Your privacy choices

We use analytics to improve Pollar and, with your consent, marketing tools (Meta, X) to measure our ads. You can change this anytime in Settings.

Privacy policy
Pollar
HomeAskLiveBriefOriginalsSearchMapMarketsNotificationsFor You
ThreadsMarkets
NewsroomSupport Pollar
Privacy
Reader-supported

Free to read, and staying that way

No ads. Membership keeps Pollar independent.

from$2.99/mo

Support Pollar
Membership

Members don't see this panel.

  • Supporter$2.99/mo
  • Founder$6.99/mo
Support Pollar

Today’s Brief

Passengers storm a cockpit mid-flight

Flydubai attack jolts aviation as Russia pressures NATO and Ukraine’s grid again

A cockpit assault over the Middle East, fresh warnings around Europe and a winter-style strike on Ukraine’s power grid gave the day a hard security edge. In Washington, Donald Trump tried to rename artificial intelligence while regulators moved in the opposite direction, asking whether autonomous systems have already escaped their makers’ control.

Read the Brief

Live now

All live coverage
  • Denmark warns of Russian hybrid threats

    Finnish police open preliminary inquiry after suspected break-ins target homes of multiple MPs in Helsinki.

  • Flydubai flight diverted to Saudi Arabia

    Passengers and crew subdue an attacker attempting to crash a Flydubai flight, bringing the plane to a safe landing.

  • Biljana Plavsic dies at 96

    Former Bosnian Serb president Biljana Plavsic, convicted of war crimes by the ICTY, dies at 96 in Belgrade.

In the spotlight

All threads

European Union · Updated 9m ago

European democracies and populism

Romania's five-month paralysis now explicitly delaying EU budget participation; Berlin coalition exploratory talks begin; France's budget dispute adds RN pressure vector.

HomeBriefThreadsAsk
Categories
© El Periódico
Safety·42m ago

Police dismantle KillSec ransomware group and arrest 16-year-old leader in Spain

An international police operation led by German authorities dismantled the KillSec ransomware gang, seizing its dark web site and arresting a 16-year-old Romanian administrator in Alicante.

International takedown of KillSec

An international law enforcement operation named Operation KillSwitch dismantled the KillSec ransomware syndicate, taking down its dark web infrastructure and securing at least 110 terabytes of stolen data. The investigation was directed by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor's Office in Germany, with coordination provided by Europol and Eurojust. Police agencies across ten countries took part in the coordinated action, including Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States. Cybersecurity firms Bitdefender and Group-IB also contributed technical support to the multi-agency effort. Authorities carried out three provisional arrests and eight property searches across Greece, Romania, Spain, and the United Kingdom to disrupt the group's network and seize its illicit profits.

Key milestones in the KillSec investigation and takedown
  1. 2024KillSec begins ransomware operations exploiting cloud and software vulnerabilities
  2. Early 2025KillSec breaches Catalan public agency Infraestructures.cat, causing €1 million in damages
  3. 2025Guardia Civil opens Operación Rotoma following intelligence from FBI San Juan
  4. 2026-08Identified developer of the ransomware group turns 18 years old
  5. Sep 30, 2026Authorities seize dark web site and arrest 16-year-old suspect in Alicante
  6. Oct 1, 2026Europol announces the dismantling of KillSec under Operation KillSwitch

Spanish arrests and investigation

The Spanish branch of the inquiry, known as Operación Rotoma, was conducted jointly by the Guardia Civil's Central Operative Unit (UCO) Cybercrime Department and the Mossos d'Esquadra Criminal Investigation Division. Officers in the province of Alicante arrested a 16-year-old Romanian national identified as the primary administrator and operator of KillSec. The Guardia Civil identified the teenager starting from a single profile image following intelligence received in 2025 from the FBI field office in San Juan, Puerto Rico. Law enforcement teams searched two locations in Alicante, comprising a residential dwelling and an office within a hotel establishment, while placing one woman under formal investigation. Officers seized computer hardware, mobile phones, cryptocurrency wallets, and specialized anonymization and data-encryption tools, with early forensic analysis confirming transactions linked to ransom payments.

Support independent Pollar

Supporter and Founder memberships keep every article free to read, and add offline reading, audio, and a sponsor-free brief.

See membership tiers

Modus operandi and operational roles

KillSec began operating in 2024, penetrating target networks by exploiting software vulnerabilities and weakly protected access points, particularly in cloud storage services. Once inside a victim's network, the group exfiltrated sensitive internal records to infrastructure under its own control before issuing financial demands. The gang published victim names on its dark web leak platform alongside threats to release the stolen files if ransoms were unpaid. In multiple instances, the group demanded ransoms in cryptocurrency, with some victims paying sums of approximately €500,000. If organizations refused to pay, KillSec published the stolen data for free public download. In addition to the 16-year-old administrator, investigators identified a core developer who turned 18 years old in August 2026, alongside individuals acting as a negotiator and an affiliate.

Victim losses and attack volume

Law enforcement records show that KillSec launched approximately 1,000 cyberattacks globally, of which an estimated 500 were successful and affected more than 280 confirmed victim organizations. One confirmed intrusion targeted Infraestructures.cat, a public sector company belonging to the Government of Catalonia, in early 2025. Intruders accessed the Catalan entity's network, extracted sensitive files, and attempted extortion, generating damages calculated at close to €1 million. The seizure of the gang's dark web platform on 30 September 2026 prevented the further publication of stolen files, while international investigators continue to examine digital evidence seized during the eight raids to identify additional victims and financial flows.

Documented global scope of KillSec attacks · entities
Alleged total attacks
1,000
Successful attacks
500
Confirmed victims
280
Alleged total attacks
1000 entities
Successful attacks
500 entities
Confirmed victims
280 entities
Alicante · Hamburg · San Juan · Barcelona
United StatesSpainAlicanteRomaniaUnited KingdomGreeceMadrid

5 sources

  • Smantellata KillSec: il gruppo ransomware guidato da un sedicenne
    Adnkronos·2h ago
  • Detenido un menor en Alicante durante una operación internacional...
    europa press·2h ago
  • La UCO arresta a un adolescente de 16 años como líder de KillSec, responsable de mil ciberataques
    ABC TU DIARIO EN ESPAÑOL·2h ago
  • Un menor detenido en Alicante en una operación internacional contra el grupo ransomware KillSec
    LaVanguardia·2h ago
  • Cae KillSec, un grupo internacional de piratas informáticos que robó datos sensibles de una empresa de la Generalitat
    El Periódico·2h ago

Get Pollar Weekly

The week in news, every Friday. Free.

Free. No ads. Unsubscribe anytime.

More from Society & Science
Health & Education·from Sep 30·upd. 9m ago
© ANSA.it

French high school protests turn violent as 625 detained and staff attacked with petrol in Marseille

Student blockades over staffing shortages and budget cuts spread across France on Thursday, resulting in 625 arrests on Wednesday, multiple school fires, and emergency government crisis meetings.

Read article
Safety·from Sep 30·upd. 2h ago
© ANSA.it

Passengers and crew foil co-pilot suicide crash attempt on Dubai-Tel Aviv flydubai flight

A flydubai flight carrying 174 people made an emergency landing in Saudi Arabia after a co-pilot stabbed the captain in an attempt to down the jet, prompting an international investigation across the UAE, Israel and Saudi Arabia.

Read article
Safety·from Sep 30·upd. 5h ago
© ANSA.it

Christa Pike survives double lethal injection in Tennessee execution attempt

Christa Pike survived two lethal injection doses during an execution attempt on 30 September 2026 in Tennessee and was transferred to an off-site hospital, prompting Governor Bill Lee to suspend upcoming executions pending an independent review.

Read article
AI-generated·
Learn how