Press play to start listening
An international police operation has disrupted the KillSec ransomware group, with three suspects arrested, five servers seized and at least 110 terabytes of stolen data placed under law enforcement control. Investigators say the suspected administrator and main operator is only 16 years old.
The operation took place on September 30 as part of Operation KillSwitch, an investigation led by German authorities into roughly 1,000 suspected attacks worldwide. Eurojust and Europol coordinated authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom and the United States.
Visitors to KillSec’s dark web leak site now see a seizure notice stating that the domain, servers and associated data have been taken under the control of the State Criminal Police Office of Hamburg and international law enforcement agencies. The separate Operation KillSwitch website also confirms the coordinated action against the group.

Teenager Identified as Suspected Main Operator
Investigators identified several people suspected of performing different jobs for KillSec, including an administrator, developer, negotiator and affiliate. According to Eurojust’s press release, the teenager suspected of serving as administrator was also considered the group’s main operator. Another suspected developer turned 18 in August 2026 and was still a minor when some of the alleged offences took place.
Spanish authorities arrested the 16-year-old in Alicante, according to additional information released Thursday. He is a Romanian national. Two other suspects in their twenties were arrested in Britain and Romania, while the suspected 18-year-old developer has been identified but was not reported as arrested.
One of those detained in Britain is a 25-year-old man suspected of negotiating with KillSec victims. The Eastern Region Special Operations Unit said he was arrested in Manchester and was due to appear at Westminster Magistrates’ Court on October 1 for an extradition hearing.
KillSec Linked to Around 1,000 Attacks
Active since around 2024, KillSec gained access to organisations by exploiting software vulnerabilities and poorly secured entry points, particularly systems connected to cloud storage. Stolen information was copied to infrastructure controlled by the group and used to pressure victims into paying ransoms.
Victims were named on KillSec’s leak site and sent samples of stolen information as proof that the attackers had their files. Organisations that refused to pay could have their information published for free. Authorities said the group received substantial ransom payments in some cases.
Investigators have so far identified around 500 attacks that were successful, although that number could change as seized evidence is examined. Europol also said investigators found that KillSec members used artificial intelligence to help build and maintain their ransomware infrastructure and identify targets.
Five Servers and 110TB of Data Seized
Police searched eight properties in Greece, Romania, Spain and the UK during the coordinated action. Five servers used by KillSec were seized, including infrastructure holding information stolen from victims, while authorities also took control of domains operated by the group.
At least 110TB of stolen data was secured against further unauthorised access. The amount gives investigators a substantial body of evidence to examine as they work to identify additional victims and people suspected of participating in KillSec.

Authorities are also following the group’s financial activity. Europol provided specialist assistance for cryptocurrency tracing and examination of digital evidence, while investigators are now analysing seized devices, servers and other material for links to further attacks.
The operation remains active. Law enforcement has not said that every suspected KillSec member has been arrested, and Eurojust said the seized evidence could identify additional victims, attacks and people involved with the group.
Alicante Has Seen Other Young Hacker Arrests
This is not the first time Alicante has appeared in a case involving an alleged teenage hacker. Back in 2012, Hackread.com reported that police arrested a 16-year-old in Alicante accused of infecting computers with a Trojan and stealing bank details, social media passwords, emails, addresses and other personal information.
The teenager was also accused of blackmailing victims and had allegedly used a neighbour’s internet connection without permission, initially leading police to the wrong person.
Another case surfaced in February 2025, when an 18-year-old known online as “Natohub” was arrested in Calpe, Alicante. Spanish authorities suspected him of more than 40 attacks against public and private organisations, with targets linked to NATO, the US Army, the United Nations and Spain’s Civil Guard and government ministries. Police seized computer equipment, an iPhone and access to around 50 cryptocurrency accounts during the investigation.
Alicante was also the location of a major cybercrime arrest in December 2023, although that case did not involve a teenager. Spanish police arrested a Venezuelan national accused of leading the financial operations of the Kelvin Security hacker group.
Authorities linked the group to more than 300 attacks against organisations in over 90 countries and accused the suspect of laundering proceeds through cryptocurrency exchanges.