Particle.news

Police Dismantle KillSec and Arrest Alleged 16‑Year‑Old Operator

Containing the group's core infrastructure gives prosecutors the evidence needed to identify victims, trace ransom payments, pursue extraditions

Overview

  • Operation KillSwitch, run from Hamburg on Wednesday, executed coordinated searches in several countries, seized KillSec’s leak site, five central servers and domains, secured at least 110 terabytes of stolen data, and led to three provisional arrests including a 16‑year‑old suspected administrator.
  • One of the detainees in the United Kingdom was named in a U.S. indictment as Fouad Eltibrizi and now faces extradition to the United States to answer charges tied to KillSec extortion calls.
  • Authorities say KillSec gained access to victims by exploiting software vulnerabilities, exposed Remote Desktop Protocol services and misconfigured cloud storage, then copied and listed stolen files to pressure payments.
  • Investigators found signs the group used artificial intelligence to build infrastructure and pick targets, and police seized cryptocurrency wallets and other financial evidence to trace ransom proceeds.
  • Officials will now analyze seized devices and data to identify more victims and affiliates, and the evidence will support cross‑border prosecutions, additional arrests and victim notifications.