The KillSec ransomware group was the target of Operation KillSwitch on September 30, when law enforcement agencies executed a coordinated action that took control of the group’s infrastructure and secured at least 110 terabytes of data.
Spanish police detained a 16-year-old Romanian national in Alicante who is suspected of acting as KillSec’s main operator and administrator, including control over the group’s leak site. Investigators arrested two other suspects—one in Britain and one in Romania—and identified a fourth suspect who has not yet been arrested as part of the same operation.
Operation KillSwitch was a coordinated law enforcement action linked to the KillSec ransomware group that included multinational searches of eight properties in Spain, Greece, Romania and the United Kingdom. The broader investigation covers around 1,000 suspected ransomware attacks worldwide, with about 500 incidents identified as successful. Law enforcement agencies involved in the operation and related investigations include Europol, the FBI Cyber Division, the Hamburg State Criminal Police Office, the Swiss federal police and Spanish police. Swiss prosecutors have been investigating suspected KillSec attacks on Swiss companies dating from October 2023 to June 2025, and that Swiss inquiry has been underway since July 2025.
The multinational searches and extensive investigative scope involved coordinated activity across several jurisdictions. Investigative measures included property searches and criminal inquiries carried out by the listed national and international agencies.
The KillSec ransomware group exploited software vulnerabilities and poorly secured access points, with particular use of cloud storage access that lacked adequate protections. The group named victims on a dark web leak site and threatened publication of stolen data unless ransoms were paid, with payments demanded in cryptocurrency. KillSec employed a double extortion tactic that involved encrypting victims’ servers and simultaneously threatening to publish stolen data if ransom demands were not met. These operational methods were described in the investigation and related indictment.
KillSec posted a Puerto Rico breach in March 2025 that included samples of stolen patient data, and roughly 180GB of data were published after the targeted company did not respond. The indictment also describes similar breaches in California, Washington State and Louisiana. Those documented incidents were presented as examples of the group’s broader pattern of stealing data, publishing samples and seeking extortionate payments.
A federal grand jury in Puerto Rico indicted Fouad Eltibrizi, a Dutch national resident in the UK who used the handle Archduke, on September 16 on charges of conspiracy to access computers without authorization for financial gain, damaging protected computers and transmitting extortion threats. The indictment states he faces extradition and a maximum penalty of 10 years. Investigators further found that the group used artificial intelligence to build and maintain its ransomware infrastructure and to identify potential victims.
Authorities carried out a coordinated action against the KillSec ransomware group that resulted in multiple arrests and the seizure of a large volume of data from the group’s infrastructure. Investigations linked to the operation remain active across several countries, with searches and inquiries continuing as authorities pursue additional suspects and examine seized material. The action involved collaboration among multiple national and international law enforcement agencies working to disrupt the group’s operations and support ongoing legal processes.


