HomeSecurity16-year-old suspect in KillSec management in hands of authorities

16-year-old suspect in KillSec management in hands of authorities

An international cybercrime law enforcement operation has led to the arrest of three suspects allegedly linked to the KillSec ransomware group, which is accused of stealing sensitive data from organizations and blackmailing its victims with ransom demands. Among those arrested is a 16-year-old in Spain, whom investigators believe is a key administrator of the group.

Article Image: Police Arrest 16-Year-Old Suspect of Running KillSec, Seize Ransomware Leak Site and Servers

The operation took place on September 30, with the participation of police and prosecutors from different countries. In addition to the arrests, the authorities took control of the website through which KillSec was publishing information about its victims and threatening to distribute the stolen files. During the operation, at least 110 terabytes of data were secured, while critical parts of the group's digital infrastructure were disabled.

The case highlights the international dimension of ransomware attacks, as well as the way in which organized cybercrime networks leverage stolen credentials, software vulnerabilities, cloud services and artificial intelligence tools to expand their activity.

International operation with arrests in three countries

According to a statement from Hamburg police on October 1, German authorities coordinated the operation in cooperation with the relevant services of other countries. The 16-year-old was arrested in the province of Alicante, Spain, by the Guardia Civil and the Mossos d'Esquadra. At the same time, searches were carried out at a residence and an office located in a hotel in the same province.

See also: KillSec ransomware targets healthcare sector

The two other arrested are adults and were located in the United Kingdom and Romania. A Europol spokesman confirmed to Reuters that the relevant authorities of those countries were involved in the operation, while Puerto Rico has submitted an extradition request for the suspect arrested in the United Kingdom.

In Romania, the DIICOT agency, which is responsible for combating organized crime and terrorism, arrested a 24-year-old and searched four homes in Bucharest and Vaslui county. The charges under investigation include, among others, forming a criminal organization, illegal access to information systems, unauthorized data transfer and extortion.

Prosecutors had requested that the 24-year-old be remanded in custody for 30 days. However, the three arrests were described as provisional by Hamburg police and all suspects are presumed innocent until proven guilty.

16-year-old suspect in KillSec management in hands of authorities

110 TB of data seized and servers deactivated

One of the most significant results of the operation was the neutralization of key infrastructure allegedly used for KillSec attacks. Authorities conducted a total of eight searches in Spain, Greece, the United Kingdom and Romania, and secured at least 110 TB of data from the seized infrastructure.

At the same time, German authorities took down five servers, including the group's main server and systems that allegedly stored files that had been removed from victim organizations. In addition, seizure flags were placed on five domains linked to its activity.

Computers, mobile phones and cryptocurrency wallets were seized in Spain . Initial examination of the data revealed transactions that appear to correspond to ransom payments from some victims.

Analyzing the massive amount of data is expected to be a critical stage of the investigation. The files may include communications between those involved, information about previous attacks, financial transactions and information that could lead to the identification of additional collaborators.

How KillSec's extortion model worked

According to authorities, KillSec allegedly gained access to corporate and other information systems by exploiting vulnerabilities , poorly protected services, and weak access points, particularly in cloud environments.

DIICOT prosecutors also said that members of the group purchased access credentials from illegal dark web marketplaces. This way, attackers could leverage already compromised accounts, without always having to develop a new penetration method themselves.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Once they gained access, they allegedly copied confidential files to servers they controlled. They then posted the organization’s name on a website data leak and threatened to release or sell the information if a ransom was not paid. In some cases, they sent victims samples of the stolen files as proof that they had indeed gained access.

This tactic is known as data extortion. It differs from a traditional ransomware attack, in which attackers encrypt files and demand money to restore them. In data extortion, the threat of releasing sensitive information can be made even without encrypting systems.

Spanish police estimate the number of victims at more than 280, while the overall investigation is looking into around 1,000 suspected attacks worldwide. Around 500 of these have so far been deemed successful, a number that could change as seized evidence is examined.

See also: Dubai Police: Beware of fake travel offers

Qilin ransomware leak site dark web victim list

Artificial intelligence in the team's arsenal

Of particular interest is the researchers' report that KillSec allegedly used artificial intelligence to develop and operate parts of its infrastructure, as well as to identify potential targets. Authorities did not provide further details about the tools or specific applications used.

The use of AI by criminal groups is a growing challenge for cybersecurity. Automated tools can speed up information processing, data organization and the search for potential targets. However, in this case, it is not clear to what extent artificial intelligence contributed to the attacks.

According to cybersecurity firm Rapid7, KillSec has been active since at least 2021, initially with hacktivist characteristics, before turning to ransomware in October 2023. Since June 2024, it has reportedly been distributing its malware to partners, following the model Ransomware-as-a-Service (RaaS). In this system, the creators provide the tools and other partners undertake attacks, with a potential revenue split.

See also: TeamCity: Ransomware gangs exploit critical vulnerability

The investigation continues

The investigation into the case began in 2025, with the participation of the Guardia Civil and the FBI in San Juan, Puerto Rico. At the same time, the Mossos d'Esquadra investigated an attack on a Catalan organization, earlier that year, with estimated damages approaching one million euros.

Europol and Eurojust coordinated the international cooperation, with support from Bitdefender and Group-IB. Authorities continue to examine the seized devices and trace financial transactions, including cryptocurrencies.

For businesses, the case highlights the importance of multi-factor authentication, promptly installing security updates, protecting cloud services, and maintaining isolated backups. Equally critical are incident response plans and the ability to quickly identify unauthorized access.

The dismantling of part of the KillSec infrastructure is an important development for the investigation, but it does not necessarily mean that all the individuals involved or all the victims have been identified. Digital findings and analysis of financial transactions will determine the authorities' next steps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS