Police in Spain, Germany, the United Kingdom and Romania have carried out a coordinated operation against the alleged KillSec ransomware group, detaining three people and taking control of infrastructure linked to its data-leak operation.
Hamburg police said a 16-year-old was detained in Alicante, Spain, on September 30 and is suspected of serving as the group’s principal administrator. Spanish authorities searched a residence and a hotel office in the province, seizing computers, mobile phones and cryptocurrency wallets. Initial analysis reportedly identified transactions consistent with ransom payments.
Two additional suspects, both in their 20s, were detained in the UK and Romania, according to Europol. Romanian prosecutors said a 24-year-old is under investigation for alleged offenses including unauthorized access to computer systems, data transfers, use of malicious tools, blackmail and participation in an organized criminal group. The suspects have not been convicted, and the arrests are provisional.
Infrastructure and data seized
Authorities conducted eight searches across Spain, Greece, the UK and Romania. Investigators said they shut down five servers, including an alleged main KillSec server, and placed seizure notices on five domains. They also secured at least 110 terabytes of data to prevent further unauthorized access after taking over the group’s leak site.
The case was coordinated by Europol and Eurojust, with support from the FBI’s San Juan office, U.S. prosecutors in Puerto Rico, and security firms Bitdefender and Group-IB. Puerto Rico has reportedly requested the extradition of the person detained in the UK.
Alleged extortion activity
Investigators believe KillSec compromised organizations through exploited software flaws, weak access controls and, in some cases, credentials acquired on criminal marketplaces. The group allegedly copied internal data and threatened to publish or sell it unless victims paid.
Hamburg police said the investigation encompasses roughly 1,000 suspected incidents globally, with about 500 believed to have resulted in successful compromises so far. Spanish police cited more than 280 victims. Authorities are continuing to examine seized devices, data and cryptocurrency activity to identify additional affected organizations and possible participants.
KillSec had previously been described by researchers as a group that evolved from hacktivist activity into ransomware and data-extortion operations. Officials also said they are examining claims that artificial intelligence tools were used to support victim targeting and infrastructure operations, though they provided no technical details.
