Read as article
KillSec Ransomware Gang Dismantled; Alleged Leader Is 16
By @sharedot · · 8 pages
- Cybersecurity
- Ransomware
- Killsec
- Operation Killswitch
- Europol
An international operation seized KillSec's servers and leak site, arresting three suspects, with Europol identifying a 16-year-old as the group's alleged administrator.
The takedown: Operation KillSwitch
On September 30, authorities from ten countries including the US, Germany, Spain, Romania, and the UK seized KillSec's dark web leak site and five central servers, now displaying a law-enforcement seizure banner. Investigators provisionally arrested three suspects and searched eight properties across Greece, Romania, Spain, and the United Kingdom. The leak site had listed victims as recently as September 27, three days before the seizure, showing the group was still active when police moved in.
Why it's surprising: teenagers ran the crew
Europol says the alleged administrator and main operator of KillSec is only 16 years old, while a suspected developer turned 18 in August 2026 and was a minor when some alleged crimes were committed. According to Risky Biz, the arrested Romanian teenager was living in Alicante, Spain, and a Dutch national named Fouad Eltibrizi was arrested in the UK — the US has filed an extradition request over a March 2025 attack on a Puerto Rico company. The probe also found the group used AI to build its ransomware infrastructure and identify potential victims.
The evidence against a low-tier but prolific gang
Investigators linked KillSec to roughly 1,000 suspected cyberattacks worldwide, with about 500 determined successful so far — a figure authorities caution may change as evidence is analyzed. At least 70 suspected attacks connect to organizations in Germany, including 18 in Hamburg. The FBI said at least 110 terabytes of seized data was secured against further criminal access. KillSec operated a Ransomware-as-a-Service scheme launched in June 2024 charging a $250 entry fee while affiliates kept 88% of successful ransom payments, per Risky Biz.
How KillSec broke in
Europol says the group exploited software vulnerabilities, unpatched servers, and poorly secured cloud storage and edge devices to breach corporate networks, steal sensitive data, and deploy ransomware. It ran double-extortion schemes, naming victims on its leak site and threatening publication unless paid, and obtained substantial ransom payments in some cases. KillSec was also linked to the zero-day CVE-2025-31161 in CrushFTP, according to Risky Biz.
Why it matters
The case shows how little infrastructure a damaging ransomware crew needs: a teenage operator, weak cloud settings, and AI-assisted tooling. Police control of the leak site cuts off free downloads of stolen files, though it cannot recall copies already taken by others. The investigation also underscores the persistent trend of teenagers fueling cybercrime, prompting efforts to steer youngsters away from hacking for profit.
What comes next
Investigators are examining seized devices and tracing criminal proceeds including cryptocurrency, and Europol says the evidence could reveal further victims, attacks, and suspects. The US Justice Department says Fouad Eltibrizi, if convicted, faces up to 10 years in prison. Organizations storing data in cloud services can reduce copycat risk by auditing public access settings and rotating exposed keys. Anyone contacted by KillSec can report it to national police.
Sources
- bleepingcomputer.com › Police dismantle KillSec ransomware gang allegedly led by 16-year-old
- pcmag.com › Europol: Leader of 'KillSec' Ransomware Group Is a 16-Year-Old
- news.risky.biz › Authorities dismantle KillSec group, arrest members across Europe
- sqmagazine.co.uk › Europol Targets KillSec in Massive Ransomware Operation