International Edition

Friday, 2 October 2026

Private Trade News

Global markets, trading & world business — for professional traders

Crypto

Spanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware Group

Private Trade News trader edition (2026-10-02): A second suspect faces extradition to Puerto Rico, while Investigators are tracing the proceeds of ransoms the group demanded in crypto. Primary source: original at Decrypt (decrypt.co).

· Decrypt

In brief

  • Spanish police arrested a 16-year-old Romanian national in Alicante, suspected of being KillSec's administrator and main operator.
  • A Dutch national living in the UK has been indicted in Puerto Rico and arrested pending extradition.
  • Investigators are tracing the group's criminal proceeds, including cryptocurrency.

Spanish police have arrested a 16-year-old suspected of being the main operator of the KillSec ransomware group, as law enforcement across Europe seized its servers and leak site and secured at least 110 terabytes of stolen data, Europol said.

The teenager, a Romanian national detained in Alicante, is suspected of acting as the group's administrator, a Europol spokesperson told Reuters. Two other people in their twenties were arrested, one in Britain and one in Romania. A fourth suspect, a developer who turned 18 in August and was a minor when some of the offences were committed, has been identified but not arrested.

The September 30 action was part of Operation KillSwitch, an investigation led by the Hamburg State Criminal Police Office and the city's public prosecutor into around 1,000 suspected attacks worldwide, of which about 500 have so far been identified as successful. Eight properties were searched in Spain, Greece, Romania and the UK.

The man held in Britain faces charges in the U.S. Fouad Eltibrizi, a Dutch national resident in the UK who used the handle Archduke, was indicted by a federal grand jury in Puerto Rico on September 16 over conspiracy to access computers without authorization for financial gain, damaging protected computers and transmitting extortion threats. He was arrested the following fortnight and faces extradition, with a maximum penalty of 10 years.

Today we’re announcing Operation KillSwitch, a joint sequenced operation led by @FBISanJuan targeting the Kill Security Ransomware Group (“KillSec”). Authorities in the U.S. and Europe took control of KillSec’s leak site, securing at least 110 terabytes of data against further… pic.twitter.com/ZYvxosEPyv

— FBI Cyber Division (@FBICyberDiv) October 1, 2026

U.S. prosecutors say KillSec posted a Puerto Rico breach on its leak site in March 2025 with samples of stolen patient data and a seven-day countdown. When the company did not respond, roughly 180GB were published. The indictment describes similar breaches in California, Washington State and Louisiana.

KillSec and crypto

KillSec has been active since around 2024, exploiting software vulnerabilities and poorly secured access points, particularly to cloud storage, to reach organizations' systems and copy internal data to infrastructure it controlled, Europol said in a statement. Victims were named on its dark web leak site and threatened with publication unless they paid, with files released for free download where no payment came.

The group used double extortion, encrypting servers and then threatening to publish the data if a company declined to pay because it had backups, Switzerland's federal police said. Ransoms were often demanded in cryptocurrency. Swiss prosecutors have been investigating since July 2025 over attacks on Swiss companies between October 2023 and June 2025.

Investigators also found the group had used AI to build and maintain its ransomware infrastructure and to identify potential victims.

Five central servers are now under police control, along with domains redirected to a seizure notice. Investigators are examining seized devices and tracing the group's proceeds, including cryptocurrency, work Europol's European Cybercrime Centre supported with specialist crypto-tracing and digital forensics.

In the UK, where 28 victim companies have been identified, officers from the Eastern Region Special Operations Unit arrested a 25-year-old suspected of negotiating with victims at an address in Levenshulme, Manchester. Ransomware causes "significant financial losses, operational disruption and harm to public confidence," Detective Sergeant John Collinson of the unit's cyber crime team said.