HomeSecurityKillSec: 18-year-old arrested in Athens, alleged leader of the group is 16-year-old

KillSec: 18-year-old arrested in Athens, alleged leader of the group is 16-year-old

A 16-year-old is believed by authorities to be the main administrator of KillSec, a ransomware group that is responsible for almost 1,000 cyberattacks worldwide. The international operation against the group, codenamed KillSwitch, also had a Greek component: the investigation into KillSec in Athens led to the arrest of an 18-year-old foreigner, who allegedly played the role of the group's programmer.

The operation took place on 30 September 2026 and was announced the following day by Europol and Eurojust. In total, three arrests were made and eight house searches were conducted in Greece, Romania, Spain and the United Kingdom. The 16-year-old was arrested in Spain. All those involved are suspects and have not been found guilty by a court.

Seized equipment from the KillSec investigation in Athens

What did the Hellenic Police find about KillSec in Athens?

The investigation in Greece was undertaken by the Hellenic Police Cybercrime Prosecution Directorate, following information received from the authorities in Germany, Romania and the USA. The police located the 18-year-old's residence in an area of ​​Athens and conducted a search by order of a prosecutor. Representatives of the German and Romanian authorities also attended the investigation, as members of the joint investigation team that had been established for the case, as reported by Potiki.

A laptop, four mobile phones, two hard drives, two USB sticks and a diary with handwritten notes were seized from his home. Backups of conversations on a messaging app were found on one of the USB sticks. The 18-year-old was a minor when some of the acts under investigation were allegedly committed, as he turned 18 in August. The announcements do not mention the specific charges against him.

See also: 16-year-old suspect in KillSec management in the hands of authorities

Nine countries and five servers

The operation was coordinated by the Public Prosecutor's Office and the State Criminal Investigation Service of Hamburg, with the support of Eurojust and Europol. According to Eurojust, authorities from nine countries participated: Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom and the United States. Europol also mentions the Netherlands. Greece was one of four countries, along with Belgium, Germany and Romania, that formed the joint investigation team at Eurojust.

Law enforcement agencies involved in the operation took control of five central servers through which the group managed its activity and stored victims’ data. They also took control of the KillSec leak website, where the group published the stolen files, as well as the domain names it used. Anyone visiting these addresses now sees a seizure notice from the authorities. In this way, at least 110 terabytes of data were protected from further access.

KillSec servers under control of authorities

How did the team act?

KillSec has been active since at least 2024. According to Europol, its members exploited software vulnerabilities and poorly protected access points, mainly in cloud storage services, to break into organizations' systems. They then copied sensitive internal data to their own servers and demanded ransom, threatening to publish the files.

To prove they actually had the data, they sent victims samples of the files. If an organization did not pay, its files were made available for free download. In some cases, according to Eurojust, the group collected significant amounts of ransom. Of the approximately 1,000 attacks being investigated, 500 have so far been confirmed as successful, a number that could change as the seized data is examined.

Teenager in front of computer at night

Researchers have identified individuals with specific roles within the group: an administrator, a programmer, a negotiator, who negotiated with victims about the ransom, and an affiliate, someone who carried out attacks on behalf of the group. Cybersecurity firm Bitdefender, which supported the investigation, notes that the leak site had recorded a total of nearly 300 victims. The group posted its last victim on September 18, 2026, twelve days before the operation. The search for the remaining members of the group is ongoing.

What should organizations check?

The case shows that such an attack does not require sophisticated malware. All it takes is a misconfigured cloud storage account or a system without security updates. The SecNews technical team recommends that organizations check which folders and cloud storage spaces are accessible from the internet, enable multi-factor authentication (MFA) on all administrative accounts, and immediately install security updates on systems exposed to the internet.

Poorly protected cloud storage

The arrest for KillSec in Athens highlights another element of the case: the young age of the suspects. The alleged ringleader is 16 years old and the alleged programmer was a minor for part of his actions. For organizations, the conclusion is simple: the threat comes not only from large, experienced teams, but also from young attackers who exploit basic security vulnerabilities.

See also: Dutch police arrest hackers in ShinyHunters investigation

See also: TeamCity: Ransomware gangs exploit critical vulnerability

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS