Connect with us

Security

16-Year-Old Mastermind Arrested for Operating KillSec Ransomware Leak Site, Servers Confiscated

Published

on

Spanish authorities have apprehended a 16-year-old individual suspected of being involved in the activities of the KillSec ransomware group. The group was known for stealing data from various organizations and threatening to expose it on a leak site unless a ransom was paid.

On September 30, a total of 3 individuals, including the 16-year-old, were arrested, and control of the leak site was seized by the police.

The Hamburg police department revealed on October 1 that the teenager was believed to be the administrator and primary operator of KillSec. The operation was led by police and prosecutors in Hamburg, Germany.

The teenager, identified as one of the group’s administrators and the presumed main administrator, was detained in Alicante by the Spanish police forces, Guardia Civil, and Mossos d’Esquadra. A search was conducted at a residence and an office located in a hotel in the province.

Additionally, two other individuals in their 20s, one in the U.K. and one in Romania, were also arrested in connection with the case, as confirmed by a spokesperson from Europol.

Collaborating in the operation were U.S. prosecutors in Puerto Rico and the FBI’s San Juan office. Puerto Rico has requested the extradition of the individual arrested in the U.K., according to the Europol spokesperson.

In Romania, a 24-year-old suspect was detained by prosecutors from DIICOT on September 30. The individual is under investigation for various offenses related to organized crime, illegal access to computer systems, unauthorized transfer of data, illegal operations with devices or software, and blackmail.

The prosecutors have requested that the suspect be held in custody for 30 days, with the presumption of innocence maintained. The arrests made by Hamburg police were described as provisional.

See also  The Future of NYC Mayoral Inaugurations: A Tech Ban on Flipper Zero and Raspberry Pi Devices

Investigators have identified four distinct roles within the group: an administrator, a developer, a negotiator, and an affiliate. An affiliate is an external partner who utilizes the group’s ransomware tools to carry out attacks.

It was noted that the suspected developer, who turned 18 in August, has been identified but not apprehended, as some of the alleged offenses were committed when the individual was a minor.

The roles of the individuals arrested in the U.K. and Romania were not specified in the statements released by Hamburg police or DIICOT.

Law enforcement agencies conducted searches in Spain, Greece, the U.K., and Romania, seizing at least 110 terabytes of data to prevent further unauthorized access when taking control of the leak site.

During the investigation, Hamburg investigators shut down five servers, including KillSec’s main server and several servers used to store data obtained from victims. Additionally, police placed a seizure notice on five of the group’s domains.

Authorities in Spain seized computer equipment, phones, and cryptocurrency wallets, with an initial analysis revealing transactions corresponding to ransom payments from certain victims.

The investigation by the Guardia Civil began in 2025 through collaboration with the FBI’s office in San Juan, Puerto Rico, with the aim of locating individuals associated with KillSec residing in Spain. The suspect in Alicante was identified by investigators starting from a single profile image.

The Mossos d’Esquadra initiated their own investigation following an attack on a Catalan organization in early 2025, believed to be the work of KillSec. The estimated damage from the attack was nearly €1 million.

See also  OpenClaw Security Suite: Protecting Your Data from Malware Threats

Several countries commenced investigations into attacks attributed to KillSec in early 2025. Europol and Eurojust coordinated the efforts, with support from security firms Bitdefender and Group-IB.

Extortion Tactics of KillSec

KillSec exploited software vulnerabilities and insecure access points, particularly in cloud storage, to infiltrate organizations and access sensitive internal data, as outlined by Hamburg police. Subsequently, the group would threaten to publish the stolen data on the dark web leak site unless a ransom was paid.

If the victim refused to comply, the stolen files could be made available for free download. The investigation has identified approximately 1,000 suspected attacks globally, with around 500 confirmed successful incidents to date.

Investigators also discovered the group’s utilization of artificial intelligence to establish and operate its infrastructure, targeting potential victims. However, no further details were provided in this regard.

According to DIICOT prosecutors, group members purchased access credentials from the dark web, sent victims samples of their own data as proof, and threatened to sell the data to other criminal entities if the ransom was not paid.

Spanish authorities indicated that over 280 victims were affected by KillSec, resulting in significant ransom payments. Despite being labeled as a ransomware group, the actions described by the agencies primarily involve data theft and extortion.

As reported by security company Rapid7 in 2025, KillSec originated as a hacktivist group, operational since at least 2021, before transitioning to ransomware activities in October 2023. The group’s ransomware variants, KillSecurity 2.0 and 3.0, are designed for file encryption, although instances of extortion solely based on stolen data have also been observed. In June 2024, KillSec began offering its ransomware to affiliates, adopting the ransomware-as-a-service model.

See also  Cyber Security Headlines: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + More!

Ongoing Investigations

Eurojust stated that the authorities involved successfully dismantled a ransomware group and will continue the investigation to uncover additional details. Hamburg police mentioned that inquiries into other potential members of the group are ongoing.

Investigators are currently analyzing the seized devices and data, as well as tracing the group’s financial transactions, including those involving cryptocurrency. The evidence recovered may lead to the identification of more victims, attacks, and suspects.

Trending