Spanish authorities have arrested a 16-year-old suspected of leading the KillSec ransomware group, which is accused of stealing sensitive data from various organizations and threatening to publish it unless ransoms were paid. The arrest occurred on September 30, during a coordinated operation that also involved the seizure of the group’s leak site and multiple servers, according to reports from Hamburg police and Europol.
The teenager, identified as the main operator of KillSec, was detained in Alicante, Spain, alongside two other suspects in their 20s, one from the U.K. and another from Romania. The operation was led by Hamburg police, with support from the Guardia Civil and the Mossos d’Esquadra, Spain’s national and regional police forces, respectively. U.S. authorities, including the FBI, also participated, with Puerto Rico filing an extradition request for the U.K. suspect.
Details of the Operation
During the operation, investigators executed searches across Spain, Greece, the U.K., and Romania, resulting in the seizure of at least 110 terabytes of data and the shutdown of five servers linked to KillSec. The police also placed seizure notices on five of the group’s domains. In Spain, authorities confiscated computers, mobile phones, and cryptocurrency wallets, with initial analyses revealing transactions that matched ransom payments from victims.
The investigation into KillSec began in 2025, following cooperation between the FBI and Spanish authorities aimed at identifying individuals connected to the group. The Mossos d’Esquadra initiated their own inquiry after a significant attack on a Catalan organization, which resulted in damages estimated at nearly €1 million.
KillSec’s Modus Operandi
KillSec reportedly gained access to its victims by exploiting software vulnerabilities and poorly secured cloud storage. Once inside, the group would copy sensitive internal data to their servers and threaten to publish this information on their dark web leak site unless a ransom was paid. If victims refused to comply, the stolen data could be offered for free download, further pressuring organizations to pay.
Authorities estimate that KillSec has been involved in approximately 1,000 attacks globally, with around 500 identified as successful. The group has been linked to over 280 victims, and Europol noted that they “obtained substantial ransom payments.” KillSec’s tactics included using AI to enhance their operational capabilities and identify potential targets.
Legal Proceedings and Future Investigations
As of now, the arrested individuals are presumed innocent, and the legal proceedings are ongoing. The investigation remains active, with authorities examining the seized devices and data to trace the group’s financial activities, including cryptocurrency transactions. This could potentially lead to the identification of additional victims and suspects involved in the KillSec operations.
While the authorities have made significant strides in disrupting KillSec’s activities, the full extent of the group’s operations and the potential for further arrests remain open questions as investigations continue.
For further details, refer to the report by The Hacker News.


