Teenage Ransomware Leader Among Three Arrested as Police Dismantle KillSec in Operation KillSwitch

Law enforcement agencies from roughly ten countries, working alongside Europol, the FBI and the U.S. Department of Justice, dismantled the infrastructure behind the KillSec ransomware-as-a-service operation in a coordinated action dubbed Operation KillSwitch, CyberScoop reported. Investigators said the group’s alleged ringleader was only 16 years old at the time of arrest, underscoring a trend in which minors have taken lead roles in major cybercrime operations. Authorities estimate KillSec has compromised roughly 500 organizations worldwide since launching in 2024, leasing ransomware tools and extortion services to affiliates on a subscription basis.

Officers searched eight residences across Spain, Greece, the United Kingdom and Romania, seizing five central servers, the group’s dark-web leak site, several domains used to manage its operations, and more than 110 terabytes of data tied to its criminal proceeds, according to the report. Among those detained was Dutch national Fouad Eltibrizi, arrested in the United Kingdom, whom investigators allege acted as a negotiator handling ransom demands with victim organizations between March and November 2025. A third suspect, described as a developer for the group, is accused of contributing to the malware before turning 18 in August.

KillSec had built a reputation as one of the more active ransomware-as-a-service brands of the past two years, leasing its leak-and-extort toolkit to affiliates who carried out the underlying intrusions. The takedown adds to a string of recent law-enforcement actions against ransomware and extortion operations, with officials involved in the case framing the cross-border cooperation as a signal that age offers no shield from prosecution for cybercrime.

Read the original report →