Authorities arrest three alleged members of KillSec ransomware group in global operation

Published:

Authorities have arrested three alleged members of the KillSec ransomware group, including its suspected leader, a 16-year-old, as part of a coordinated global operation dubbed “Operation KillSwitch.” This crackdown, announced by Europol and the U.S. Justice Department, follows the group’s reported compromise of approximately 500 organizations since 2024.

The operation involved law enforcement from ten countries and private cybersecurity firms, resulting in the seizure of KillSec’s data-leak site and over 110 terabytes of data, which includes information on the group’s criminal activities. The arrests are seen as a significant blow to the group’s operational capabilities, with the FBI stating that the actions taken have “imposed serious cost and degraded the adversary’s core capabilities.”

Details of the Arrests

Among those arrested is Fouad Eltibrizi, who was apprehended in the United Kingdom and is awaiting extradition to the United States. Eltibrizi faces charges related to unauthorized computer access conspiracy, which could lead to a prison sentence of up to ten years. The alleged leader, whose identity has not been disclosed, reportedly played a central role in the group’s operations, which included negotiating ransom payments.

Europol noted that investigators gained control of critical infrastructure used by KillSec, including five central servers that managed the group’s activities and stored stolen data. The group, also known as the Kill Security Ransomware Group, exploited various vulnerabilities to infiltrate victims’ systems and extort sensitive information.

Impact on Victims and Ongoing Investigations

Some victims of KillSec have been identified in legal documents, including organizations in Puerto Rico, Washington state, and Louisiana. Prosecutors allege that Eltibrizi participated in extortion attempts against these entities, which were targeted for their sensitive information. The FBI’s Cyber Division emphasized that the operation has limited the group’s ability to conduct future attacks and has significantly disrupted their operations.

In addition to the arrests, law enforcement agencies conducted searches at eight locations across Spain, Greece, the United Kingdom, and Romania, gathering evidence to identify additional members of the group. The ongoing investigation aims to dismantle the remaining infrastructure of KillSec and prevent further cyber extortion activities.

As ransomware continues to pose a serious threat across various sectors, including critical infrastructure and small businesses, authorities remain vigilant in their efforts to combat such cybercrime. “Ransomware remains a serious and evolving threat to all sectors of our economy,” stated Héctor Ramírez‑Carbó, acting U.S. attorney for the District of Puerto Rico.

For further details on the operation and its implications, refer to CyberScoop.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

French Navy conducts first at-sea tests of Rampart CIWS during WILDFIRE 26.2 exercise

The French Navy has successfully conducted its first at-sea tests of the Rampart multi-purpose modular launching system, developed by Naval Group, during the WILDFIRE...

AI’s evolving role in cyber threats and defenses highlighted in Microsoft’s 2026 Digital Defense Report

The 2026 Microsoft Digital Defense Report reveals a significant evolution in the role of artificial intelligence (AI) within the cybersecurity landscape, highlighting how threat...

Suspected ShinyHunters member Rey detained in Jordan, aiding FBI investigation

A suspected member of the ShinyHunters digital extortion group, known online as "Rey," has reportedly been detained by authorities in Jordan, as confirmed by...

Jordan arrests suspected ShinyHunters hacker linked to FBI data theft claims

Jordan has confirmed the arrest of a suspected member of the ShinyHunters hacking group, which claims to have stolen sensitive data on every employee...