
Europol says law enforcement across Europe seized servers and 110TB of stolen data in Operation KillSwitch.
AI-generated summary
KillSec has operated since around 2024, utilizing double extortion tactics, software vulnerabilities, and AI to execute ransomware attacks.
Spanish police have arrested a 16-year-old suspected of being the main operator of the KillSec ransomware group, as law enforcement across Europe seized its servers and leak site and secured at least 110 terabytes of stolen data, Europol said.
The teenager, a Romanian national detained in Alicante, is suspected of acting as the group's administrator, a Europol spokesperson told Reuters. Two other people in their twenties were arrested, one in Britain and one in Romania. A fourth suspect, a developer who turned 18 in August and was a minor when some of the offences were committed, has been identified but not arrested.
The September 30 action was part of Operation KillSwitch, an investigation led by the Hamburg State Criminal Police Office and the city's public prosecutor into around 1,000 suspected attacks worldwide, of which about 500 have so far been identified as successful. Eight properties were searched in Spain, Greece, Romania and the UK.
The man held in Britain faces charges in the U.S. Fouad Eltibrizi, a Dutch national resident in the UK who used the handle Archduke, was indicted by a federal grand jury in Puerto Rico on September 16 over conspiracy to access computers without authorization for financial gain, damaging protected computers and transmitting extortion threats. He was arrested the following fortnight and faces extradition, with a maximum penalty of 10 years.
U.S. prosecutors say KillSec posted a Puerto Rico breach on its leak site in March 2025 with samples of stolen patient data and a seven-day countdown. When the company did not respond, roughly 180GB were published. The indictment describes similar breaches in California, Washington State and Louisiana.
KillSec and crypto
KillSec has been active since around 2024, exploiting software vulnerabilities and poorly secured access points, particularly to cloud storage, to reach organizations' systems and copy internal data to infrastructure it controlled, Europol said in a statement. Victims were named on its dark web leak site and threatened with publication unless they paid, with files released for free download where no payment came.
The group used double extortion, encrypting servers and then threatening to publish the data if a company declined to pay because it had backups, Switzerland's federal police said. Ransoms were often demanded in cryptocurrency. Swiss prosecutors have been investigating since July 2025 over attacks on Swiss companies between October 2023 and June 2025.
Investigators also found the group had used AI to build and maintain its ransomware infrastructure and to identify potential victims.
Five central servers are now under police control, along with domains redirected to a seizure notice. Investigators are examining seized devices and tracing the group's proceeds, including cryptocurrency, work Europol's European Cybercrime Centre supported with specialist crypto-tracing and digital forensics.
AI outlook — possibilities, not facts
Fouad Eltibrizi faces extradition to the U.S.
Very likely · Within weeks

Aave v3 remained unaffected after an exploit drained roughly $305,000 from two Safe multisig wallets using a third-party adapter. Blockchain security firm SlowMist reported the attack exploited an access-control flaw.

Core Lightning team urges operators to upgrade from version 26.06.7 or earlier after reports of attackers targeting unpatched nodes, following a September update that patched vulnerabilities including memory exhaustion and fund-loss risks.

NEAR Intents identified the individual responsible for a $3.8 million security breach involving user funds and gave them 48 hours to return the assets under responsible disclosure, pausing services and pledging full compensation while blockchain investigator ZachXBT traced funds to KuCoin and Bitcoin.

Crypto firms and users lost nearly $2.7 billion to security incidents in 2026 through September, with North Korea-linked thefts surpassing $1 billion. CertiK recorded 658 incidents, $420.4 million in recovered assets, and September alone accounted for $766.5 million in losses driven by major breaches at Bitget and Liquid Network. The concentration of losses in a few mega-hacks highlights systemic vulnerability, while physical 'wrench attacks' increased significantly in frequency and value.

OpenAI disrupted a coordinated extraction campaign aimed at copying its AI models' internal reasoning. The company attributed a core cluster of the activity to individuals associated with Chinese startup Moonshot AI.

Meta says its Muse AI agent cannot access iMessages on Mac without explicit user permission, requiring both Full Disk Access and its internal Messages connector to be enabled, countering a journalist's report that the app synced his texts despite denied access.