
Police arrest 16-year-old Romanian suspected of leading KillSec ransomware ring
Authorities in nine countries coordinated the arrest of key KillSec members, including a 16-year-old administrator seized in Alicante, over roughly 1,000 cyberattacks.
International sweep hits KillSec leadership
Law enforcement agencies across Europe and the United States dismantled the operational core of the KillSec ransomware syndicate under Operation Killswitch. Spanish police arrested a 16-year-old Romanian national in Alicante on Thursday, identifying him as the primary coordinator and administrator of the network. Authorities attribute approximately 1,000 ransomware attacks worldwide to the cybercrime group over the past two years. Two additional suspects in their twenties were detained during coordinated raids in the United Kingdom and Romania. A fourth individual, an identified programmer who turned 18 in August 2026, avoided arrest because of their minor status when several offences occurred.
The coordinated sweep involved eight residential searches across Spain, Greece, Romania, and the United Kingdom, where police seized digital evidence and technical hardware. Romanian prosecutors from DIICOT executed four search warrants across Bucharest and Vaslui County on 30 September 2026, detaining a 24-year-old member. Authorities in Puerto Rico submitted an extradition request for the suspect apprehended in the United Kingdom.
- KillSec begins operating as an organized cross-border cybercrime group
- Romania and Belgium form a joint investigation team under Eurojust
- DIICOT executes four search warrants in Bucharest and Vaslui County
- Police announce the arrest of three KillSec suspects across Spain, Romania, and the UK
Technical infrastructure and extortion methods
Investigative findings show that KillSec operated a systematic model targeting organizations through software vulnerabilities and weakly secured access points. The syndicate specifically compromised cloud storage systems and acquired illicit access credentials sold on darknet marketplaces. Members established command-and-control servers hosted on an international cloud computing provider, communicating through encrypted channels while operating under cybercrime aliases.
DIICOT outlined the syndicate's operational purpose during judicial proceedings.
In October 2023, the defendant, together with other members, acted in a cross-border organized criminal group, generically named KillSec, in order to obtain sums of money from the theft of computer data and selling it to interested third parties.
After breaching victim networks, KillSec exfiltrated sensitive data files before delivering ransom demands. To compel payment, the syndicate forwarded stolen data samples directly to targeted organizations or provided web links showing leaked materials. Group members threatened to publish the data online or sell it to rival cybercrime networks if ransom payments were not delivered in cryptocurrency.
Europol confirmed the financial impact of the group's extortion demands.
The group obtained substantial payments in the form of ransom.
Cross-border judicial cooperation
Operation Killswitch brought together judicial and police authorities from nine countries: Romania, Germany, Belgium, Finland, Greece, Spain, Switzerland, the United Kingdom, and the United States. The international framework originated in December 2025 under Eurojust, when Romania and Belgium established a joint investigation team that later expanded to include Germany and Greece. Europol supported intelligence exchanges between national police units throughout the multi-year investigation.
Romanian prosecutors have charged the 24-year-old detainee with forming an organized criminal group, illegal access to a computer system, unauthorized transfer of computer data, illicit operations with software devices, and blackmail. Digital evidence seized from the eight raided premises across four countries is undergoing forensic analysis to identify further enterprise breaches and track financial flows.


