- What: On September 30, police in Spain, the U.K. and Romania arrested 3 people, including a 16-year-old suspected of being KillSec's main administrator, and took over the group's leak site and servers.
- Impact: KillSec is tied to about 1,000 suspected attacks, about 500 of them successful so far, and police secured at least 110 TB of data held on the group's infrastructure.
- Fix / mitigation: Hamburg police said KillSec got in through software vulnerabilities, poorly secured access points (especially cloud storage) and login credentials bought on the dark web, so those are the exposures to close.
- Who's at risk: The group worked worldwide, and any organization with exposed cloud storage, unpatched internet-facing software or leaked credentials fits the profile of its victims.
On September 30, police in Spain detained a 16-year-old in Alicante province. Investigators suspect he was the administrator and main operator of KillSec, a data theft and extortion group tied to about 1,000 suspected attacks worldwide. Two other people, both in their 20s, were arrested the same day: one in the U.K. and one in Romania. Hamburg police led the operation with Hamburg prosecutors. They announced the arrests on October 1 and called all three provisional.
His age is the headline, but the scale of the operation is the real story. Hamburg police say about 500 of the suspected attacks have been confirmed as successful so far. Spanish police count more than 280 victims. When police took over the group's leak site, they secured at least 110 terabytes of data. In one case, an attack on a Catalan organization in early 2025, the damage was put at close to €1 million.
How the case came together
Agencies in several countries worked the case. Hamburg police and prosecutors led it. Two Spanish police forces, the Guardia Civil and the Mossos d'Esquadra, made the Alicante arrest and searched a home and an office at a hotel in the province. In Romania, prosecutors from DIICOT, the country's organized crime and terrorism directorate, detained a 24-year-old and searched 4 homes in Bucharest and Vaslui county. U.S. prosecutors in Puerto Rico and the FBI's San Juan office also took part, and Puerto Rico has filed an extradition request for the man arrested in the U.K. Europol and Eurojust coordinated the work, with support from security companies Bitdefender and Group-IB.
Police carried out 8 searches in Spain, Greece, the U.K. and Romania. They shut down 5 servers, including KillSec's main server, and put seizure notices on 5 of the group's domains. Spanish officers seized computers, phones and cryptocurrency wallets. A first analysis found transactions that match ransom payments from some victims.
The Guardia Civil's case began in 2025, working with the FBI's San Juan office to find people linked to KillSec who might live in Spain. Starting from a single profile image, its investigators identified the suspect. The Mossos d'Esquadra opened their own case after the attack on the Catalan organization.
The Guardia Civil says it identified the suspect from one profile image. Small security slips expose attackers just as they expose victims, and investigators can take advantage of them.
The playbook was unglamorous
According to Hamburg police, KillSec got in by exploiting software vulnerabilities and poorly secured access points, especially cloud storage. It copied sensitive data to servers it controlled, named the victim on its dark web leak site and threatened to publish the data. If a victim did not pay, the stolen files could be offered for free download. DIICOT added that members bought login credentials sold on the dark web, sent victims samples of their own data as proof, and threatened to sell the data to other criminal groups.
Rapid7 reported in 2025 that KillSec started as a hacktivist group, active since at least 2021, and turned to ransomware in October 2023. In June 2024 it began offering its ransomware to affiliates, outside partners who use a group's tools to carry out attacks. Its ransomware, KillSecurity 2.0 and 3.0, is designed to encrypt files, but in some incidents the group extorted victims with stolen data alone. Investigators have identified suspects in 4 roles: administrator, developer, negotiator and affiliate. The suspected developer turned 18 in August. He has been identified but not arrested.
Hamburg police also said the group used AI to build and run its infrastructure and to find potential victims. Their statement gives no further detail, so it is not known how much of the operation relied on AI.
The RedEye take
Coverage will focus on the teenager, and for defenders that is the least useful part. What matters is that about 500 successful intrusions came from known vulnerabilities, exposed cloud storage and bought credentials. That takes no sophisticated adversary, just an opportunistic one and a target that left a door open. When running an extortion operation is this easy, the age and skill of the operator tell you nothing about your risk. The person probing your perimeter could be anyone.
The label matters too. Agencies call KillSec a ransomware group, but what they describe is data theft and extortion. An organization that measures its ransomware readiness by how fast it can restore from backup is ready for only half the threat. Backups do nothing about a leak site.
The takedown is real progress, but it has limits. Eurojust says the group was shut down, yet inquiries into other possible members continue and one identified suspect is still free. Affiliates who used KillSec's tools can simply move to another group. The seized evidence may also turn up victims who never knew they were hit.
Investigators are still working through 110 TB of secured data and the seized devices, and the counts of 1,000 suspected and 500 successful attacks may change. Some organizations may learn about a past compromise from police, not from their own monitoring.
What defenders should learn
- Plan for extortion without encryption as the main case. KillSec sometimes skipped encryption entirely, so incident plans and cyber insurance terms should cover data exposure, breach notification and negotiation, not only recovery.
- Cloud storage settings are part of your external attack surface. Hamburg police singled out poorly secured access points, especially cloud storage. One owner should be accountable for storage exposure, not a split between the cloud and security teams.
- Stolen credentials for sale are a threat you can watch for. DIICOT says members bought login credentials on the dark web. Watching for leaked credentials tied to your domains costs far less than responding to the breach they enable.
- Prepare for a call from law enforcement. With payment records and stolen data now in police hands, victims may be contacted months after the fact. Decide in advance who takes that call, when legal counsel gets involved and how you will verify what police tell you.
- A takedown does not end your exposure. Data already offered for free download is still out there, and seizing the leak site does not pull back copies people have already taken.
What remains open
Investigators are examining the seized devices and tracing the group's money, including cryptocurrency, and say the evidence may identify more victims, attacks and suspects. The Romanian suspect is under investigation for forming an organized criminal group, illegal access to a computer system, unauthorized transfer of computer data, illegal operations with devices or software, and blackmail. On October 1, prosecutors asked a Bucharest court to keep him in custody for 30 days. He is presumed innocent. Neither Hamburg police nor DIICOT has said what roles the suspects arrested in the U.K. and Romania are believed to have held.
Source: The Hacker News, "Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers," October 1, 2026, https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us