
Police dismantle KillSec ransomware group and arrest 16-year-old leader in Spain
An international police operation led by German authorities dismantled the KillSec ransomware gang, seizing its dark web site and arresting a 16-year-old Romanian administrator in Alicante.
International takedown of KillSec
An international law enforcement operation named Operation KillSwitch dismantled the KillSec ransomware syndicate, taking down its dark web infrastructure and securing at least 110 terabytes of stolen data. The investigation was directed by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office in Germany, with coordination provided by Europol and Eurojust. Police agencies across ten countries took part in the coordinated action, including Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States. Cybersecurity firms Bitdefender and Group-IB also contributed technical support to the multi-agency effort. Authorities carried out three provisional arrests and eight property searches across Greece, Romania, Spain, and the United Kingdom to disrupt the group's network and seize its illicit profits.
- KillSec begins ransomware operations exploiting cloud and software vulnerabilities
- KillSec breaches Catalan public agency Infraestructures.cat, causing €1 million in damages
- Guardia Civil opens Operación Rotoma following intelligence from FBI San Juan
- Identified developer of the ransomware group turns 18 years old
- Authorities seize dark web site and arrest 16-year-old suspect in Alicante
- Europol announces the dismantling of KillSec under Operation KillSwitch
Spanish arrests and investigation
The Spanish branch of the inquiry, known as Operación Rotoma, was conducted jointly by the Guardia Civil's Central Operative Unit (UCO) Cybercrime Department and the Mossos d'Esquadra Criminal Investigation Division. Officers in the province of Alicante arrested a 16-year-old Romanian national identified as the primary administrator and operator of KillSec. The Guardia Civil identified the teenager starting from a single profile image following intelligence received in 2025 from the FBI field office in San Juan, Puerto Rico. Law enforcement teams searched two locations in Alicante, comprising a residential dwelling and an office within a hotel establishment, while placing one woman under formal investigation. Officers seized computer hardware, mobile phones, cryptocurrency wallets, and specialized anonymization and data-encryption tools, with early forensic analysis confirming transactions linked to ransom payments.
Modus operandi and operational roles
KillSec began operating in 2024, penetrating target networks by exploiting software vulnerabilities and weakly protected access points, particularly in cloud storage services. Once inside a victim's network, the group exfiltrated sensitive internal records to infrastructure under its own control before issuing financial demands. The gang published victim names on its dark web leak platform alongside threats to release the stolen files if ransoms were unpaid. In multiple instances, the group demanded ransoms in cryptocurrency, with some victims paying sums of approximately €500,000. If organizations refused to pay, KillSec published the stolen data for free public download. In addition to the 16-year-old administrator, investigators identified a core developer who turned 18 years old in August 2026, alongside individuals acting as a negotiator and an affiliate.
Victim losses and attack volume
Law enforcement records show that KillSec launched approximately 1,000 cyberattacks globally, of which an estimated 500 were successful and affected more than 280 confirmed victim organizations. One confirmed intrusion targeted Infraestructures.cat, a public sector company belonging to the Government of Catalonia, in early 2025. Intruders accessed the Catalan entity's network, extracted sensitive files, and attempted extortion, generating damages calculated at close to €1 million. The seizure of the gang's dark web platform on 30 September 2026 prevented the further publication of stolen files, while international investigators continue to examine digital evidence seized during the eight raids to identify additional victims and financial flows.
- Alleged total attacks
- 1000 entities
- Successful attacks
- 500 entities
- Confirmed victims
- 280 entities


