16-year-old Arrested Suspected of Being the Leader of KillSec Ransomware Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Authorities have identified a 16-year-old as the suspected main operator of the KillSec ransomware group after an international law-enforcement operation disrupted the group’s infrastructure and led to three arrests.

The coordinated action, involving authorities from nine countries and supported by Eurojust and Europol, targeted a group linked to almost 1,000 ransomware incidents worldwide.

Eurojust said the suspects are believed to have stolen sensitive data from organizations and demanded payment to prevent its public release.

KillSec has been active since 2024 and built its name by stealing data and using public pressure against victims. Investigators said the group gained entry through software weaknesses and poorly protected access points, with cloud-storage environments being a key target.

After gaining access, the operators allegedly copied victim data to systems under their control and used it to demand ransom payments.

The group reportedly sent victims samples of stolen files to prove it had the data. If a victim did not pay, KillSec threatened to publish the information or make it available for free download through its leak platform.

This method is commonly called double extortion because the criminals use the risk of a data leak to pressure victims, whether or not files are encrypted.

Authorities identified several people suspected of holding different roles within the KillSec operation, including an administrator, developer, negotiator, and affiliate.

Authorities suspect the 16-year-old is the administrator and main operator. Investigators also identified a suspected developer who recently turned 18 and was still a minor when some of the alleged offenses took place. The group used online aliases and encrypted messaging services to hide the real identities of those involved.

Eurojust coordinated the international case, with judicial and law-enforcement authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom, and the United States taking part.

Authorities in Belgium, Germany, Greece, and Romania established a joint investigation team. Europol supported the operation by preparing reports on KillSec activity, helping investigators work with private-sector partners, tracing cryptocurrency movements, and examining digital evidence.

During the action day, officers carried out eight searches in Spain, Greece, the United Kingdom, and Romania. Authorities seized evidence and assets, secured at least 110 TB of stolen data, and took control of five servers allegedly used to store data taken from victims. Authorities also seized domains operated by KillSec, cutting off access to the group’s public-facing infrastructure.

The seizure of such a large volume of data may help investigators identify organizations that did not know they had been affected. Authorities are now reviewing seized devices, servers, and files while tracing financial proceeds connected to the group. The work could reveal further suspected members, victims, and ransomware activity connected to KillSec.

The operation also shows why organizations must treat cloud security, exposed services, and identity controls as core security priorities. Companies should review cloud-storage permissions, enforce multi-factor authentication, patch internet-facing systems quickly, monitor unusual data transfers, and keep tested backups. These controls can reduce the chance that criminals gain access and copy data before issuing a ransomware demand.

KillSec had previously been linked to activity targeting healthcare IT environments, where weak cloud configurations and unpatched applications can expose highly sensitive records.

Cyber Security News previously reported on KillSec ransomware activity affecting healthcare systems and the risks created by exposed cloud storage. Read the earlier KillSec healthcare coverage.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post 16-year-old Arrested Suspected of Being the Leader of KillSec Ransomware Group appeared first on Cyber Security News.