KillSec ransomware servers seized, suspects arrested
An international police operation dismantled the KillSec ransomware group, seizing servers and arresting key suspects including a 16-year-old.

International police have seized the servers and leak site of the KillSec ransomware group and arrested key suspects, preventing the exposure of at least 110 terabytes of stolen data. Operation KillSwitch, led by German police on September 30, involved authorities from ten countries including Belgium, the United States, Finland, and the United Kingdom.
Police seized five servers used to manage the group's activities and store victim data. They conducted eight house searches in Spain, Greece, Romania, and the United Kingdom. KillSec's dark web domains now redirect to a law enforcement seizure notice. The investigation, based in Hamburg and supported by Europol's European Cybercrime Centre, began in 2025 and identified at least four suspected members of the gang, which has operated since 2024.
Key suspects arrested across Europe
Provisional arrests were made in Spain, Greece, Romania, and the UK. A 16-year-old Romanian national, believed to be the group's main operator and administrator, was arrested in Alicante, Spain. Another suspected member, described as a developer, turned 18 in August 2026 and was a minor when some alleged crimes were committed. A third individual was identified as a negotiator and another as an affiliate.
Separately, US authorities indicted Dutch national Fouad Eltibrizi, also known as 'Archduke'. British police arrested him on September 30, and he faces hacking and extortion charges carrying a maximum ten-year sentence. He is awaiting extradition to the US.
KillSec’s AI-enabled ransomware-as-a-service model exposed
The group used artificial intelligence to help build ransomware infrastructure and identify potential victims. Cybersecurity firms Bitdefender and Group-IB assisted the investigation. The ransomware-as-a-service outfit exploited software vulnerabilities and insecure cloud storage access points.
KillSec carried out roughly 1,000 attacks, with at least half being successful. Group-IB identified 274 publicly claimed victims, with the majority located in the United States and India. The group acted as a data broker, advertising stolen data from healthcare, government, and financial sector victims for prices ranging from $5,000 to $500,000.
| Victim Region | Percentage of Attacks |
|---|---|
| United States | 35% |
| India | 17% |
The platform allowed cybercriminals with limited skills to carry out attacks. Dmitry Volkov of Group-IB stated, "KillSec's affiliates went after the organizations people depend on most: hospitals, government bodies, and financial institutions." The group used Windows and VMware ESXi lockers and sometimes stole data without encrypting it. Authorities are now examining seized computers and servers to trace alleged criminal proceeds, including cryptocurrency.





