Police dismantle KillSec ransomware operation, arrest suspected 16-year-old leader

A Eurojust-coordinated operation led to three arrests, eight searches and the seizure of KillSec's leak site, five servers and 110 TB of stolen data.

Police dismantle KillSec ransomware operation, arrest suspected 16-year-old leader

At a glance

  • A 16-year-old Romanian national suspected of leading KillSec was arrested in Alicante, Spain
  • Three arrests and eight house searches in Spain, Greece, the UK and Romania; five servers and several domains seized
  • Investigators secured about 110 TB of stolen data; the group is linked to roughly 1,000 attacks since 2024
  • Victims included healthcare, government and financial services organizations

European law enforcement agencies have disrupted the KillSec ransomware-as-a-service operation and arrested a 16-year-old suspected of being its main operator and administrator, authorities announced on October 1, 2026. The international action, coordinated by Eurojust with support from Europol, also took down the group's dark web leak site and seized servers that allegedly stored stolen data, according to The Record and Help Net Security.

What happened

According to The Record, the teenager, a Romanian national, was detained in the Spanish town of Alicante by Catalan police and the Civil Guard's cybercrime unit. Help Net Security reports that the operation resulted in three arrests in total and eight house searches across Spain, Greece, the United Kingdom and Romania. Investigators seized five servers and multiple domains and secured about 110 terabytes of stolen data.

The Record reports that the operation was coordinated from Hamburg, Germany, and that the investigation began in early 2025. Judicial authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom and the United States took part, according to Eurojust as cited by Help Net Security. Europol supported cryptocurrency tracing and digital evidence analysis, and The Record notes that private firms Bitdefender and Group-IB also assisted.

The Record also reports that a Dutch national known online as "Archduke" was arrested in the U.K. and had been indicted by a U.S. federal grand jury in Puerto Rico on September 16. At least four suspected members have been identified; one suspected developer turned 18 in August, the outlet said.

Technical details

KillSec emerged in 2024 and ran a ransomware-as-a-service platform advertised at "affordable" rates, offering affiliates a Tor-accessible control panel with chat and custom ransomware tools, according to The Record. The group primarily abused poorly secured access points, especially exposed or misconfigured cloud storage.

Eurojust described the playbook as data theft followed by extortion: "Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen data public unless the victims paid a ransom," Help Net Security quoted. Members held roles as administrator, developer, negotiator and affiliate and communicated over encrypted messaging services.

Who is affected

KillSec is linked to approximately 1,000 attacks worldwide since it appeared, with at least half believed to have been successful, according to The Record. Victims included healthcare, government and financial services organizations, which were listed on the group's leak site with extortion threats. Authorities have not published a full victim list.

What to do

The takedown removes one extortion platform, but affiliates and stolen data may resurface elsewhere. Organizations should audit cloud storage buckets and other internet-facing data stores for public access or weak authentication, rotate credentials that may have been exposed, and enforce multi-factor authentication on remote access. Organizations that were previously listed by KillSec may want to contact their national law enforcement or CERT, as seized data could support victim notification and investigations.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.