Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

1 hour ago 3

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.

The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site.

Investigators identified him as KillSec's suspected administrator and main operator, Hamburg police said on October 1. Police and prosecutors in Hamburg, Germany, led the operation.

The Guardia Civil and the Mossos d'Esquadra, both Spanish police forces, detained him in Alicante and searched a home and an office at a hotel in the province. Their joint statement, carried by elperiodic.com, calls him one of the group's administrators and its presumed main administrator.

The other 2 people arrested are in their 20s, one in the U.K. and one in Romania, a spokesperson for Europol, the European Union's police agency, told Reuters.

U.S. prosecutors in Puerto Rico and the FBI's San Juan office took part in the operation. Puerto Rico has filed an extradition request for the man arrested in the U.K., the Europol spokesperson said.

In Romania, prosecutors from DIICOT, the country's organized crime and terrorism directorate, detained a 24-year-old on September 30 and searched 4 homes in Bucharest and Vaslui county. He is under investigation for forming an organized criminal group, illegal access to a computer system, unauthorized transfer of computer data, illegal operations with devices or software, and blackmail, according to DIICOT's statement, carried by the newspaper Bursa.

Cybersecurity

On October 1, the prosecutors asked a Bucharest court to keep him in custody for 30 days. He is presumed innocent. Hamburg police described all 3 arrests as provisional.

Investigators have identified suspects in 4 roles: an administrator, a developer, a negotiator and an affiliate. An affiliate is an outside partner who uses a group's ransomware tools to carry out attacks.

The suspected developer turned 18 in August and was a minor when some of the alleged offenses took place. He has been identified but not arrested, Reuters reported.

Neither Hamburg police nor DIICOT said in their statements what roles the men arrested in the U.K. and Romania are suspected of holding.

Police carried out 8 searches in Spain, Greece, the U.K. and Romania. They secured at least 110 terabytes of data against further unauthorized access when they took over the leak site.

During the investigation, Hamburg investigators also shut down 5 servers, including KillSec's main server and several used to hold data taken from victims. They put a police seizure notice on 5 of the group's domains.

In Spain, officers seized computer equipment, phones and cryptocurrency wallets. A first analysis found transactions that match ransom payments from some victims, Spanish police said.

The Guardia Civil's investigation began in 2025 from cooperation with the FBI's office in San Juan, Puerto Rico, aimed at finding people linked to KillSec who might live in Spain. Starting from a single profile image, its investigators identified the suspect, who lived in Alicante province.

The Mossos d'Esquadra opened their own case after an attack on a Catalan organization in early 2025 that they suspect was KillSec's work. The damage was put at close to €1 million.

Authorities in several countries began investigating attacks blamed on KillSec in early 2025. Europol and the EU's judicial cooperation agency, Eurojust, coordinated the work, and security companies Bitdefender and Group-IB supported the investigation.

How KillSec Extorted Its Victims

KillSec gained access to organizations by exploiting software vulnerabilities and poorly secured access points, especially cloud storage, according to Hamburg police. Its members then copied sensitive internal data to servers they controlled.

The group named its victims on its dark web leak site and threatened to publish their data unless they paid a ransom. Where a victim did not pay, the stolen files could be offered for free download.

The investigation covers about 1,000 suspected attacks worldwide. About 500 have been identified as successful so far, and both figures may change as investigators work through the seized evidence.

Cybersecurity

Investigators also uncovered how the group used AI to build and operate its infrastructure and identify potential victims, Hamburg police said. Their statement gives no further detail.

DIICOT prosecutors said members also bought access credentials offered for sale on the dark web, sent victims samples of their own data as proof, and threatened to sell the data to other criminal groups if no ransom was paid.

Spanish police put the number of victims at more than 280. The group "obtained substantial ransom payments," Europol said in a statement quoted by Reuters.

The agencies call KillSec a ransomware group, but the conduct they describe is data theft and extortion.

Security company Rapid7 reported in 2025 that KillSec began as a hacktivist group, active since at least 2021, and turned to ransomware in October 2023. Its ransomware, KillSecurity 2.0 and 3.0, is designed to encrypt files, although in some incidents the group extorted victims with stolen data alone. In June 2024, it began offering the ransomware to affiliates, a model known as ransomware-as-a-service.

What Remains Open

Eurojust said the authorities taking part "successfully shut down a ransomware group" and will now continue their investigation. Hamburg police said inquiries into other possible members continue.

Investigators are examining the seized devices and data and tracing the group's money, including cryptocurrency. The evidence may identify more victims, attacks and suspects.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article