For more than a year, a ransomware group called KillSec extorted companies around the world: it stole their data, encrypted their systems, and threatened to publish everything if they didn't pay. We're talking about roughly a thousand attacks and more than a hundred terabytes of stolen information. What nobody expected is that when police finally identified the person running the whole operation, it turned out to be a 16-year-old living in Alicante, Spain.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

A digital extortion empire run out of Alicante

Spain's Guardia Civil and the Catalan Mossos d'Esquadra, as part of an international operation named "Operation KillSwitch," arrested a 16-year-old in Alicante on September 30, identifying him as KillSec's administrator and main operator. He wasn't a minor contributor or a simple affiliate: according to authorities, he was the one calling the shots.

The investigation also led to the arrest of a 24-year-old man in Romania, handled by the Romanian anti-mafia police (DIICOT), and to the identification of a person in the United Kingdom wanted for extradition by prosecutors in Puerto Rico. A suspected developer for the group, who turned 18 this past August, was identified but not arrested, since he was a minor when the acts attributed to him took place.

How KillSec operated: from poorly secured cloud storage to data hostage-taking

KillSec had been running since June 2024 as a "ransomware-as-a-service" (RaaS) operation: the core group built the malware and the infrastructure, then recruited outside affiliates who carried out the attacks in exchange for a cut of the ransom. Its preferred method wasn't especially sophisticated: unpatched known vulnerabilities and poorly configured access points, with a particular focus on cloud storage left exposed without proper protection.

Once inside, they stole data and published it, in whole or in part, on a leak site hosted on the dark web, as a way to pressure victims into paying. When authorities took control of that site, they secured at least 110 terabytes of information before it could become accessible to anyone.

Artificial intelligence in the service of ransomware

According to Hamburg police, who led the investigation, KillSec used artificial intelligence tools both to build and maintain its technical infrastructure and to identify potential victims. This isn't an isolated case: it's becoming increasingly common for cybercrime groups to use generative AI to speed up tasks that once required more technical knowledge, from spotting vulnerable targets to drafting extortion messages.

An unprecedented operation across ten countries

"Operation KillSwitch" coordinated authorities across ten countries: Spain, Germany, Belgium, Finland, Greece, the Netherlands, Romania, Switzerland, the United Kingdom, and the United States, with Hamburg police leading and support from Europol and Eurojust. The FBI's San Juan field office and the Puerto Rico prosecutor's office also took part, given that some victims were American. In total, eight raids were carried out in Spain, Greece, Romania, and the United Kingdom, resulting in three provisional arrests and the seizure of five of the group's central servers. The investigation has linked KillSec to around a thousand suspected attacks worldwide, of which roughly five hundred have been confirmed as successful so far.

Don't do this:

Do this:

Perhaps the most unsettling part of this case isn't the amount of stolen data or the number of countries involved, but what it reveals about who's behind attacks like this today. It didn't take a nation-state or a criminal organization with decades of experience: a teenager with access to the right tools was enough. The lesson isn't that cybercrime has become more sophisticated, but that it increasingly takes less technical sophistication to cause enormous damage. And that means a company's defenses can't depend on attackers knowing little: they have to depend on its own systems being properly protected.