16-Year-Old Suspected KillSec Leader Arrested as Police Seize Ransomware Infrastructure

International authorities disrupted KillSec, arresting 3 suspects including its alleged 16-year-old operator and seizing infrastructure containing at least 110 TB of stolen data.
Operation KillSwitch seizure notice displayed after international law enforcement took control of KillSec infrastructure.
Operation KillSwitch seizure notice displayed following the international law enforcement disruption of KillSec’s infrastructure, including its servers and data leak site. Credit: Europol.

International law enforcement authorities have disrupted the KillSec ransomware and extortion operation, arresting 3 suspects, seizing its data leak site and taking control of infrastructure containing at least 110 TB of stolen victim data.

The coordinated operation, dubbed Operation KillSwitch, targeted a cybercrime group investigators link to around 1,000 suspected attacks worldwide. Authorities have so far determined that approximately 500 of those attacks were successful, although that number could increase as investigators examine seized evidence.

One of the most striking findings involves the suspected main operator. Europol says investigators identified a 16-year-old as KillSec’s alleged administrator and primary operator.

The Sept. 30 action included 8 property searches across Spain, Greece, Romania and the United Kingdom, 3 provisional arrests, infrastructure seizures and efforts to trace and seize the group’s alleged criminal proceeds.

Police seize KillSec leak site and 110 TB of data

Law enforcement took control of KillSec’s data leak site on Sept. 30, preventing further unauthorized access to at least 110 TB of information allegedly stolen from victims.

Authorities also seized 5 central servers during the investigation, including infrastructure allegedly used by KillSec to coordinate its activities and store stolen information.

Domains operated by KillSec were taken under law enforcement control and redirected to a seizure notice.

Investigators are now examining seized devices, servers and stolen data in an effort to identify additional victims, attacks and people associated with the operation.

The investigation is being led by the Hamburg State Criminal Police Office and Hamburg Public Prosecutor’s Office, with authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and United States participating alongside Europol and Eurojust.

Teenagers allegedly held key KillSec roles

Investigators say KillSec operated with members assigned different responsibilities, including administrator, developer, negotiator and affiliate roles.

The alleged administrator and main operator is only 16 years old, according to Europol.

Another suspected member identified as a developer turned 18 in August 2026 and was still a minor when some of the alleged criminal activity occurred.

Authorities have also identified suspects believed to have served as a negotiator and an affiliate. Investigations into additional suspected KillSec members remain ongoing.

Law enforcement has not publicly identified the teenage suspects, and BreachNews is not publishing individual cybercrime handles associated with the investigation.

KillSec linked to around 1,000 attacks

KillSec has operated since approximately 2024, using ransomware and data theft to pressure organizations into paying extortion demands.

According to Europol, the group and its alleged co-conspirators are linked to approximately 1,000 suspected attacks worldwide, with around 500 currently assessed as successful compromises.

After obtaining access, KillSec allegedly copied sensitive internal information to infrastructure controlled by the group.

Victims were subsequently added to KillSec’s data leak site and threatened with publication of the stolen information unless they paid a ransom. If an organization refused to pay, KillSec could release the stolen files publicly.

Investigators say the group received substantial ransom payments in some cases.

Authorities are investigating approximately 1,000 suspected KillSec attacks worldwide and have so far classified around 500 as successful compromises.

KillSec allegedly used AI to find victims

The investigation also uncovered evidence that KillSec incorporated artificial intelligence into its cybercrime operations.

Europol says investigators found that the group used AI to help build and maintain its ransomware infrastructure and identify potential victims.

Authorities have not disclosed which AI services or models KillSec allegedly used or detailed the extent to which automated tools contributed to its attacks.

The finding nevertheless provides another example of cybercrime groups incorporating AI into operational workflows rather than limiting its use to phishing content or social engineering.

U.S. charges KillSec suspect over extortion attacks

The U.S. Justice Department announced charges Thursday against an alleged KillSec participant arrested in the United Kingdom as part of the coordinated international operation.

Federal prosecutors in Puerto Rico allege that the suspect and co-conspirators targeted organizations from at least March through November 2025, exploiting vulnerabilities to access computer systems before stealing sensitive business and customer information.

According to the indictment, stolen information was transferred to infrastructure outside the victims’ networks before portions were published on KillSec’s leak site as leverage for ransom demands.

The charges include conspiracy to intentionally access computers without authorization for financial gain, intentionally causing damage to a protected computer and transmitting an extortion threat.

The suspect is awaiting extradition from the United Kingdom and faces up to 10 years in prison if convicted. The charges remain allegations and have not been proven in court.

Puerto Rico victim had 180 GB of patient data leaked

The U.S. case provides additional detail about the impact KillSec allegedly had on individual victims.

Prosecutors say KillSec announced the compromise of an organization in Puerto Rico in March 2025 and gave the victim 7 days to meet its ransom demand.

The group allegedly published samples of stolen patient information to demonstrate that it possessed the data.

When the victim did not comply with the demand, KillSec allegedly released approximately 180 GB of stolen information on the dark web.

The indictment also describes alleged KillSec compromises involving victims in California, Washington and Louisiana.

Operation KillSwitch targets infrastructure and money

Operation KillSwitch was designed to disrupt more than the group’s public leak site.

Authorities targeted KillSec members, hosting infrastructure, stolen information and alleged criminal proceeds simultaneously.

Europol supported investigators with intelligence analysis, cryptocurrency tracing and digital forensics, while Eurojust coordinated judicial authorities across participating countries to execute the searches and seizures at the same time.

Private cybersecurity companies Bitdefender and Group-IB also provided support during the investigation.

Investigators are now analyzing the 110 TB or more of recovered data, seized devices and financial records. Authorities believe that evidence could expose additional KillSec attacks, victims and participants.

The disruption represents a significant blow to KillSec’s existing infrastructure, but law enforcement has not declared the broader investigation complete.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →