Spanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware Group
Spanish police detained a 16-year-old Romanian in Alicante on suspicion of acting as the administrator and principal operator of the KillSec ransomware group, part of a broader law enforcement sweep that seized servers and at least 110 terabytes of stolen data. Authorities in multiple countries including the U.S., UK, Romania, Greece and Spain coordinated Operation KillSwitch, and one suspect in Britain faces extradition to Puerto Rico after a federal indictment.

Why It Matters
The arrests and seizures disrupt a transnational ransomware group accused of hundreds of breaches and illuminate how crypto and AI tools are being used to run modern extortion campaigns. The operation also demonstrates coordinated international law enforcement efforts to identify victims and trace illicit proceeds across borders.
Key Facts
- Operation name: Operation KillSwitch
- Primary arrest: 16-year-old Romanian national detained in Alicante
- Other arrests: Two people in their twenties arrested (one in Britain, one in Romania); a fourth suspect identified but not arrested
- Indicted suspect: Fouad Eltibrizi, Dutch national resident in the UK, indicted in Puerto Rico and arrested pending extradition
- Data secured: At least 110 terabytes of stolen data seized
Spanish police have detained a 16-year-old Romanian in Alicante on suspicion of being the administrator and main operator of the KillSec ransomware group, Europol said. The arrest came during Operation KillSwitch, a multinational investigation led by the Hamburg State Criminal Police Office and the city's public prosecutor that targeted roughly 1,000 suspected intrusions, about 500 of which investigators have identified as successful. Law enforcement actions on September 30 included searches of eight properties in Spain, Greece, Romania and the UK.
Authorities also arrested two people in their twenties — one in Britain and one in Romania — and have identified a fourth suspect, a developer who was a minor at the time some offenses were allegedly committed but has not been taken into custody. Separately, Fouad Eltibrizi, a Dutch national living in the UK and known online as Archduke, was indicted by a federal grand jury in Puerto Rico on September 16 for conspiracy to access computers for financial gain, damaging protected computers and transmitting extortion threats; he was arrested in the UK and is facing extradition proceedings.
Investigators say they secured at least five central servers and redirected domains to seizure notices, and have taken control of KillSec’s leak site. Law enforcement recovered a minimum of 110 terabytes of data, and Europol reported that seized devices are being forensically examined while specialists trace the group's proceeds, including cryptocurrency. Officials noted KillSec used double-extortion tactics — encrypting systems and threatening to publish stolen data if victims did not pay — and frequently demanded ransoms in crypto.
KillSec has been active since around 2024, according to Europol, exploiting software flaws and weakly protected cloud access to copy internal files to infrastructure it controlled. U.S. prosecutors allege the group published patient data from a Puerto Rico breach in March 2025 and released roughly 180GB when a company did not meet a seven-day ultimatum; the indictment references similar incidents in California, Washington State and Louisiana. Swiss authorities have been investigating attacks on Swiss firms dating from October 2023 through June 2025, and Europol said investigators found the group used AI to develop and maintain its ransomware operations and to identify potential targets.
In the UK, police identified 28 victim companies and arrested a 25-year-old in Levenshulme, Manchester, who is suspected of negotiating with victims. Law enforcement officials emphasized the broad financial and operational harm ransomware causes as the cross-border action continues and tracing of criminal proceeds proceeds with crypto-tracing and digital forensics support from Europol’s European Cybercrime Centre.
Keep Reading

Fiserv Launches Roughrider Coin Settlement on Solana

SMBC Nikko and Nethermind Plan Compliance Hooks for Uniswap Pools

Morning Minute: NEAR Intents Hacked for $3.8M - Was It A Bullish Hack?

'Uptober' Off With a Bang as Bitcoin Surges to $86K
Original source: Decrypt