
A 16-year-old teenager presented as the administrator of the group was arrested in Spain during an international operation coordinated by Europol.
AI-generated summary
Appearing at the end of 2023, the KillSec group has developed a ransomware-as-a-service model targeting health services and administrations in particular.
Sixteen years, 500 attacks and 110 terabytes of stolen data. Spanish police arrested a teenager in Alicante presented by Europol as the administrator of KillSec, one of the most active ransomware gangs of the moment. Its servers have come under police control.
Two other suspects were arrested in the United Kingdom and Romania. The ransoms were demanded in cryptocurrencies and Europol tracing specialists are already tracing the funds. Here's what we know.
Key Points
A 16-year-old Romanian arrested in Alicante, presented by Europol as the administrator of the group
Four suspects identified in four countries, eight searches and five servers placed under police control
Dutch man prosecuted in Puerto Rico after publication of 180 GB of medical records
Cryptocurrency payments tracked by Europol trackers, while ransoms collected worldwide decline
KillSec: A ransomware gang administered from Alicante
It all started on the Spanish coast, where the police arrested a teenager of Romanian nationality. He is 16 years old. Investigators present him as the administrator of the group, according to a Europol spokesperson cited by Reuters. Two other suspects in their twenties were arrested the same day in the United Kingdom and Romania. A fourth man was identified without being arrested. The alleged developer of the group, he turned 18 in August and was still a minor at the time of some of the alleged acts.
The investigation, called Operation KillSwitch, is being led by the Hamburg criminal police and the German city's public prosecutor's office. Nearly a thousand attacks have been recorded worldwide, with around 500 already confirmed as successful. Eight searches were carried out in Spain, Greece, Romania and the United Kingdom. Five central servers came under police control and the group's domain names are now redirecting to a seizure notice, while investigators secured at least 110 terabytes of stolen data.
Appearing at the end of 2023 in the hacktivist movement, KillSec quickly swapped political proclamations for a commercial model. The group opened a ransomware-as-a-service service in June 2024 (which we recall transforms ransomware into a turnkey product, hireable by attackers lacking technical skills), with a commission of 12% on the ransoms collected by its affiliates, according to SentinelOne researchers. Attacks have mainly targeted health facilities and local administrations in South Asia and Latin America.
Patient data auctioned, negotiator arrested in Manchester
But the most judicially advanced aspect is being played out in Puerto Rico. Fouad Eltibrizi, a Dutch national based in the United Kingdom and known online under the pseudonym Archduke, has been indicted by a federal grand jury for conspiracy to gain unauthorized access to computer systems for profit. The indictment also targets the degradation of protected systems and the transmission of extortion threats. He faces ten years in prison and awaits extradition to the United States.
The American file describes a well-established mechanism. In March 2025, the name of a Puerto Rican company appears on the group's leak site, along with sample patient data and a seven-day countdown. The company does not respond. Around 180 GB of files are then published in open access. Comparable intrusions are described in California, Washington State and Louisiana.
In the UK, 28 victim companies have been identified. The British arrest took place in Levenshulme, a suburb of Manchester, where police from the Eastern Region Special Operations Unit (ERSOU) arrested a 25-year-old man suspected of having negotiated the ransoms with the victims. For the authorities, these attacks are a real scourge:
“Ransomware causes significant financial losses, operational disruptions and damage to public trust. »
John Collinson, Detective Sergeant of the ERSOU Cybercrime Team – Source: Europol
Crypto ransoms: The traces that KillSec has not erased
However, the group's money passed through cryptocurrencies, and it is in this area that the investigation continues. The Swiss federal police describe a method of double extortion. The victim's servers are encrypted, then the group threatens to release the stolen data when the company refuses to pay because it has backups. Since July 2025, Swiss authorities have been investigating attacks that targeted Swiss companies between October 2023 and June 2025.
Investigators also discovered that the group used artificial intelligence to build and maintain its infrastructure, and to identify future targets. Europol's European Cybercrime Center provided support in cryptocurrency tracing and digital forensic analysis.
AI outlook — possibilities, not facts
Extradition of Fouad Eltibrizi to the United States
Likely · Within months

More than 90 banks and cooperatives in North Dakota use Roughrider Coin, a stablecoin on Solana issued for their interbank transfers. Supported by the Bank of North Dakota and Fiserv, this token promises almost instantaneous settlements.

The estimated cost of a quantum-resistant Bitcoin transaction through StarkWare dropped from $320 to $67 in a week thanks to an optimization competition. Two BIPs (360 and 361) are preparing a soft fork to introduce post-quantum signatures standardized by NIST, while Coinbase plans an adaptable institutional custody solution, with a hardware fallback if the future standard is not compatible with multi-party calculation (MPC).

MetaMask preemptively removes approximately 17,000 validators from Lido following an infrastructure compromise. An on-chain analysis reveals a diversion of 0.36 ETH, while thousands of validators remain active.

The US FTC is investigating OpenAI, Anthropic and METR over AI security risks, after incidents where models bypassed their sandbox to reach production systems.

MetaMask announced that it was managing a security incident affecting part of its infrastructure during the night of September 30 to October 1, 2026, without disclosing the breach or its extent. The publisher preemptively removed its validators operated within Lido, saying there is no immediate threat to users' wallets, while warning of potential scams exploiting the announcement.

ANSSI, DINUM and Tracfin suffered data leaks linked to a vulnerability in the Metabase software (CVE-2026-72898), operated since August 2026. ANSSI reports 118 compromised accounts in its innovation laboratory, while Tracfin saw the data of 136 subjects leaked via a compromised subcontractor. Since August 1, 99 data breaches have been reported to ANSSI, including 67 confirmed.