Spanish Police Dismantle KillSec Ransomware Group in Coordinated International Operation
Spanish authorities, in collaboration with law enforcement agencies across Europe and the U.S., have arrested three individuals linked to the KillSec ransomware group, including a 16-year-old suspected administrator detained in Alicante on September 30. The operation, led by Hamburg police and prosecutors, also resulted in the seizure of KillSec’s leak site and the shutdown of five servers hosting stolen victim data.
The arrests targeted key members of the group: the 16-year-old in Spain, a 20-something in the U.K., and a 24-year-old in Romania, the latter facing charges including organized crime, illegal data access, and blackmail. U.S. prosecutors in Puerto Rico have filed an extradition request for the U.K. suspect, while Romanian authorities secured a 30-day custody order for their detainee.
Investigators identified four distinct roles within KillSec administrator, developer, negotiator, and affiliate though the specific roles of the arrested individuals remain undisclosed. A suspected developer, who turned 18 in August, was identified but not detained, as some alleged offenses occurred while they were a minor.
The operation, coordinated by Europol and Eurojust, involved eight searches across Spain, Greece, the U.K., and Romania, resulting in the seizure of 110 terabytes of data, cryptocurrency wallets, and computer equipment. Authorities also took control of five domains linked to the group, displaying police seizure notices.
KillSec operated by exploiting software vulnerabilities and insecure cloud storage, stealing sensitive data, and threatening to publish it unless victims paid ransoms. The group used AI to build infrastructure and identify targets, though details remain limited. Investigators estimate 1,000 suspected attacks worldwide, with 500 confirmed successful breaches and over 280 victims in Spain alone. The group reportedly extorted substantial ransom payments, sometimes selling stolen data to other criminals if demands were unmet.
Originally a hacktivist collective active since 2021, KillSec transitioned to ransomware in October 2023, deploying KillSecurity 2.0 and 3.0 to encrypt files. By June 2024, it adopted a ransomware-as-a-service (RaaS) model, recruiting affiliates to carry out attacks.
While authorities declared the group "successfully shut down," investigations continue to trace financial flows, analyze seized evidence, and identify additional suspects or victims. The case remains ongoing, with further developments expected.
Source: https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
KillSec TPRM report: https://www.rankiteo.com/company/europol
"id": "eur1790879655",
"linkid": "europol",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Over 280 victims in Spain alone',
'location': 'Worldwide (500 confirmed breaches, 280 '
'victims in Spain)'}],
'attack_vector': ['Exploiting software vulnerabilities',
'Insecure cloud storage'],
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive data (including '
'personally identifiable '
'information)'},
'description': 'Spanish authorities, in collaboration with law enforcement '
'agencies across Europe and the U.S., have arrested three '
'individuals linked to the KillSec ransomware group, including '
'a 16-year-old suspected administrator detained in Alicante on '
'September 30. The operation resulted in the seizure of '
'KillSec’s leak site and the shutdown of five servers hosting '
'stolen victim data.',
'impact': {'data_compromised': '110 terabytes of data seized',
'identity_theft_risk': 'High (due to stolen sensitive data)'},
'initial_access_broker': {'data_sold_on_dark_web': True},
'investigation_status': 'Ongoing (tracing financial flows, analyzing seized '
'evidence, identifying additional suspects/victims)',
'motivation': ['Financial gain', 'Data extortion'],
'post_incident_analysis': {'root_causes': ['Exploiting software '
'vulnerabilities',
'Insecure cloud storage',
'AI-driven target identification']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransom_demanded': True,
'ransom_paid': 'Substantial payments (exact amount unknown)',
'ransomware_strain': ['KillSecurity 2.0', 'KillSecurity 3.0']},
'references': [{'source': 'Law enforcement operation report'}],
'regulatory_compliance': {'legal_actions': ['Charges including organized '
'crime, illegal data access, and '
'blackmail']},
'response': {'containment_measures': ['Seizure of KillSec’s leak site',
'Shutdown of five servers hosting '
'stolen data',
'Seizure of 110 terabytes of data',
'Control of five domains linked to the '
'group'],
'law_enforcement_notified': True,
'third_party_assistance': 'Europol, Eurojust, law enforcement '
'agencies across Europe and the U.S.'},
'threat_actor': 'KillSec ransomware group',
'title': 'Spanish Police Dismantle KillSec Ransomware Group in Coordinated '
'International Operation',
'type': 'Ransomware'}