Spain Arrests Teen Suspected of Leading KillSec Ransomware Network
Spanish authorities have arrested a 16-year-old Romanian national accused of acting as the main operator of KillSec, a ransomware group linked to about 1,000 attacks worldwide. The arrest formed part of an international investigation spanning several European countries.
Authorities say KillSec targeted organizations by exploiting software vulnerabilities and poorly secured access points, particularly cloud storage. The group allegedly copied sensitive information and then demanded cryptocurrency payments while threatening to publish stolen data.
The investigation also focuses on the financial trail from those ransom demands. Spanish police said officers seized cryptocurrency wallets during searches and found transactions that appear to match ransom payments made by some victims.
International crackdown expands
The operation produced three arrests and eight searches across Spain, Greece, Romania and the United Kingdom. A second suspect, arrested in Britain, faces an extradition request from Puerto Rico, where U.S. authorities have separately charged a Dutch national over alleged KillSec-related cyberattacks.
A third suspect was detained in Romania. Investigators have also identified a developer who turned 18 in August but was allegedly a minor when some of the suspected offenses occurred. That person has not been arrested.
Reuters reported that the 16-year-old was detained in Alicante and is suspected of serving as KillSec’s administrator. Authorities have not publicly identified the teenager.
Crypto proceeds remain under investigation
Spanish investigators seized computer equipment, mobile phones, cryptocurrency wallets and tools designed to conceal activity. The evidence could help authorities trace how ransom payments moved through crypto wallets and identify additional participants or assets connected to the alleged operation.
Europol said KillSec obtained substantial ransom payments from victims. The group also operated a leak site where it threatened to publish stolen information when organizations refused to pay.
Authorities have taken control of KillSec’s infrastructure, including servers containing about 110 terabytes of data. The investigation remains ongoing as law enforcement agencies examine the group’s suspected attacks, financial proceeds and wider network.