For more than a year, a ransomware group called KillSec extorted companies around the world: it stole their data, encrypted their systems, and threatened to publish everything if they didn't pay. We're talking about roughly a thousand attacks and more than a hundred terabytes of stolen information. What nobody expected is that when police finally identified the person running the whole operation, it turned out to be a 16-year-old living in Alicante, Spain.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
A digital extortion empire run out of Alicante
Spain's Guardia Civil and the Catalan Mossos d'Esquadra, as part of an international operation named "Operation KillSwitch," arrested a 16-year-old in Alicante on September 30, identifying him as KillSec's administrator and main operator. He wasn't a minor contributor or a simple affiliate: according to authorities, he was the one calling the shots.
The investigation also led to the arrest of a 24-year-old man in Romania, handled by the Romanian anti-mafia police (DIICOT), and to the identification of a person in the United Kingdom wanted for extradition by prosecutors in Puerto Rico. A suspected developer for the group, who turned 18 this past August, was identified but not arrested, since he was a minor when the acts attributed to him took place.
How KillSec operated: from poorly secured cloud storage to data hostage-taking
KillSec had been running since June 2024 as a "ransomware-as-a-service" (RaaS) operation: the core group built the malware and the infrastructure, then recruited outside affiliates who carried out the attacks in exchange for a cut of the ransom. Its preferred method wasn't especially sophisticated: unpatched known vulnerabilities and poorly configured access points, with a particular focus on cloud storage left exposed without proper protection.
Once inside, they stole data and published it, in whole or in part, on a leak site hosted on the dark web, as a way to pressure victims into paying. When authorities took control of that site, they secured at least 110 terabytes of information before it could become accessible to anyone.
Artificial intelligence in the service of ransomware
According to Hamburg police, who led the investigation, KillSec used artificial intelligence tools both to build and maintain its technical infrastructure and to identify potential victims. This isn't an isolated case: it's becoming increasingly common for cybercrime groups to use generative AI to speed up tasks that once required more technical knowledge, from spotting vulnerable targets to drafting extortion messages.
An unprecedented operation across ten countries
"Operation KillSwitch" coordinated authorities across ten countries: Spain, Germany, Belgium, Finland, Greece, the Netherlands, Romania, Switzerland, the United Kingdom, and the United States, with Hamburg police leading and support from Europol and Eurojust. The FBI's San Juan field office and the Puerto Rico prosecutor's office also took part, given that some victims were American. In total, eight raids were carried out in Spain, Greece, Romania, and the United Kingdom, resulting in three provisional arrests and the seizure of five of the group's central servers. The investigation has linked KillSec to around a thousand suspected attacks worldwide, of which roughly five hundred have been confirmed as successful so far.
Don't do this:
- Don't leave cloud storage buckets, shared repositories, or NAS systems accessible without authentication or encryption: that's exactly where KillSec found many of its victims.
- Don't delay applying security patches to servers and applications exposed to the internet, even ones that seem low priority.
- Don't pay the ransom assuming it guarantees your stolen data will be deleted: there's no guarantee that it will be.
- Don't ignore alerts about unusual access to your storage systems, however small or routine they may seem.
Do this:
- Keep regular backups and store them offline, disconnected from the network, so a ransomware attack can't encrypt them too.
- Review and restrict access permissions to your repositories and cloud storage: only people who genuinely need access should have it.
- If you've already been hit by an attack like this: disconnect the affected systems from the network, don't delete anything that could serve as evidence, and file a report with the police before considering any negotiation with the attackers.
- If you receive an extortion notice or a threat of data leakage, contact incident response specialists before making any decisions.
Perhaps the most unsettling part of this case isn't the amount of stolen data or the number of countries involved, but what it reveals about who's behind attacks like this today. It didn't take a nation-state or a criminal organization with decades of experience: a teenager with access to the right tools was enough. The lesson isn't that cybercrime has become more sophisticated, but that it increasingly takes less technical sophistication to cause enormous damage. And that means a company's defenses can't depend on attackers knowing little: they have to depend on its own systems being properly protected.