[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5X0KDSSdYJ3sfk2F_bkOkvRC11_6ep6rlqR7SedhWdc":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":37},"1933cb79-e253-4521-abfb-3b863a6dfe64","Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers","police-arrest-16-year-old-suspected-of-running-killsec-seize-ransomware-leak-sit-1ba8da","Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected","Authorities in Spain, Germany, the UK, and Romania have arrested three individuals, including a 16-year-old suspected of leading the KillSec ransomware group. The operation, coordinated by Europol and involving the FBI, resulted in the seizure of KillSec's leak site, servers, and over 110 terabytes of victim data. The group is accused of stealing data and demanding ransoms, with investigations ongoing into other alleged members.","Police arrested a 16-year-old suspected of running KillSec ransomware group.","Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Swati KhandelwalOct 01, 2026Ransomware \u002F Cybercrime Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected administrator and main operator, Hamburg police said on October 1. Police and prosecutors in Hamburg, Germany, led the operation. The Guardia Civil and the Mossos d'Esquadra, both Spanish police forces, detained him in Alicante and searched a home and an office at a hotel in the province. Their joint statement, carried by elperiodic.com, calls him one of the group's administrators and its presumed main administrator. The other 2 people arrested are in their 20s, one in the U.K. and one in Romania, a spokesperson for Europol, the European Union's police agency, told Reuters. U.S. prosecutors in Puerto Rico and the FBI's San Juan office took part in the operation. Puerto Rico has filed an extradition request for the man arrested in the U.K., the Europol spokesperson said. In Romania, prosecutors from DIICOT, the country's organized crime and terrorism directorate, detained a 24-year-old on September 30 and searched 4 homes in Bucharest and Vaslui county. He is under investigation for forming an organized criminal group, illegal access to a computer system, unauthorized transfer of computer data, illegal operations with devices or software, and blackmail, according to DIICOT's statement, carried by the newspaper Bursa. On October 1, the prosecutors asked a Bucharest court to keep him in custody for 30 days. He is presumed innocent. Hamburg police described all 3 arrests as provisional. Investigators have identified suspects in 4 roles: an administrator, a developer, a negotiator and an affiliate. An affiliate is an outside partner who uses a group's ransomware tools to carry out attacks. The suspected developer turned 18 in August and was a minor when some of the alleged offenses took place. He has been identified but not arrested, Reuters reported. Neither Hamburg police nor DIICOT said in their statements what roles the men arrested in the U.K. and Romania are suspected of holding. Police carried out 8 searches in Spain, Greece, the U.K. and Romania. They secured at least 110 terabytes of data against further unauthorized access when they took over the leak site. During the investigation, Hamburg investigators also shut down 5 servers, including KillSec's main server and several used to hold data taken from victims. They put a police seizure notice on 5 of the group's domains. In Spain, officers seized computer equipment, phones and cryptocurrency wallets. A first analysis found transactions that match ransom payments from some victims, Spanish police said. The Guardia Civil's investigation began in 2025 from cooperation with the FBI's office in San Juan, Puerto Rico, aimed at finding people linked to KillSec who might live in Spain. Starting from a single profile image, its investigators identified the suspect, who lived in Alicante province. The Mossos d'Esquadra opened their own case after an attack on a Catalan organization in early 2025 that they suspect was KillSec's work. The damage was put at close to €1 million. Authorities in several countries began investigating attacks blamed on KillSec in early 2025. Europol and the EU's judicial cooperation agency, Eurojust, coordinated the work, and security companies Bitdefender and Group-IB supported the investigation. How KillSec Extorted Its Victims KillSec gained access to organizations by exploiting software vulnerabilities and poorly secured access points, especially cloud storage, according to Hamburg police. Its members then copied sensitive internal data to servers they controlled. The group named its victims on its dark web leak site and threatened to publish their data unless they paid a ransom. Where a victim did not pay, the stolen files could be offered for free download. The investigation covers about 1,000 suspected attacks worldwide. About 500 have been identified as successful so far, and both figures may change as investigators work through the seized evidence. Investigators also uncovered how the group used AI to build and operate its infrastructure and identify potential victims, Hamburg police said. Their statement gives no further detail. DIICOT prosecutors said members also bought access credentials offered for sale on the dark web, sent victims samples of their own data as proof, and threatened to sell the data to other criminal groups if no ransom was paid. Spanish police put the number of victims at more than 280. The group \"obtained substantial ransom payments,\" Europol said in a statement quoted by Reuters. The agencies call KillSec a ransomware group, but the conduct they describe is data theft and extortion. Security company Rapid7 reported in 2025 that KillSec began as a hacktivist group, active since at least 2021, and turned to ransomware in October 2023. Its ransomware, KillSecurity 2.0 and 3.0, is designed to encrypt files, although in some incidents the group extorted victims with stolen data alone. In June 2024, it began offering the ransomware to affiliates, a model known as ransomware-as-a-service. What Remains Open Eurojust said the authorities taking part \"successfully shut down a ransomware group\" and will now continue their investigation. Hamburg police said inquiries into other possible members continue. Investigators are examining the seized devices and data and tracing the group's money, including cryptocurrency. The evidence may identify more victims, attacks and suspects. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, data breach, law enforcement, ransomware ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitati","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fpolice-arrest-16-year-old-suspected-of.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgy6XYYOXNZNjc51viw5FvCk49pWIXCCRS6yr_hl0ZKdwhBWRfYrCQ7bM6AJZJdmI_W3AEz1V3X0DAP6k39KfgjlKFfB5JcFaKN9zzIl1-7c49Vnuaz55yhRXjdmY5K2kIPuY_-7624KyVHqkHzikJIi11iClljnXv_3i2X21JiRCMU8ElmiHiZdHVQ7ws\u002Fs1600\u002Fkillsec-ransomware.jpg","2026-10-01T16:55:57+00:00","2026-10-01T18:00:03.053284+00:00",8,[18,21,24,27,29,31],{"name":19,"type":20},"KillSec","threat_actor",{"name":22,"type":23},"ransomware","product",{"name":25,"type":26},"Europol","vendor",{"name":28,"type":26},"FBI",{"name":30,"type":26},"Bitdefender",{"name":32,"type":26},"Group-IB","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":33,"icon":35,"name":36,"slug":22},null,"Ransomware",[38,43,45,50],{"category":39},{"id":40,"icon":35,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":33,"icon":35,"name":36,"slug":22},{"category":46},{"id":47,"icon":35,"name":48,"slug":49},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":51},{"id":52,"icon":35,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]