Spanish police have arrested a 16-year-old Romanian national in Alicante suspected of serving as the administrator and main operator of the KillSec ransomware group. Europol announced that the international law enforcement action also resulted in the seizure of the group's servers and leak site, securing at least 110 terabytes of stolen data.
Operation KillSwitch Targets Global Attacks
The coordinated September 30 action, dubbed Operation KillSwitch, was led by the Hamburg State Criminal Police Office and the city's public prosecutor. The operation targeted approximately 1,000 suspected attacks worldwide, with about 500 identified as successful. Authorities conducted searches across eight properties in Spain, Greece, Romania, and the United Kingdom.
Alongside the teenager detained in Alicante, two individuals in their twenties were arrested in Britain and Romania. A fourth suspect, identified as a developer who turned 18 in August but was a minor during the commission of some offenses, has been identified but not arrested.
Indictments and Extradition
In the United Kingdom, a 25-year-old Dutch national residing in the UK, Fouad Eltibrizi, was arrested and faces extradition to the United States. Eltibrizi, who used the online handle Archduke, was indicted by a federal grand jury in Puerto Rico on September 16. Charges include conspiracy to access computers without authorization for financial gain, damaging protected computers, and transmitting extortion threats. He faces a maximum penalty of 10 years if convicted.
U.S. prosecutors stated that KillSec published a Puerto Rico data breach in March 2025 featuring stolen patient data after a company failed to meet an extortion countdown. The indictment outlines similar breaches orchestrated by the group in California, Washington State, and Louisiana.
Methods and Cryptocurrency Proceeds
Active since around 2024, KillSec exploited software vulnerabilities and poorly secured cloud storage access points to infiltrate organizational systems. The group utilized a double extortion model, encrypting servers and threatening to leak stolen data on the dark web unless ransoms were paid. According to Swiss police, ransoms were frequently demanded in cryptocurrency.
Investigators also discovered that the group leveraged artificial intelligence to build and maintain its ransomware infrastructure and to identify potential targets. Swiss prosecutors have been investigating attacks on Swiss companies spanning from October 2023 to June 2025.
Authorities now control five central servers and have redirected the group's domains to law enforcement seizure notices. Europol's European Cybercrime Centre is assisting with digital forensics and tracing the group's criminal proceeds, including cryptocurrency transactions.


