Authorities have arrested three alleged members of the KillSec ransomware group, including its suspected leader, a 16-year-old, as part of a coordinated global operation dubbed “Operation KillSwitch.” This crackdown, announced by Europol and the U.S. Justice Department, follows the group’s reported compromise of approximately 500 organizations since 2024.
The operation involved law enforcement from ten countries and private cybersecurity firms, resulting in the seizure of KillSec’s data-leak site and over 110 terabytes of data, which includes information on the group’s criminal activities. The arrests are seen as a significant blow to the group’s operational capabilities, with the FBI stating that the actions taken have “imposed serious cost and degraded the adversary’s core capabilities.”
Details of the Arrests
Among those arrested is Fouad Eltibrizi, who was apprehended in the United Kingdom and is awaiting extradition to the United States. Eltibrizi faces charges related to unauthorized computer access conspiracy, which could lead to a prison sentence of up to ten years. The alleged leader, whose identity has not been disclosed, reportedly played a central role in the group’s operations, which included negotiating ransom payments.
Europol noted that investigators gained control of critical infrastructure used by KillSec, including five central servers that managed the group’s activities and stored stolen data. The group, also known as the Kill Security Ransomware Group, exploited various vulnerabilities to infiltrate victims’ systems and extort sensitive information.
Impact on Victims and Ongoing Investigations
Some victims of KillSec have been identified in legal documents, including organizations in Puerto Rico, Washington state, and Louisiana. Prosecutors allege that Eltibrizi participated in extortion attempts against these entities, which were targeted for their sensitive information. The FBI’s Cyber Division emphasized that the operation has limited the group’s ability to conduct future attacks and has significantly disrupted their operations.
In addition to the arrests, law enforcement agencies conducted searches at eight locations across Spain, Greece, the United Kingdom, and Romania, gathering evidence to identify additional members of the group. The ongoing investigation aims to dismantle the remaining infrastructure of KillSec and prevent further cyber extortion activities.
As ransomware continues to pose a serious threat across various sectors, including critical infrastructure and small businesses, authorities remain vigilant in their efforts to combat such cybercrime. “Ransomware remains a serious and evolving threat to all sectors of our economy,” stated Héctor RamÃrez‑Carbó, acting U.S. attorney for the District of Puerto Rico.
For further details on the operation and its implications, refer to CyberScoop.


