Police arrest 16-year-old suspected of running KillSec ransomware group in Spain

Published:

Spanish authorities have arrested a 16-year-old suspected of leading the KillSec ransomware group, which is accused of stealing sensitive data from various organizations and threatening to publish it unless ransoms were paid. The arrest occurred on September 30, during a coordinated operation that also involved the seizure of the group’s leak site and multiple servers, according to reports from Hamburg police and Europol.

The teenager, identified as the main operator of KillSec, was detained in Alicante, Spain, alongside two other suspects in their 20s, one from the U.K. and another from Romania. The operation was led by Hamburg police, with support from the Guardia Civil and the Mossos d’Esquadra, Spain’s national and regional police forces, respectively. U.S. authorities, including the FBI, also participated, with Puerto Rico filing an extradition request for the U.K. suspect.

Details of the Operation

During the operation, investigators executed searches across Spain, Greece, the U.K., and Romania, resulting in the seizure of at least 110 terabytes of data and the shutdown of five servers linked to KillSec. The police also placed seizure notices on five of the group’s domains. In Spain, authorities confiscated computers, mobile phones, and cryptocurrency wallets, with initial analyses revealing transactions that matched ransom payments from victims.

The investigation into KillSec began in 2025, following cooperation between the FBI and Spanish authorities aimed at identifying individuals connected to the group. The Mossos d’Esquadra initiated their own inquiry after a significant attack on a Catalan organization, which resulted in damages estimated at nearly €1 million.

KillSec’s Modus Operandi

KillSec reportedly gained access to its victims by exploiting software vulnerabilities and poorly secured cloud storage. Once inside, the group would copy sensitive internal data to their servers and threaten to publish this information on their dark web leak site unless a ransom was paid. If victims refused to comply, the stolen data could be offered for free download, further pressuring organizations to pay.

Authorities estimate that KillSec has been involved in approximately 1,000 attacks globally, with around 500 identified as successful. The group has been linked to over 280 victims, and Europol noted that they “obtained substantial ransom payments.” KillSec’s tactics included using AI to enhance their operational capabilities and identify potential targets.

Legal Proceedings and Future Investigations

As of now, the arrested individuals are presumed innocent, and the legal proceedings are ongoing. The investigation remains active, with authorities examining the seized devices and data to trace the group’s financial activities, including cryptocurrency transactions. This could potentially lead to the identification of additional victims and suspects involved in the KillSec operations.

While the authorities have made significant strides in disrupting KillSec’s activities, the full extent of the group’s operations and the potential for further arrests remain open questions as investigations continue.

For further details, refer to the report by The Hacker News.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike details ClickFix attacks and strategies to mitigate user-executed threats

ClickFix attacks represent a sophisticated social engineering technique that exploits user behavior to execute malicious commands on their systems. Observed by CrowdStrike Intelligence, these...

Universities in UAE urged to adopt secure AI practices amid rising cybersecurity risks

As universities in the UAE increasingly integrate Artificial Intelligence (AI) into their operations, experts are urging institutions to prioritize cybersecurity measures to mitigate the...

WordPress backdoor ‘SC’ employs self-repairing mechanisms to evade detection

Cybersecurity researchers have identified a sophisticated WordPress backdoor, codenamed SC, which employs multiple persistence mechanisms to ensure its payload can regenerate itself after attempts...

NIST publishes guidelines for secure remote access in water and wastewater operational technology environments

Recent cyberattacks targeting the U.S. water and wastewater systems (WWS) sector have underscored the urgent need for enhanced cybersecurity measures within critical infrastructure. The...