Spanish police have arrested a 16-year-old suspected of being the main operator of the KillSec ransomware group, in a coordinated European law enforcement action that also led to server seizures, arrests in multiple countries, and the protection of at least 110 terabytes of stolen data, according to Europol.
The teenager, a Romanian national detained in Alicante, is suspected of acting as the group’s administrator, a Europol spokesperson told Reuters. Two other suspects in their twenties were also arrested, one in Britain and one in Romania. A fourth suspect, identified as a developer who turned 18 in August, has not been arrested. Investigators said some of the alleged offences tied to that suspect were committed while he was still a minor.
The September 30 action formed part of Operation KillSwitch, an investigation led by the Hamburg State Criminal Police Office and the city’s public prosecutor. The case covers around 1,000 suspected attacks worldwide, with about 500 of them identified so far as successful. Authorities searched eight properties across Spain, Greece, Romania, and the UK.
UK suspect faces U.S. charges
The suspect arrested in Britain is also facing charges in the United States. Fouad Eltibrizi, a Dutch national living in the UK and known online as Archduke, was indicted by a federal grand jury in Puerto Rico on September 16.
The indictment accuses him of conspiracy to access computers without authorization for financial gain, damaging protected computers, and transmitting extortion threats. He was arrested during the following fortnight and now faces extradition, with a maximum penalty of 10 years.
On October 1, the FBI Cyber Division said it was announcing Operation KillSwitch, describing it as a joint sequenced operation led by @FBISanJuan and targeting the Kill Security Ransomware Group, or KillSec. The post said authorities in the U.S. and Europe had taken control of KillSec’s leak site and secured at least 110 terabytes of data against further exposure.
Puerto Rico breach cited in U.S. indictment
U.S. prosecutors said KillSec posted a Puerto Rico breach on its leak site in March 2025, showing samples of stolen patient data and a seven-day countdown. When the company did not respond, about 180GB of data was published.
The indictment also describes similar breaches in California, Washington State, and Louisiana.
Ransoms were often sought in cryptocurrency
Europol said KillSec has been active since around 2024, using software vulnerabilities and weak access points, particularly around cloud storage, to break into organizations, copy internal data, and move it to infrastructure under the group’s control. Victims were then listed on the group’s dark web leak site and threatened with publication unless they paid. Where no payment was made, files were released for free download.
Switzerland’s federal police said the group used double extortion: first encrypting servers, then threatening to publish data even when companies refused to pay because they had backups. Ransom demands were often made in cryptocurrency. Swiss prosecutors have been investigating since July 2025 over attacks on Swiss companies that took place between October 2023 and June 2025.
Investigators are tracing crypto proceeds
Investigators also found that the group had used AI to build and maintain its ransomware infrastructure and to identify potential victims.
Authorities now control five central servers, and related domains have been redirected to a seizure notice. Investigators are examining seized devices and tracing the group’s proceeds, including cryptocurrency. Europol said its European Cybercrime Centre has supported the case with specialist crypto-tracing and digital forensics.
28 victim companies identified in the UK
In the UK, investigators have identified 28 victim companies. Officers from the Eastern Region Special Operations Unit arrested a 25-year-old man at an address in Levenshulme, Manchester, on suspicion of negotiating with victims.
Detective Sergeant John Collinson of the unit’s cyber crime team said ransomware causes “significant financial losses, operational disruption and harm to public confidence.”


