That assessment frames a coordinated law-enforcement sweep that ripped into a prolific ransomware-as-a-service (RaaS) group called KillSec. Led by German police under an operation named KillSwitch and supported by Europol and private firm Group-IB, authorities say they dismantled core infrastructure, executed cross-border searches, and detained suspected operators — including a 16-year-old alleged ringleader arrested in Alicante, Spain.
Europol and Operation KillSwitch
Europol described the action as Operation KillSwitch. According to Europol, KillSec has been active since 2024 and "carried out at least 500 successful attacks in that time, although it is responsible for twice that number." Law enforcement seized the group's leak site and said the takedown prevented at least 110TB of stolen data from being exposed. Five servers used to manage KillSec’s activities and store victims’ data were claimed by police, and domains linked to the group now redirect to a police seizure notice.
Arrests, searches and evidence seized across Europe
Authorities executed eight house searches in Spain, Greece, Romania, and the UK. Police seized evidence and assets and made three provisional arrests. The detained 16-year-old is described in reports as a Romanian national arrested in the Spanish city of Alicante; other individuals identified include a suspected developer who turned 18 in August 2026, a person believed to have negotiated with victims, and another affiliate.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleKillSec’s methods: vulnerabilities, cloud storage and mixed extortion
Europol and Group-IB described KillSec as a RaaS outfit that targeted organizations by exploiting software vulnerabilities and poorly secure cloud storage access points. The group used Windows and VMware ESXi virtualization lockers but did not always encrypt victim systems; in some cases it stole data and relied on extortion rather than encryption. Group-IB said KillSec depended on a small core team that developed the locker and approved each build, signaling an operational model that combined development, approval and affiliate execution.
Victim profile and public claims identified by Group-IB
Group-IB identified 274 publicly claimed victims tied to KillSec. The firm reported that most of those organizations were based in the United States (35%) and India (17%). KillSec advertised stolen data for sale on its platforms, acting both as a ransomware operator and a data broker; price tags for stolen datasets ranged from $5,000 to $500,000, according to Group-IB’s findings.
What this means for hospitals, government bodies, and financial institutions
- Hospitals: The public attribution that KillSec “went after” hospitals underscores continued exposure for healthcare organizations where patient care and service continuity can be immediately affected by data theft or extortion.
- Government bodies: Public-sector entities named in the takedown face the twin tasks of confirming whether data was exfiltrated and strengthening defenses where poor cloud configurations or unpatched vulnerabilities were exploited.
- Financial institutions: For banks and related firms, the mix of locker tools and data brokerage poses both availability and confidentiality risks — and raises the cost calculus for incident response and potential regulatory scrutiny.
Indictment of Fouad Eltibrizi (aka Archduke) and U.S. charges
U.S. authorities announced the indictment of a Dutch national living in the UK, identified as Fouad Eltibrizi (aka Archduke). British police arrested Eltibrizi on September 30, and he is charged with hacking and extortion-related offenses that, if proven, carry a maximum sentence of 10 years imprisonment. The U.S. action shows prosecutors pursuing individuals connected to KillSec beyond the core seizures and provisional arrests carried out in Europe.
Operation KillSwitch dismantled parts of an active criminal platform, stopped the public release of a substantial trove of stolen files, and brought several suspects into custody. Yet the operation’s architects — those who developed and approved the locker builds, Group-IB said — remain the critical targets if law enforcement seeks to convert a pause into an enduring end to KillSec’s activities. The coming weeks will test whether evidence seized across multiple countries produces prosecutions that match the scale of the group's alleged campaign.




