Spanish authorities have apprehended a 16-year-old believed to be the mastermind behind the KillSec ransomware group. KillSec is accused of pilfering sensitive information from various organizations and threatening to expose it on their leak site unless a ransom was paid.
On September 30, the 16-year-old, along with two other individuals, was arrested, and control of the leak site was seized by the police.
Hamburg police identified the teenager as the suspected administrator and main operator of KillSec. The operation was led by police and prosecutors in Hamburg, Germany.
The Spanish police forces, Guardia Civil and Mossos d’Esquadra, detained the teenager in Alicante and conducted searches at a home and an office in a hotel in the province. According to a joint statement carried by elperiodic.com, he was one of the group’s administrators and its presumed main administrator.
Two other individuals, one in the U.K. and one in Romania, were also arrested in connection with KillSec. The U.S. prosecutors in Puerto Rico and the FBI’s San Juan office were involved in the operation. Puerto Rico has requested the extradition of the individual arrested in the U.K.
In Romania, a 24-year-old was detained and is under investigation for various cybercrimes related to the operation of an organized criminal group known as KillSec.
The investigation revealed that KillSec had different roles within the group, including an administrator, a developer, a negotiator, and an affiliate who carried out attacks using the group’s ransomware tools.
Authorities seized computer equipment, phones, and cryptocurrency wallets in Spain, leading to the discovery of ransom payments from some victims. The investigation into KillSec began in 2025 and involved cooperation between several countries and security agencies.
How KillSec Operated
KillSec exploited software vulnerabilities and insecure access points to gain entry into organizations, particularly through cloud storage. They would then copy sensitive data and demand ransom from the victims.
The group would threaten to publish the stolen data if the ransom was not paid, and in some cases, offer the data for free download. The investigation has identified approximately 1,000 attacks worldwide, with about 500 confirmed successful attacks.
KillSec utilized artificial intelligence to build and manage its infrastructure and identify potential targets. They would buy access credentials from the dark web, send samples of stolen data to victims as proof, and demand ransom payments.
Continued Investigation
The authorities have successfully shut down the KillSec ransomware group and are continuing their investigation to uncover more victims, attacks, and suspects involved in the operation.
They are examining the seized devices and data, tracing the group’s financial transactions, including cryptocurrency, to identify additional criminal activities associated with KillSec.



