The KillSec ransomware crew has lost its leak site. Police and prosecutors from 10 countries took it over on Wednesday 30 September. They also seized five of the group's central servers and made three provisional arrests. Investigators think a 16-year-old was running the whole thing.

The takedown, called Operation KillSwitch, was run out of Hamburg, with Europol and Eurojust coordinating. Officers searched eight homes in Greece, Romania, Spain and the UK. And they locked at least 110 terabytes of stolen data away from anyone who'd want to download it.

What police took

Europol announced the operation on Thursday 1 October. Its release puts it bluntly in the headline: a teenager is suspected of leading KillSec, police have its servers and its leak site, and the group is linked to about 1,000 attacks worldwide.

Photo: OSeveno / Wikimedia Commons (CC BY-SA 3.0), cropped

That leak site was KillSec's main weapon. The group posted samples of stolen files there, then told victims the rest would go public unless they paid. If a victim didn't pay, Europol said, the stolen files could end up as free downloads. The site now shows a law enforcement seizure notice, and so do the group's other domains.

The five servers matter just as much as the website. Group-IB, a security firm that helped with the investigation, said they included the systems KillSec used to manage its activities and store data taken from victims. Europol described them the same way. Switzerland's federal government said all five were used to store victims' data, and that the raids also turned up evidence and assets.

For the people who got hit, this is the bit that counts. Europol says the 110 terabytes is now secured by police. It isn't sitting on a leak site waiting for the next download.

Who's been arrested

Investigators haven't named the 16-year-old. They believe the teen was KillSec's administrator and main operator. They also say they've identified a suspected developer, who turned 18 in August, plus a negotiator and an affiliate.

One of the three people arrested has been named. The US Justice Department said Fouad Eltibrizi, a Dutch national living in the UK who's also known as Archduke, was arrested in the UK on 30 September. A federal grand jury in Puerto Rico indicted him on 16 September. He's charged with conspiracy to access computers without authorization for financial gain, damaging a protected computer, and sending a threat with intent to extort.

Prosecutors say Eltibrizi and the others were at it from at least March to November 2025. They allege the group broke into a business in Puerto Rico in March 2025, gave it a seven-day countdown and posted samples of stolen patient data. When the company didn't respond, KillSec dumped about 180 gigabytes of its data, the indictment says. CyberScoop reported that prosecutors say Eltibrizi made calls as a KillSec representative in at least one extortion demand.

He's waiting on extradition from the UK. If he's convicted, he faces up to 10 years in prison. An indictment is only an allegation, and he's presumed innocent.

"The defendant and his co-conspirators carried out targeted intrusions against multiple companies and organizations, stealing highly sensitive information and attempting to extort their victims for substantial sums of money," Héctor Ramírez-Carbó, Acting US Attorney for the District of Puerto Rico, said in the department's release.

The FBI's San Juan office ran the US side. "Cyber-crimes will not go unpunished," Special Agent in Charge Carlos R. Goris said in the same release.

The other two arrests were in Romania and the UK, a Europol spokesperson told Reuters. In Romania, the country's organized crime prosecutors detained a 24-year-old on 30 September and asked a Bucharest court to hold him for 30 days, The Hacker News reported. Hamburg police called all three arrests provisional.

How big KillSec got

About 1,000 suspected attacks are linked to KillSec. So far investigators have confirmed about 500 of them as successful. Europol and the Justice Department both say that number could change as the seized evidence gets worked through. Before the takedown, the leak site listed about 450 victims, SecurityWeek reported.

KillSec didn't need anything fancy to get in. Prosecutors say it exploited different weaknesses in victims' systems, and the Justice Department's release adds poorly secured access points to the list. Europol says cloud storage was a particular target. Once inside, the group copied the data to its own servers and started the countdown.

Switzerland had been chasing the same crew since 31 July 2025. That's when the Swiss Attorney General's office opened criminal proceedings, after a run of attacks on Swiss companies between October 2023 and June 2025. The case covers data theft, unauthorized access, damage to data and extortion. Switzerland's federal police, fedpol, worked it with the country's National Cyber Security Centre and passed what it found to the international team.

Ten countries took part: Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK and the US. Security firms Bitdefender and Group-IB backed the work. The Justice Department also named Spain's Guardia Civil and Mossos d'Esquadra, the UK's Eastern Region Special Operations Unit, Romania's Central Cybercrime Unit, the Hellenic Police and Belgium's Federal Police.

What happens next

This isn't over. Investigators are going through the seized devices and data, and they're following KillSec's money, crypto included. In Spain, police seized computers, phones and crypto wallets. The Hacker News reported that a first look found transactions matching ransom payments from some victims. Hamburg police said they're still looking into other possible members.

The FBI's Cyber Division said in a post on X that the actions against KillSec "imposed serious cost and degraded the adversary's core capabilities." It went on: "We have undermined the group's ability to rebuild, limited their operational reach and reduced the likelihood of future attacks."

If your organization was hit, report it. Switzerland's cyber centre made that point in its release: reports and complaints are what make investigations like this one work. In the US, the FBI asks victims to report through IC3.gov.

The patching lesson

I won't go into how KillSec got in beyond what the charging papers say. They point to software weaknesses and badly secured access points, and that's enough to know what to do. The fix is the boring stuff. Patch internet-facing systems quickly, lock down cloud storage, and switch on multifactor login everywhere it's offered.

If you want somewhere to start, CISA's catalog of bugs criminals are already exploiting is the shortlist. Our guide to reading the KEV before you patch shows how to use it to set priorities.

Ransomware crews come back. Some rebrand within a month. But this one's alleged leader is in custody, its servers are gone, and 110 terabytes of other people's data is off the market. For one week, that's good news.