Authorities arrested the alleged leader and two other members of KillSec, a teenager-run data extortion group, and seized the group's infrastructure. Europol and the Justice Department announced the action on Thursday.
What happened
Authorities arrested three alleged KillSec members on September 30, 2026, as part of "Operation KillSwitch," a global operation that 10 countries and private cybersecurity companies supported. Investigators said the alleged leader is 16 years old but declined to name them. Europol said a suspected developer committed multiple crimes before turning 18 in August.
Police in the United Kingdom arrested Fouad Eltibrizi on Wednesday, and he awaits extradition to the United States. Prosecutors indicted him last month in Puerto Rico for unauthorized computer access conspiracy, which carries up to 10 years in prison. They are accusing him of acting as the group's negotiator.
Officials seized KillSec's data-leak site and at least 110 terabytes of data, including information on the group's criminal proceeds.
The backstory
Infosecurity Magazine reported on September 10, 2025, that KillSec had claimed responsibility for breaches at several healthcare organizations in the preceding weeks. These included Archer Health in the US, Suiza Lab in Peru, and the Colombian providers GoTelemedicina and eMedicoERP. The magazine described the activity as part of a campaign in Latin America and beyond.
Going deeper
- Infrastructure: Europol said investigators gained control of domains and five central servers. The group used these to manage its activities and store stolen data.
- Tactics: KillSec, also known as Kill Security Ransomware Group, exploited various defects to break into victims' computers or cloud-based network infrastructure. It then stole sensitive data to make extortion demands.
- Raids: Officials from the United States and Europe searched eight residences in Spain, Greece, the United Kingdom, and Romania. Investigators are now reviewing the seized evidence to identify other potential members.
What was said
The FBI's Cyber Division said in a statement on X that law enforcement's actions against KillSec's infrastructure and people "imposed serious cost and degraded the adversary's core capabilities." The FBI added, "We have undermined the group's ability to rebuild, limited their operational reach and reduced the likelihood of future attacks."
Héctor Ramírez‑Carbó, acting U.S. attorney for the District of Puerto Rico, said in a statement, "The defendant and his co-conspirators carried out targeted intrusions against multiple companies and organizations, stealing highly sensitive information and attempting to extort their victims for substantial sums of money."
He added, "Ransomware remains a serious and evolving threat to all sectors of our economy, from critical infrastructure to small businesses."
By the numbers
- 3 alleged members arrested
- About 500 organizations compromised since 2024
- 10 countries supported the operation
- 8 residences searched in Spain, Greece, the United Kingdom, and Romania
- 5 central servers seized
- At least 110 terabytes of data seized
- 16 years old, the alleged leader's age
Why it matters
A group run mostly by teenagers compromised about 500 organizations in less than two years, and officials say it collected substantial ransom payments in some cases.
The group also has a documented link to US healthcare. Infosecurity Magazine reported that KillSec claimed a breach at Archer Health, and the group's own leak site listed US BioTek Laboratories, a laboratory company, among its victims. Healthcare organizations hold sensitive data, which gives extortionists leverage over providers and patients. The U.S. attorney said ransomware threatens organizations of every size, from critical infrastructure to small businesses.
The case is not finished. Investigators are still examining evidence from the raids to identify other potential members, so more arrests could follow.
The bottom line
Law enforcement has seized KillSec's leak site and servers and arrested three suspected members. The FBI says this lowers the chance of future attacks, but the hunt for other members continues. Healthcare organizations and their vendors should treat ransomware as a threat to their own operations and not assume a takedown ends the risk. They should also check that their cloud storage is properly secured.
Related: HIPAA Compliant Email: The Definitive Guide
FAQs
What does Europol do?
Europol is the European Union's law enforcement agency, and it helps national police forces coordinate investigations into cross-border crime.
What is extradition?
Extradition is the legal process of transferring a suspect from one country to another so they can face charges there.
Does HIPAA apply to ransomware attacks?
Yes, HHS guidance says a ransomware attack that encrypts or exposes protected health information is presumed to be a reportable breach unless the organization can show a low probability the data was compromised.
How can organizations reduce their ransomware risk?
Organizations can lower their risk by training staff to spot phishing, keeping software patched, using multi-factor authentication, securing cloud storage, and keeping tested offline backups.
