International Law Enforcement Seizes KillSec Ransomware Servers and Arrests Three Suspects

Investigators found that KillSec used artificial intelligence to help build and maintain its ransomware infrastructure.
The US charges against Dutch national Fouad Eltibrizi include alleged conspiracy to access computers without authorization for financial gain, damage protected computers, and transmit threats to obtain information for extortion; the US is seeking his extradition.
There is a discrepancy over when KillSec began: Romanian police said a 24-year-old helped establish the group in October 2023, while other authorities date its formation to 2024.
Spanish police also referred to a woman who remains under investigation in connection with the case but was not arrested.
International law enforcement shut down KillSec, a ransomware gang that stole data from roughly 500 organizations worldwide. Shattered.io reported that Operation KillSwitch — a coordinated raid across eight locations — resulted in three arrests and the seizure of five central servers holding at least 110 terabytes of stolen data. Authorities believe a 16-year-old Romanian is the group's main operator, though conflicting reports dispute whether the teenager was among those arrested.
The takedown recovered victim data and dismantled KillSec's dark-web leak site on September 30, 2026. The Register noted that investigators traced roughly 1,000 suspected attacks to the group since its formation around 2024. A Dutch national named Fouad Eltibrizi faces U.S. extradition on charges of unauthorized computer access and extortion conspiracy.
KillSec operated as a ransomware-as-a-service outfit targeting organizations with unpatched software and weak cloud access points. ITPro reported that the gang stole sensitive files, then extorted victims or sold data on dark-web forums. Threat researchers from Group-IB and Bitdefender noted KillSec used artificial intelligence to accelerate malware development and manage its infrastructure — a sign that even small cybercrime teams now rely on automation to scale attacks.
Spanish Civil Guard and Catalan authorities arrested a 16-year-old in Alicante, Spain, on suspicion of leading the operation. CryptoNews reported that a Dutch national called Fouad Eltibrizi was also arrested in the UK on a U.S. extradition warrant. A third suspect — described as an 18-year-old developer — was taken into custody by Hamburg Police in Germany. Spanish authorities identified a woman under investigation but did not arrest her.
The September 30, 2026 raids seized five management servers and took control of KillSec's leak site. Mexico Business News noted authorities also recovered cryptocurrency assets tied to the operation. Confusion initially surrounded whether the 16-year-old suspected leader was arrested or under surveillance — Spanish police later confirmed the arrest.
KillSec targeted roughly 1,000 organizations worldwide, with about 500 attacks confirmed successful. The Register reported that extortion demands ranged from $5,000 to $500,000 per victim. Threat intelligence firm Group-IB logged 274 publicly claimed victim organizations on KillSec's leak site before shutdown. Researchers found 35% of victims were U.S.-based, 17% were Indian, and at least 70 incidents involved government agencies.
U.S. federal prosecutors in Puerto Rico indicted Fouad Eltibrizi on September 16, 2026, on charges including conspiracy to access computers without authorization and transmit extortion threats. The U.S. government is seeking his extradition from the UK. Héctor Ramírez-Carbó, the acting U.S. attorney, stated the group "carried out targeted intrusions, stealing highly sensitive information and attempting to extort victims for substantial sums." Juvenile proceedings will govern the 16-year-old suspect in Spain.
Security analysts expressed alarm over the rising involvement of minors in high-impact ransomware syndicates. AI tools have lowered technical barriers — teenagers can now run sophisticated operations without extensive hacking experience. The seizure of 110 terabytes prevents further data leaks and allows law enforcement to notify affected organizations and assist with damage control.
Publishers
26
Articles
18
Reach
44