Back
Police Arrest 16-Year-Old Suspected of Running KillSec Ransomware Group
SiTech AI Team3 min read

Police Arrest 16-Year-Old Suspected of Running KillSec Ransomware Group

Police in Spain arrested a 16-year-old suspected of running the KillSec ransomware group. The Hamburg-led operation seized the leak site, secured 110 terabytes of data, shut down 5 servers and saw two more arrests, in the U.K. and Romania.

Police in Spain arrested a 16-year-old on September 30 on suspicion of running KillSec, a ransomware group that stole data from organizations and threatened to publish it unless they paid. The Hamburg-led operation also took control of the group's leak site.

Three Arrests and a Leak-Site Takedown

The teenager was detained in Alicante province; the Guardia Civil and the Mossos d'Esquadra searched a home and a hotel office. Hamburg police identified him as KillSec's suspected administrator and main operator, and the Spanish forces' joint statement called him the group's presumed main administrator.

Two other suspects in their 20s were arrested in the U.K. and Romania. Police carried out 8 searches in Spain, Greece, the U.K. and Romania, secured at least 110 terabytes of data when they seized the leak site, shut down 5 servers including KillSec's main server, and posted seizure notices on 5 of the group's domains.

In Romania, DIICOT detained a 24-year-old on September 30 and searched 4 homes in Bucharest and Vaslui county. He is investigated for forming an organized criminal group, illegal computer access, unauthorized data transfer and blackmail. He is presumed innocent, and Hamburg police described all three arrests as provisional.

How KillSec Extorted Its Victims

KillSec gained access by exploiting software vulnerabilities and poorly secured access points, especially cloud storage, then copied sensitive internal data to its own servers, Hamburg police said. Victims were named on the group's leak site and threatened with publication; those who refused could have their files offered for free download.

DIICOT said members also bought dark web access credentials, sent victims samples of their own data as proof, and threatened to sell it to other criminal groups. Hamburg police said the group used AI to build and operate its infrastructure and to identify potential victims.

The investigation covers about 1,000 suspected attacks worldwide, roughly 500 of them successful so far, though the figures may change. Spanish police count more than 280 victims, and Europol said the group obtained substantial ransom payments.

Rapid7 reported in 2025 that KillSec began as a hacktivist group active since at least 2021 and turned to ransomware in October 2023. Its KillSecurity 2.0 and 3.0 encrypt files, though the group sometimes extorted victims with stolen data alone; in June 2024 it began offering its tools to affiliates, a model known as ransomware-as-a-service.

What Happens Next

The Guardia Civil's investigation began in 2025 with the FBI's San Juan office in Puerto Rico; from a single profile image, investigators identified the suspect in Alicante province. Puerto Rico has filed an extradition request for the man arrested in the U.K.

Investigators have identified suspects in 4 roles: an administrator, a developer, a negotiator and an affiliate. The suspected developer turned 18 in August and was a minor during some alleged offenses; he has been identified but not arrested. Europol and Eurojust coordinated the operation, with support from Bitdefender and Group-IB; Hamburg police said other possible members remain under investigation.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.