**Hacker Pranks** **Teenage Ransomware Kingpin Brought Down: KillSec Servers Seized, Three Arrested**

A 16-year-old is suspected of leading the notorious KillSec ransomware group, responsible for over 1,000 attacks worldwide. In a coordinated effort, international authorities have seized the group's infrastructure, arrested three individuals, and secured over 110 terabytes of stolen data.

The operation, dubbed "KillSwitch," was led by German authorities and involved ten law enforcement agencies from Europe and the US. The raids took place on September 30, following a year-long investigation that began in early 2025. Officers raided eight properties across Greece, Romania, Spain, and the UK, seizing five central servers used to manage the group's activities and store victims' data.

**The Rise and Fall of KillSec**

KillSec emerged in 2024, initially using a Windows encryptor. However, they later developed a more sophisticated tool capable of encrypting VMware ESXi hosts, deleting data, shutting down VMs, and removing recovery points. The group used double extortion tactics, encrypting victims' systems and threatening to publish stolen data unless they paid. According to Group-IB, KillSec primarily targeted financial services and healthcare organizations, but also attacked government entities and large enterprises.

In a statement, Group-IB CEO Dmitry Volkov emphasized the importance of bringing down the individuals behind the platform: "Servers can be replaced in weeks; the people who build the platform and approve every attack cannot." Volkov's comments highlight the significance of targeting the human element behind ransomware groups.

**The Arrests and Seized Data**

While the suspected 16-year-old leader has not been publicly named, authorities have identified several individuals involved in the group. These include:

* Fouad Eltibrizi, a Dutch national, arrested by UK police and charged with alleged cybercrimes in the US and Puerto Rico. He is suspected of being one of KillSec's negotiators. * A 24-year-old Romanian national, accused of helping establish KillSec in October 2023. * A Romanian national in his twenties, arrested in Romania on suspicion of acting as a KillSec affiliate. * A suspected developer who turned 18 in August and was a minor when some of the alleged offenses were committed. * A woman, who remains under investigation in connection to the case, but has not been arrested.

Authorities have secured over 110 terabytes of data on KillSec's leak site, which will be examined to identify victims, attacks, and suspects, and to trace the group's criminal proceeds.

**Implications and Future Directions**

The takedown of KillSec highlights the importance of international cooperation in combating ransomware groups. As Volkov noted, bringing down the individuals behind the platform is crucial to disrupting the group's activities. The seized data and arrested suspects will undoubtedly provide valuable insights into the group's operations and tactics.

However, the fight against ransomware is far from over. As new groups emerge and existing ones adapt, law enforcement and cybersecurity experts must remain vigilant. The lessons learned from the KillSec operation will undoubtedly inform future efforts to combat these threats.

Stay tuned for further updates on this developing story and the ongoing fight against ransomware.