German authorities have identified a 16-year-old as the alleged mastermind of the KillSec ransomware operation, following a coordinated law enforcement operation that resulted in the arrests of three suspects and searches of eight properties in Spain, Greece, Romania, and the UK.
In an Oct. 1 statement, Hamburg police said investigators also took control of KillSec’s leak website and secured at least 110TB of data to prevent further unauthorized access.
“Operation KillSwitch” Cybercrime Takedown
The developments stem from “Operation KillSwitch,” an international investigation that German law enforcement led into roughly 1,000 suspected KillSec cyberattacks worldwide, at least 70 of which involved government organizations. Investigators have so far confirmed about 500 of those attacks to be successful.
Authorities from multiple countries, including Germany, the United States, the United Kingdom, Spain, Romania, and Greece, took part in the investigation. Europol and Eurojust coordinated the international effort, while cybersecurity firms Bitdefender and Group-IB provided technical support.
“The coordinated action targeted both the people behind KillSec and the systems they relied on,” Europol said in a press statement. Authorities raided eight homes across four countries, provisionally arrested three individuals, and took control of five servers and other infrastructure that KillSec was using to manage its activities and store victim data, it added. “Authorities also took control of domains operated by KillSec and redirected visitors to a law enforcement seizure notice.”
Reuters described the 16-year-old as a Romanian national who was arrested in the Spanish city of Alicante. Reuters quoted a Europol spokesman as describing the teen as the “administrator” of the KillSec operation. Separately, the US Justice Department indicted Dutch national Fouad Eltibrizi for his alleged role related to the KillSec operation. Meanwhile, police in the UK arrested Eltibrizi (aka “Archduke”) on Sept. 30 and are preparing to extradite him to the US, where he will face charges related to unauthorized computer access conspiracy. He faces a maximum sentence of 10 years in prison if convicted.
Suspect Orchestrated Opportunistic Ransomware Attacks
KillSec is a prolific ransomware group that surfaced in 2024 and became known for exploiting known vulnerabilities and poorly secured access points, particularly in cloud environments, to gain access to enterprise systems and exfiltrate data. The group then used its leak site to publicly name victims and threaten to publish stolen files unless they paid a ransom, says Alexandru Nicola Stoica, senior threat researcher at Bitdefender DracoTeam, in comments to Dark Reading. Investigators also found evidence that the group used AI to build and maintain its infrastructure and identify potential victims, Stoica says.
Bitdefender, which has tracked KillSec since 2024, provided technical assistance, infrastructure mapping, and continuous monitoring support for Operation KillSwitch for more than a year, Stoica says. The company has observed nearly 300 victims appearing on KillSec’s leak site since the company began tracking the threat actor.
“The group posted 126 victims in 2025 and 25 in 2026, the most recent on Sept. 18, 12 days before action day on the last leak site they used,” Stoica says, but cautions that leak-site counts do not necessarily reflect the actual number of victims claimed by a threat actor. “KillSec is mostly opportunistic with its targets,” he adds, “and we don’t have an estimate of losses” to victims.


