KillSec ransomware: 16-year-old suspected leader arrested

KillSec ransomware: 16-year-old suspected leader arrested

A 16-year-old is suspected of running KillSec, a ransomware group linked to almost 1,000 attacks around the world. Police arrested three people during a coordinated action day across four European countries.

The operation was coordinated by Eurojust, the European Union's agency for judicial cooperation in criminal matters. According to the agency, KillSec has been active since 2024. Investigators identified suspects in four roles within the group: administrator, developer, negotiator and affiliate.

The teenager is suspected of being both the administrator and the main operator of the group. A second suspect, who worked as a developer, has just turned 18. Eurojust noted that this person was still a minor when some of the alleged offences took place.

How KillSec operated

KillSec did not rely on sophisticated exploits to break in. The group targeted access points that organizations had not secured properly, with a particular focus on access tied to cloud storage. Weak protection of this kind is a recurring problem, as shown by the scale of credentials left exposed in code repositories.

After getting in, the attackers copied data from the victim's systems to their own servers. Eurojust described a familiar extortion model. Victims received samples of the stolen files as proof, along with a demand for payment. Those who refused to pay saw their data published and offered as a free download.

According to Eurojust, some victims paid "substantial" ransoms. The agency did not give a figure.

The members of the group used aliases online to hide who they were. They talked to each other through encrypted messaging services.

Searches in four countries

On the action day, officers searched eight homes in Spain, Greece, the United Kingdom and Romania. Besides the three arrests, they seized evidence and assets.

Authorities secured at least 110 terabytes of stolen data. During the wider investigation, they also took down five servers that KillSec used to store victim data, and seized domains run by the group. A seizure notice from Eurojust now appears in their place.

The work is not finished. Investigators will now go through the seized devices and data and follow the money the group made. Eurojust says this could reveal more victims, more attacks and more people involved.

Who took part

Judicial authorities from nine countries worked together through Eurojust: Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom and the United States. Belgium, Germany, Greece and Romania set up a joint investigation team at the agency. The action day itself was directed from a coordination centre at Eurojust.

Several police agencies were involved:

  • Germany's Federal Criminal Police Office
  • the UK's Eastern Region Special Operations Unit
  • Spain's Mossos d'Esquadra, the regional police force of Catalonia, and the Guardia Civil, one of Spain's national police forces
  • the FBI's San Juan Field Office

Europol, the EU's law enforcement agency, wrote reports on KillSec's activity and connected investigators with partners in the private sector. It also gave specialist help with tracing cryptocurrency and analysing digital evidence.

Our Take

The age of the suspects stands out. A 16-year-old as the alleged main operator, and a developer who was a minor for part of the period, suggests that running a large extortion operation no longer needs years of experience or a big budget. It fits a wider pattern of young offenders in cybercrime. In a separate case this week, the FBI urged ShinyHunters members to surrender after an arrest.

For defenders, the lesson is a basic one. KillSec reportedly did not need advanced tools. Poorly secured access, especially to cloud storage, was enough to reach close to 1,000 victims. Reviewing who and what can reach cloud data, and how that access is protected, is still one of the most effective controls available.

It is worth watching what the analysis of the 110 terabytes and the financial trail turns up. More victims may be notified, and more suspects may be named. How courts handle the cases of minors in a group of this size could also become a reference point for future prosecutions, much like other recent cases against cybercrime operators.