16-Year-Old Suspected KillSec Ransomware Leader Arrested in International Operation
Authorities arrested three KillSec suspects, including an alleged 16-year-old administrator, in a nine-country operation.
On October 1, agencies from nine countries, coordinated by Eurojust and supported by Europol, arrested three suspects linked to the KillSec ransomware group, active since 2024 and suspected of nearly 1,000 attacks. A 16-year-old is alleged to be the main administrator and operator; a developer who recently turned 18 was allegedly a minor during part of the activity. KillSec is accused of stealing data, often through weakly secured cloud storage, then extorting victims with publication threats rather than relying on encryption. Searches in Spain, Greece, the United Kingdom, and Romania seized five servers, domains, and at least 110 TB of stolen data.
- Three suspects arrested, including alleged teen administrator
- KillSec suspected of nearly 1,000 attacks since 2024
- Extortion used stolen data rather than encryption
- Eight searches seized five servers and 110 TB of data
- Eurojust and Europol backed a nine-country operation
Full article550 words · extracted from gbhackers.com · click to collapse
International law enforcement authorities have arrested three suspects linked to the KillSec ransomware group, including a 16-year-old who is alleged to be the operation’s administrator and primary operator.
This coordinated action, announced on October 1, involved agencies from nine countries and was supported by Eurojust and Europol.
KillSec Ransomware Leader Arrested
KillSec, which has been active since 2024, is suspected of carrying out nearly 1,000 attacks against organizations worldwide. Investigators believe the group primarily targeted poorly secured entry points, particularly those related to cloud storage, to infiltrate victim environments.
Once they gained access, the attackers allegedly exfiltrated sensitive data to infrastructure they controlled. They used the threat of public exposure to extort victims.
Rather than relying solely on encryption-based disruption, KillSec reportedly utilized a data theft and extortion model. Victims were sent samples of their stolen files as proof of compromise and were warned that the data would be published if ransom demands were not met.
In cases where organizations declined to pay, the group allegedly made the stolen material available for free download, thereby increasing the potential impact on affected businesses, customers, and partners.
Authorities identified several individuals believed to have performed distinct operational functions within the group, including administrator, developer, negotiator, and affiliate.
The 16-year-old suspect is accused of serving as KillSec’s main administrator and operator, while a second suspect, described as a developer who recently turned 18, was allegedly a minor during part of the criminal activity being investigated.
The group reportedly used online aliases to conceal its members’ identities and relied on encrypted messaging platforms for communication. Investigators traced infrastructure, examined cryptocurrency transactions, and pursued digital evidence to map the group’s alleged operations and financial flows.
The action day resulted in eight house searches across Spain, Greece, the United Kingdom, and Romania. Authorities seized evidence, assets, and five servers allegedly used to store victim data, as well as domains operated by KillSec.
Investigators also secured at least 110 TB of stolen data, a significant collection that may help law enforcement identify previously unknown victims, additional intrusions, and other alleged participants.
Eurojust coordinated judicial authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom, and the United States.
A joint investigation team involving Belgium, Germany, Greece, and Romania supported the case. At the same time, a Eurojust coordination center helped plan and manage the international operation.
Europol contributed intelligence reports on KillSec’s activity, connected investigators with private-sector partners, and provided specialized assistance for cryptocurrency tracing and digital forensics.
The operation involved various organizations, including the FBI’s San Juan Field Office, the U.S. Attorney’s Office for the District of Puerto Rico, the UK’s Eastern Region Special Operations Unit, Spanish law enforcement bodies, Romanian anti-organized crime authorities, German federal and state police, and national agencies in the other participating countries.
Investigators will now analyze the seized devices, servers, and datasets, while continuing efforts to trace ransom proceeds. This case underscores how ransomware crews increasingly rely on data extortion, cloud access vulnerabilities, cryptocurrency payments, and cross-border infrastructure, requiring equally coordinated international responses.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.