Europol seizes KillSec leak site, says 16-year-old was a key operator

Europol seizes KillSec leak site, says 16-year-old was a key operator

N
News Editor
2026-10-02 11:35:33
Europol said on Oct. 1 that law enforcement agencies took control of the leak site used by the ransomware group KillSec on Sept. 30, securing at least 110 TB of stolen data and blocking further outside access. The operation, called “KillSwitch,” was led by Hamburg state criminal police and prosecutors in Germany and included searches at eight locations across Spain, Greece, Romania, and the U.K., with three temporary arrests. Investigators identified a 16-year-old suspect as the group’s alleged administrator and main operator. Europol said KillSec was linked to about 1,000 attacks worldwide, with roughly 500 confirmed successful cases so far, though that figure could change as evidence is reviewed. The agency also said the group used AI to build and maintain its ransomware infrastructure and to identify potential victims, but did not disclose the tools involved or the exact tasks AI handled. According to The Hacker News, citing statements from national police forces and Reuters, the 16-year-old was arrested in Spain. Spanish authorities said more than 280 victims were affected and that some paid around €500,000 in cryptocurrency ransom. Investigators also seized computer equipment, phones, and crypto wallets, and said preliminary analysis found transactions matching some ransom payments.

Europol said on Oct. 1 that law enforcement agencies took over the data leak site used by the ransomware group KillSec on Sept. 30, securing at least 110 TB of stolen data and preventing further outside access. Investigators said a 16-year-old suspect was the group’s alleged administrator and main operator.

Operation KillSwitch led to searches in four countries

The operation, named “KillSwitch,” was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office in Germany. Authorities searched eight locations across Spain, Greece, Romania, and the United Kingdom, and temporarily arrested three suspects.

Europol said KillSec was linked to about 1,000 attacks worldwide, with around 500 confirmed successful cases so far. The agency added that the figure could change as investigators continue to analyze the evidence.

Europol says the group used AI in its operations

Europol said the investigation found that KillSec used AI to build and maintain its ransomware infrastructure and to identify potential victims. The agency did not say which AI tools were used or what specific tasks were handled by those systems.

Investigation centers on two teenage suspects

Europol said investigators identified several roles inside KillSec, including administrators, developers, negotiators, and affiliates. Affiliates were described as outside hackers who rented the group’s ransomware tools and then carried out attacks on their own.

The suspected developer will not turn 18 until August 2026, meaning some of the alleged conduct took place while that person was still a minor.

According to The Hacker News, which cited statements from national police agencies, the 16-year-old suspect was arrested in Spain by the Guardia Civil and Catalan police. A joint statement from those agencies described him as the group’s alleged main administrator.

The Hacker News, citing Reuters, said the other two arrested suspects were both in their 20s and were detained in the U.K. and Romania. Puerto Rico has requested the extradition of the suspect arrested in the U.K. The suspected developer has been identified but has not been arrested.

Spanish investigation began in 2025

The Guardia Civil said its investigation began in 2025 and was carried out with the FBI’s San Juan field office in Puerto Rico to track possible KillSec members living in Spain. In a joint statement, authorities said investigators identified the Spain-based administrator from a single profile image.

Some ransom payments were made in cryptocurrency

Europol said KillSec had been active since around 2024. After gaining access to an organization’s systems, members copied sensitive internal data to servers under their control. They then named victims on a dark web leak site and threatened to publish the data. If victims refused to pay, the stolen files could be made available for free download. Europol said the group obtained large ransom payments in some cases.

The Hacker News noted that law enforcement agencies have described KillSec as a ransomware group, but the conduct outlined by authorities focused on data theft followed by extortion. In a typical ransomware case, attackers encrypt a victim’s files and demand payment for decryption.

Spanish police said more than 280 targets were affected, and some victims paid about €500,000 in cryptocurrency ransom. During searches in Spain, officers seized computer equipment, mobile phones, and cryptocurrency wallets. Preliminary analysis found transactions that matched some of the ransom payments made by victims.

A separate case handled by Catalan police began after a local institution was attacked in early 2025. Police suspect KillSec was behind that incident. The estimated damage from that attack was close to €1 million.

Authorities took control of servers and domains

Europol said five core servers were brought under law enforcement control during the investigation. Those servers were used to manage the group’s operations and store victim data. Authorities also seized domains operated by KillSec, and visitors are now redirected to an official seizure notice.

Key facts disclosed so far

  • Europol announced the action on Oct. 1 after law enforcement took over the KillSec leak site on Sept. 30.
  • At least 110 TB of stolen data was secured.
  • Authorities searched eight locations in four countries and temporarily arrested three people.
  • A 16-year-old suspect was identified as the alleged main operator.
  • KillSec was linked to about 1,000 attacks worldwide, with around 500 confirmed successful cases.
  • Spanish police said more than 280 victims were affected, and some paid about €500,000 in cryptocurrency ransom.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.