A 16-Year-Old Is Suspected of Running KillSec, One of Ransomware's Busiest Criminal Groups

European police arrested three people and seized servers after a year-long investigation into roughly 1,000 cyberattacks. The alleged ringleader is a Romanian teenager.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
A dim, blue-tinted server room at night, rows of blinking rack servers casting faint light on the floor, yellow police crime-scene tape stretched across the ent
Share

Key points

  • A 16-year-old Romanian national, arrested in Alicante, Spain, is suspected of leading the KillSec ransomware group, according to a Europol statement published on 1 October 2025.
  • Operation KillSwitch, led by German law enforcement, targeted roughly 1,000 suspected KillSec attacks worldwide, at least 70 of which hit government organisations.
  • Three people were arrested, eight properties were raided across Spain, Greece, Romania, and the UK, and five servers plus KillSec's public leak site were seized.
  • Dutch national Fouad Eltibrizi, known online as "Archduke", was arrested in the UK on 30 September and faces US charges carrying up to ten years in prison for his alleged role in the operation.
  • Investigators confirmed roughly 500 of the 1,000 suspected attacks as successful, and seized at least 110 terabytes of data to stop it being leaked or sold.

The person suspected of running one of the past year's most active ransomware operations may not yet be old enough to vote. Europol confirmed on 1 October 2025 that a 16-year-old is the suspected administrator of KillSec, a criminal group linked to around 1,000 cyberattacks globally. Ransomware is malicious software that locks or steals a company's data, then demands payment to keep it private.

German police led the investigation, code-named Operation KillSwitch, with support from authorities in the US, UK, Spain, Romania, and Greece. Europol and Eurojust, the EU's judicial cooperation agency, coordinated the cross-border effort. Cybersecurity firms Bitdefender and Group-IB provided technical assistance.

How did KillSec operate?

KillSec surfaced in 2024 and quickly became prolific by targeting known software weaknesses and poorly secured login points, especially in cloud environments, the internet-connected computing services that most large organisations now rely on to store data and run applications. Once inside a victim's systems, the group copied files, then threatened to publish them on its leak site unless a ransom was paid.

Bitdefender, which tracked the group throughout, reported nearly 300 victim listings on KillSec's leak site since 2024, including 126 posted in 2025 and 25 in 2026. The most recent appeared on 18 September, twelve days before police acted. Investigators also found evidence the group used artificial intelligence tools to build its infrastructure and identify targets.

Metric Figure
Suspected attacks worldwide ~1,000
Attacks involving governments at least 70
Attacks investigators confirmed successful ~500
Properties raided 8
Countries involved in raids 4
Servers seized 5

What happened to the people running it?

Three people were provisionally arrested. The 16-year-old, described by a Europol spokesman as the group's "administrator", was detained in Alicante, Spain. Separately, Dutch national Fouad Eltibrizi was arrested in the UK on 30 September. The US Justice Department has indicted him, and UK authorities are preparing extradition. He faces a maximum of ten years in prison if convicted on charges of unauthorised computer access conspiracy.

Hamburg police said investigators seized at least 110 terabytes of data, the equivalent of tens of millions of documents, to prevent it from being leaked or sold.

In practice, takedowns like this create a vacuum other groups fill fast. Our coverage of JadePuffer, published the same day as this arrest, shows how quickly a new crew can build destructive ransomware infrastructure from scratch. Criminal tooling gets rebuilt faster than court processes move.

The failure mode here is assuming a single arrest ends the problem. KillSec was opportunistic, not sophisticated; the techniques it used are documented, the tools are available, and the business model works. Other groups know this.

If you work in IT at any organisation and haven't audited which cloud storage buckets or remote-login portals are exposed to the public internet, that's the first thing to check today.

© 2026 Threat Vectr