Skip to Main Content
PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Europol: Leader of 'KillSec' Ransomware Group Is a 16-Year-Old

Investigators allege that at least two teens are behind the KillSec gang, which conducted ransomware attacks and threatened to leak the stolen information unless victims paid up.

Principal Reporter
OUR EXPERT
When he's not battling bugs and robots in Helldivers 2, Michael is reporting on AI, satellites, cybersecurity, PCs, and tech policy.
Edited By:  
October 1, 2026
Add as a preferred source on Google
ransomware site (Europol)

Getting your Trinity Audio player ready...

Police in Europe allege that a 16-year-old is the leader of a ransomware group called KillSec, which tried to extort hundreds of businesses and organizations. 

Europol says the investigation also led to the shutdown of the KillSec site on the dark web, which has since been replaced with a seizure notice.  

“The alleged administrator and main operator is 16 years old,” Europol said. Investigators also identified another teenager who turned 18 last month as a KillSec developer. A third suspect was identified as a negotiator for the group, while a fourth acted as an “affiliate,” or a buyer who leased access to KillSec’s ransomware attacks. 

According to Europol, “Authorities carried out eight house searches in Spain, Greece, Romania, and the United Kingdom, made three provisional arrests, and seized evidence and assets.” The FBI also participated, and said "at least 110 terabytes of data" was seized, protecting it from further criminal acess.

In addition, Justice Department named one of the arrested suspects as "Fouad Eltibrizi (a/k/a Archduke)," a Dutch national, who was nabbed on Wednesday in the UK. The US is preparing to extradite him to face computer hacking charges. "If convicted, he faces a maximum penalty of 10 years in prison," the department said. His age was left unclear.

Still, the investigation underscores a persistent trend of teenagers fueling cybercrime, prompting efforts to steer youngsters away from hacking for profit. 

Europol alleges that KillSec, active since 2024, is behind 1,000 suspected cyberattacks, about half of which were successful. The group is known for infiltrating companies by exploiting software vulnerabilities or server misconfigurations to breach IT networks and then spreading ransomware to encrypt computers. 

The group also uses "double extortion" to steal sensitive information from their targets. “Victims were named on the group’s dark web leak site and threatened with publication of their data unless paid. Where a victim did not pay, the stolen files could be made available for free download,” Europol added. 

The authorities began investigating the group early last year, leading to the seizure of five key servers. “Investigators also uncovered how the group used AI to build and operate its ransomware infrastructure and to identify potential victims,” police in Germany said.

About Our Expert