Back to Feed
Nation-stateOct 1, 2026

Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members

Authorities dismantle KillSec extortion group, arresting 3 alleged members and seizing infrastructure.

Summary

Law enforcement agencies have arrested three alleged members of the teenage-run data extortion group KillSec, including its suspected 16-year-old leader. The operation, dubbed 'Operation KillSwitch,' involved 10 countries and resulted in the seizure of KillSec's data-leak site, servers, and over 110 terabytes of data, significantly degrading the group's capabilities. KillSec is believed to have compromised around 500 organizations since 2024.

Full text

Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024, Europol and the Justice Department said Thursday. Investigators said the alleged leader of the group is 16 years old, but declined to name them. One of the group’s accused members, Fouad Eltibrizi, was arrested Wednesday in the United Kingdom and awaits extradition to the United States, the Justice Department said. The Dutch national, who is accused of acting as a negotiator for the group, was indicted last month in Puerto Rico and faces up to 10 years in prison for unauthorized computer access conspiracy. Europol said a suspected developer involved in the group committed multiple crimes before they turned 18 in August. The arrests were part of “Operation KillSwitch,” a globally coordinated operation aided by 10 countries and private cybersecurity companies. Officials seized KillSec’s data-leak site and at least 110 terabytes of data, including information on the group’s criminal proceeds. Law enforcement’s accumulated actions targeting KillSec’s infrastructure and people involved “imposed serious cost and degraded the adversary’s core capabilities,” the FBI’s Cyber Division said in a statement on X. “We have undermined the group’s ability to rebuild, limited their operational reach and reduced the likelihood of future attacks,” the FBI added. Europol said investigators gained control of domains and five central servers, including infrastructure the group used to manage its activities and store stolen data. The cybercrime group, which was also known as Kill Security Ransomware Group, exploited various defects to intrude victims’ computers or cloud-based network infrastructure and steal sensitive data for extortion demands. Officials said the group obtained substantial ransom payments in some cases. Officials from the United States and Europe searched eight residences in Spain, Greece, the United Kingdom and Romania, and investigators are looking through evidence seized during those raids to identify other potential members of the group. Some of the group’s victims were identified by initials and the location and date of the attack in the indictment filed against Eltibrizi. This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025. Three of those victims align with organizations that were listed on KillSec’s data-leak site for Instituto de Ojos, US BioTek Laboratories and Accelerated Academy. Prosecutors accuse Eltibrizi, who allegedly participated in the conspiracy from at least March through November 2025, of placing calls as a KillSec representative in at least one of those extortion demands. “The defendant and his co-conspirators carried out targeted intrusions against multiple companies and organizations, stealing highly sensitive information and attempting to extort their victims for substantial sums of money,” Héctor Ramírez‑Carbó, acting U.S. attorney for the District of Puerto Rico, said in a statement. “Ransomware remains a serious and evolving threat to all sectors of our economy, from critical infrastructure to small businesses,” he added. Share Facebook LinkedIn Twitter Copy Link Add to Preferred Sources

Entities

KillSec (threat_actor)Kill Security Ransomware Group (threat_actor)Operation KillSwitch (campaign)KillSec data-leak site (product)