Police Arrest 16-Year-Old Suspected of Running KillSec Ransomware Group

Spanish police have arrested a 16-year-old suspected of being the main administrator and operator of the KillSec ransomware group, as part of an international investigation into hundreds of alleged cyberattacks.

The teenager was arrested in Alicante on September 30, 2026. Two other suspects were also arrested in the United Kingdom and Romania during the coordinated operation.

Authorities also seized KillSec's leak site and shut down several servers used by the group to store stolen victim data.

International Operation Targets KillSec

The operation involved law enforcement agencies from Germany, Spain, Romania, the United Kingdom, the United States and other European countries.

German police and prosecutors led the investigation, while Europol and Eurojust coordinated the international effort.

Authorities carried out eight searches across Spain, Greece, the United Kingdom and Romania.

Investigators also seized five servers, including KillSec's main server and infrastructure allegedly used to store stolen information.

More than 110 TB of data was secured after authorities took control of the group's leak-site infrastructure.

16-Year-Old Suspected of Leading the Group

Spanish authorities arrested the 16-year-old in Alicante.

Investigators identified him as KillSec's suspected administrator and main operator.

Spanish police searched a residence and an office located at a hotel in Alicante province. Officers seized computers, mobile phones and cryptocurrency wallets.

An initial examination of the cryptocurrency evidence reportedly identified transactions matching ransom payments from some victims.

Authorities have also identified suspected individuals associated with four different roles within the group:

  • Administrator
  • Developer
  • Negotiator
  • Affiliate

A suspected developer who turned 18 in August 2026 has also been identified. Authorities said the individual was a minor when some of the alleged offenses took place.

Two Other Suspects Arrested

Two additional suspects were arrested during the operation.

One was arrested in the United Kingdom, while Romanian authorities arrested a 24-year-old man.

Romanian prosecutors searched four locations in Bucharest and Vaslui County.

The Romanian suspect is being investigated for alleged involvement in an organized criminal group, unauthorized access to computer systems, unauthorized transfer of computer data, illegal operations involving computer devices or software, and blackmail.

Prosecutors requested that the Bucharest court place the suspect in custody for 30 days.

All three arrests were described as provisional, and the suspects are presumed innocent.

KillSec Leak Site Taken Down

Law enforcement authorities also took control of KillSec's dark web leak site.

The group allegedly used the site to publish the names of organizations it had compromised and threaten victims with the release of stolen data.

Investigators secured at least 110 terabytes of stolen information stored on the group's infrastructure.

Five domains associated with KillSec were also seized and replaced with law enforcement notices.

Around 1,000 Suspected Attacks

Investigators are examining approximately 1,000 suspected KillSec attacks worldwide.

Around 500 attacks have so far been identified as successful, although authorities said these figures may change as the investigation continues.

Spanish authorities have identified more than 280 victims.

Investigators also linked KillSec to an attack against a Catalan organization in early 2025 that allegedly caused damage estimated at nearly €1 million.

How KillSec Targeted Organizations

According to investigators, KillSec gained access to organizations by exploiting software vulnerabilities and poorly secured access points.

Cloud storage systems were among the infrastructure targeted by the group.

After obtaining access, attackers allegedly copied sensitive internal information to servers under their control.

The stolen information was then used to pressure victims into paying cryptocurrency ransoms.

Victims were listed on the group's leak site and threatened with publication of their data if they refused to pay.

In some cases, stolen files were made available for free download after victims did not pay.

Investigators also found evidence that KillSec members purchased compromised credentials from underground marketplaces.

AI Used in KillSec Operations

Hamburg investigators said KillSec used artificial intelligence to build and operate parts of its infrastructure and identify potential victims.

Authorities have not disclosed which AI systems were used or provided technical details about how the technology was incorporated into the group's operations.

Ransomware-as-a-Service Activity

Security researchers previously reported that KillSec evolved from hacktivist activity into financially motivated cybercrime.

The group later developed ransomware variants and began offering its ransomware to affiliates.

This ransomware-as-a-service model allowed external operators to use the group's tools to conduct attacks while KillSec maintained its own infrastructure and extortion operations.

Investigators said the current case involves both ransomware activity and attacks where victims were extorted using stolen data without necessarily encrypting their systems.

Investigation Continues

Authorities are continuing to examine the seized computers, phones, servers, cryptocurrency wallets and stolen data.

The investigation could identify additional victims, previously unknown attacks and other individuals associated with KillSec.

Investigators are also tracing cryptocurrency transactions linked to suspected ransom payments and examining how the group operated its infrastructure.

Authorities said investigations into other possible members of the group remain ongoing.

Key Takeaway

The international operation has disrupted KillSec's infrastructure after authorities arrested three suspects, seized five servers and secured more than 110 TB of stolen victim data.

A 16-year-old has been identified as the suspected main administrator and operator, while investigators continue analyzing the seized evidence to identify additional victims, attacks and suspected members.