ransomware crews use the same doors. Inventory internet-facing devices, patch them on an emergency clock, and remove any that are exposed without need.

For general counsel and CFOs at organizations KillSec hit, the seized servers may matter. Police now hold at least 110 terabytes of stolen data, which could help victims confirm what was taken and size their notification duties. None of the reports we reviewed mentioned a decryption tool, so do not count on one. If your company dealt with KillSec, contact the authorities and preserve your incident records, ransom correspondence and any payment details.

For boards, the age of the suspects is the warning. Security firm Halcyon, cited by The Record, said KillSec offered one of the most affordable ransomware-as-a-service platforms, a model in which operators rent their tools to affiliates for a cut. It said the group's Tor-based control panel, chat features and custom tools let people with limited technical skills run attacks. When a teenager can allegedly run such a service, the pool of potential attackers is large, and security budgets should be set for volume, not just sophistication.

The bigger picture

KillSec's path shows how quickly these groups evolve. Security company Rapid7 has said the group began as a hacktivist outfit, active since at least 2021, turned to ransomware in October 2023 and started offering ransomware-as-a-service to affiliates in June 2024, The Hacker News reported. Group-IB chief executive Dmitry Volkov told The Register that servers can be replaced within weeks but the people who build the platform cannot, an argument for arrests over infrastructure takedowns alone. With only three people in custody, affiliates who rented KillSec's tools may simply move to another brand.

What’s next

Watch for Eltibrizi's extradition to Puerto Rico, any juvenile proceedings in Spain, and victim notifications as investigators work through the seized data. Also watch whether KillSec, or its affiliates, resurface under a new name, as ransomware crews sometimes do after takedowns.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

KillSecEuropolRansomwareLaw enforcement

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.