About 500 organizations were successfully compromised by KillSec since 2024, investigators said — a startling tally that ended this week with the seizure of core infrastructure and the arrests of three alleged group members.
Operation KillSwitch: a coordinated takedown
Law enforcement described the action as “Operation KillSwitch,” a globally coordinated operation aided by 10 countries and private cybersecurity companies. Europol and the U.S. Justice Department said investigators seized KillSec’s data‑leak site and at least 110 terabytes of data, including information on the group’s criminal proceeds. Europol reported that investigators gained control of domains and five central servers the group used to manage activity and store stolen data.
Arrests, alleged roles, and charges
Authorities arrested three alleged members: the indicted negotiator Fouad Eltibrizi, a Dutch national who was arrested in the United Kingdom and is awaiting extradition to the United States; an alleged leader the agencies said is 16 years old (officials declined to name the individual); and a suspected developer whom Europol said committed multiple crimes before turning 18 in August. Eltibrizi was indicted last month in Puerto Rico and faces up to 10 years in prison on a charge of unauthorized computer access conspiracy. Prosecutors say Eltibrizi participated in the conspiracy from at least March through November 2025 and placed calls as a KillSec representative in at least one extortion demand.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageHow KillSec operated and what was taken
Europol and U.S. authorities described KillSec — also known as Kill Security Ransomware Group — as a data‑extortion group “primarily run by teenagers” that exploited various defects to intrude victims’ computers or cloud‑based network infrastructure and steal sensitive data for extortion demands. Officials said the group obtained substantial ransom payments in some cases. Law enforcement’s accumulated actions targeting KillSec’s infrastructure and people “imposed serious cost and degraded the adversary’s core capabilities,” the FBI’s Cyber Division said in a statement on X. The FBI added: “We have undermined the group’s ability to rebuild, limited their operational reach and reduced the likelihood of future attacks.”
Victims named in the indictment and links to the leak site
Some victims were identified in the indictment by initials alongside the location and date of the attacks: I.D.O. in Puerto Rico in March 2025; U.S.B.L. in Washington state in March 2025; and A.A. in Louisiana in September 2025. Prosecutors noted that three of those entries align with organizations listed on KillSec’s data‑leak site as Instituto de Ojos, US BioTek Laboratories and Accelerated Academy. Officials searched eight residences in Spain, Greece, the United Kingdom and Romania and said investigators are examining seized evidence to identify other potential members of the group.
How technologists, policymakers, and affected enterprises are likely to respond
- Technologists and security teams will be focused on the seized servers, domains and the 110 terabytes of data as sources of forensic indicators that can reveal the defects and intrusion vectors KillSec exploited, helping defenders to patch similar exposures.
- Policymakers and prosecutors will note the cross‑border coordination — 10 countries plus private firms — and the use of extradition to pursue alleged negotiators, reinforcing legal and diplomatic pathways for tackling transnational cyber extortion.
- Affected enterprises and victims will be monitoring the evidence review and the restored control of the group’s leak site, both to determine whether stolen material has been recovered and to learn whether listing practices on the site can be tied to particular operational patterns or negotiating tactics.
Officials framed the takedown as both a disruption and an investigative springboard: beyond arrests and seizures, investigators are combing through evidence to identify additional participants and to trace criminal proceeds. As authorities pursue extradition and evidence review continues, the case will test how well multinational cooperation and private‑sector assistance can translate seized infrastructure into prosecutions and recovered data.




