A joint law-enforcement operation seized control of the KillSec ransomware group’s leak site on September 30, 2026, arresting three suspects and searching eight properties across four countries. The action, named Operation KillSwitch, secured at least 110 terabytes of data from the group’s infrastructure and identified a 16-year-old as the suspected main operator and administrator of the operation, according to Europol and reporting from SecurityWeek.

The most significant new detail to emerge since the initial takedown announcement is the identity of a second suspect: Fouad Eltibrizi, a Dutch national who goes by the online alias “Archduke.” The US Department of Justice says Eltibrizi was arrested in the United Kingdom on the same day the leak site went dark and is now awaiting extradition to face charges tied to a federal indictment handed down in Puerto Rico. That indictment, combined with the scale of the data haul and the involvement of a minor as the alleged ringleader, reframes what looked at first like a routine takedown into one of the stranger ransomware cases of the year.

What Happened on September 30: Inside Operation KillSwitch

Operation KillSwitch was coordinated by German authorities in Hamburg, with support from Europol, Eurojust, and law enforcement agencies spanning Belgium, Finland, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States. The coalition’s target was KillSec, a ransomware-as-a-service (RaaS) group that investigators have linked to roughly 1,000 suspected attacks worldwide.

On the day of the action, authorities took control of KillSec’s dark-web leak site, the public-facing page the group used to list victims and pressure them into paying. Taking over that infrastructure accomplishes two things at once: it cuts off the group’s main extortion lever, since victims can no longer be threatened with publication on a site the group controls, and it hands investigators a trove of server-side evidence that ransomware crews rarely leave behind voluntarily.

Three suspects were provisionally arrested as part of the sweep. Investigators searched eight properties in Greece, Romania, Spain, and the United Kingdom. Spanish authorities separately announced the arrest of a 16-year-old they describe as KillSec’s suspected leader, administrator, and main operator. The Record reported that five servers believed to have managed the group’s operations and stored stolen victim data were also seized during the action.

Who Is Fouad Eltibrizi, the Suspect Known as “Archduke”

The Department of Justice identified Eltibrizi as a Dutch national arrested in the UK on September 30 and now awaiting extradition proceedings to the United States. According to DOJ statements reported by The Register and The Record, a federal grand jury in the District of Puerto Rico indicted him on September 16, 2026, roughly two weeks before his arrest became public.

The reported charges against Eltibrizi include conspiracy to access computers without authorization, damaging a protected computer, and transmitting threats with intent to extort. The DOJ has framed the case as involving alleged cybercrime against systems in the United States and Puerto Rico specifically, which explains the unusual choice of venue for the indictment. Puerto Rico’s federal district has become a more frequent venue for cybercrime indictments in recent years, partly because incidents touching US territories but outside the mainland sometimes route through FBI field offices with jurisdiction there, including FBI San Juan.

Because extradition from the UK to the US runs through a formal judicial process rather than an administrative handover, Eltibrizi’s case could take months to resolve. He has not been convicted of anything at this stage, and the charges against him remain allegations that a US court will need to test.

The 16-Year-Old at the Center of the Investigation

The most unusual thread in this case is the age of the suspect investigators consider central to the whole operation. Spanish police announced the arrest of a 16-year-old described by Europol as KillSec’s suspected main operator and administrator. Public reporting reviewed for this story does not name the teenager, which is consistent with standard practice when a suspect is a minor, and it’s not clear from available sources whether the teen has been formally charged in any jurisdiction.

That detail matters beyond the individual case. Reporting describes KillSec as a group largely run by teenagers, a pattern that has shown up repeatedly in recent cybercrime enforcement. Law enforcement agencies in multiple countries have spent the last two years building cases against minors tied to extortion crews, and KillSec’s structure, if the reporting holds up, fits a pattern where technical skill and a willingness to take legal risk substitute for the organizational maturity of older, more established ransomware operations.

Identity of the Other Two Suspects Remains Unclear

Of the three suspects provisionally arrested, public sources confirm the identities of two: Eltibrizi and the 16-year-old. The third suspect’s identity was not established in the reporting reviewed for this story, and readers should treat that detail as still open rather than assume it has been resolved.

110 Terabytes: What Investigators Actually Seized

Europol says authorities secured at least 110 terabytes of data from KillSec’s leak-site infrastructure, protecting it against further unauthorized access. That figure, confirmed separately by SecurityWeek, represents one of the larger data seizures tied to a ransomware takedown in 2026. For context, 110 terabytes is roughly equivalent to tens of millions of typical office documents, or enough raw capacity to store several years of a mid-sized hospital system’s imaging archive.

What’s inside that data matters more than its size. Ransomware leak sites typically host a mix of stolen victim files used as extortion leverage, internal group communications, and sometimes affiliate-panel records showing who did what inside the operation. If investigators can mine that data for affiliate identities, the KillSwitch seizure could generate follow-on arrests well beyond the three suspects named so far. Bitdefender, which supported the operation, published an analysis arguing the takedown’s value extends past the immediate arrests because of what the seized infrastructure reveals about how the group recruited and paid affiliates.

Eight Properties, Four Countries: Mapping the Raids

The physical footprint of Operation KillSwitch spanned Greece, Romania, Spain, and the United Kingdom, where officers searched eight properties in total. That geographic spread illustrates something common to modern ransomware-as-a-service crews: the people involved rarely live in one country, and the affiliate model means a single group can have developers, administrators, and money-laundering contacts scattered across a continent or more.

Spain’s arrest of the 16-year-old suggests at least one search location tied directly to the alleged lead operator. The UK search led to Eltibrizi’s arrest. Reporting hasn’t clarified what, if anything, the Greek and Romanian searches turned up in terms of arrests, though property searches without accompanying arrests are common in multi-country operations where investigators are still building evidence against additional suspects.

Fast Facts: Operation KillSwitch at a Glance

Operation name:        Operation KillSwitch
Target:                KillSec ransomware-as-a-service group
Date of takedown:       September 30, 2026
Lead authority:         German police (Hamburg), with Europol/Eurojust
Suspects arrested:      3 (provisional)
Properties searched:    8, across Greece, Romania, Spain, UK
Data secured:           At least 110 TB
Suspected attacks tied: ~1,000 worldwide
Named suspect:          Fouad Eltibrizi ("Archduke"), Dutch national
Indictment:             Federal grand jury, District of Puerto Rico, Sept 16, 2026
Alleged lead operator:  16-year-old, arrested in Spain
Servers seized:         5 (per The Record)

KillSec’s Rise: A Short History of a Teen-Run RaaS Operation

Public reporting traces KillSec’s activity back to around 2024, operating under the now-familiar ransomware-as-a-service model: a core team builds and maintains the encryption and extortion tooling, then recruits affiliates who carry out the actual intrusions in exchange for a cut of any ransom paid. The group ran a leak site to pressure non-paying victims by threatening to publish stolen data, the same playbook used by larger, longer-running operations like LockBit and Clop.

Figures on KillSec’s reach vary depending on how you count. Investigators have linked the group to approximately 1,000 suspected attacks worldwide, a figure that includes incidents still under investigation. Separate reporting citing Europol and the DOJ put the number of organizations successfully compromised since 2024 at roughly 500. The gap between those two numbers is the difference between every attempted or suspected intrusion and the subset where investigators are confident the group actually got in and did damage.

A Pattern of Younger Operators in Ransomware Crews

KillSec is not the first ransomware-adjacent operation where law enforcement has pointed to a minor as a central figure, but the scale here, roughly 500 to 1,000 attacks allegedly run under a 16-year-old’s direction, is large for that pattern. It raises an uncomfortable question for defenders: the technical bar to run a modern RaaS operation has dropped far enough that age and operational maturity no longer track together the way they used to.

Operation KillSwitch by the Numbers

MetricFigureSource
Date of takedownSeptember 30, 2026Europol, DOJ
Suspects provisionally arrested3Europol, SecurityWeek
Properties searched8Europol, The Register
Countries searchedGreece, Romania, Spain, UKEuropol
Data secured from leak-site infrastructureAt least 110 TBEuropol, SecurityWeek
Suspected attacks linked to KillSec~1,000 worldwideEuropol, DOJ
Organizations reportedly compromised since 2024~500Reporting citing Europol, DOJ
Servers seized5The Record
Countries contributing agencies to the wider operation10 (reported)CyberScoop
Named suspect facing US extraditionFouad Eltibrizi (“Archduke”)DOJ

How KillSec Compares to Other Ransomware-as-a-Service Takedowns

Operation KillSwitch joins a short list of major RaaS disruptions over the past two years, and the comparison is useful for gauging how far this one actually goes. Operation Cronos, the UK-led action against LockBit in February 2024, seized the group’s dark-web infrastructure and obtained decryption keys, but it did not result in the immediate arrest of the group’s core leadership, who investigators say remain outside the reach of Western law enforcement. The FBI’s December 2023 disruption of ALPHV/BlackCat similarly seized the group’s site and released a decryption tool, yet the group resurfaced within weeks and went on to pull off an exit scam against its own affiliates after the Change Healthcare attack. Clop, by contrast, has never faced a comparable infrastructure seizure despite running the 2023 MOVEit mass-exploitation campaign that hit hundreds of organizations. Its operators are believed to still be at large.

Measured against that backdrop, KillSwitch stands out for actually producing arrests, including a named suspect now facing a US indictment, rather than just infrastructure disruption that a resilient group can rebuild.

OperationYearGroup TargetedArrests of Named SuspectsInfrastructure Seized
Operation KillSwitch2026KillSecYes (3 provisional, incl. named suspect)Yes, leak site + 110 TB
Operation Cronos2024LockBitNo core leadership arrest confirmedYes, site + decryption keys
ALPHV/BlackCat disruption2023ALPHV/BlackCatNoYes, site seized, group resurfaced
MOVEit campaign response2023-2024ClopNo confirmed arrestsNo comparable seizure

What Cybersecurity Firms and Agencies Are Saying

Law enforcement’s own announcement carried most of the operational detail. The FBI Cyber Division stated: “Today we’re announcing Operation KillSwitch, a joint sequenced operation led by @FBISanJuan targeting the Kill Security Ransomware Group (‘KillSec’).” The same agency described the immediate results of the action: “Authorities in the U.S. and Europe took control of KillSec’s leak site, securing at least 110 terabytes of data against further criminal access, and arrested Dutch national Fouad Eltibrizi, an alleged KillSec member who is now pending extradition to the United States.” Both statements appear in the FBI Cyber Division’s public announcement.

CyberScoop’s coverage framed the scale of the coalition behind the action, reporting that “the arrests were part of ‘Operation KillSwitch,’ a globally coordinated operation aided by 10 countries and private cybersecurity companies,” a detail available in CyberScoop’s report.

Bitdefender, one of the private firms that supported the operation, summarized the enforcement outcome in its own writeup: “It resulted in three provisional arrests and eight property searches across four countries,” according to Bitdefender’s analysis of what the takedown means for defenders. The company’s involvement reflects a broader trend of private security vendors contributing technical analysis, and sometimes infrastructure access, to law enforcement ransomware cases.

Market and Industry Impact: What This Means for Ransomware Defense

For security teams, the immediate practical impact of a takedown like this is limited. KillSec’s leak site is down and its named infrastructure is in investigators’ hands, but ransomware-as-a-service operations have shown repeatedly that disrupting one group’s brand doesn’t shrink the overall market. Affiliates who worked under KillSec’s banner can, and historically do, resurface under a different name within weeks or months, carrying the same tooling and the same access to compromised networks they built up before the takedown.

That said, the 110 terabytes of seized data gives defenders something LockBit’s and ALPHV’s takedowns didn’t fully deliver: a large body of internal operational records that, if shared with threat-intelligence vendors and incident responders, could expose indicators tied to dozens of still-unreported victim organizations. Bitdefender’s framing of the takedown’s value, centered on affiliate exposure rather than the arrests themselves, points toward where the real defensive payoff is likely to land in the coming months.

Insurance and Compliance Ripple Effects

Organizations that paid KillSec ransoms, or that are still negotiating with affiliates who claimed to represent the group, now face a complicated question: does a law-enforcement seizure of the group’s leak site change their exposure if stolen data was already copied elsewhere before the takedown? Cyber-insurance underwriters typically treat a confirmed law-enforcement seizure as a mitigating factor in post-incident claims, but it does not erase the underlying breach notification obligations a victim organization already owed regulators before September 30.

The Minors-Running-Ransomware Problem

KillSec’s case adds to a growing body of enforcement actions where the alleged architect of a cybercrime operation turns out to be a teenager. The pattern has shown up across multiple categories of cybercrime over the past two years, from SIM-swapping crews to data-extortion groups, and it’s prompting renewed debate among prosecutors and policymakers about how to handle cases where the most capable technical operator in a criminal enterprise is legally a minor.

That debate matters for how this specific case plays out. If the 16-year-old suspect is ultimately prosecuted as a juvenile under Spanish law, the legal consequences and the public disclosure of details will look very different than the federal prosecution Eltibrizi faces in the US. Readers should expect two very different legal tracks to run in parallel from the same takedown.

Eltibrizi’s path to a US courtroom runs through UK extradition proceedings, a process that can take anywhere from a few months to well over a year depending on whether he contests the request. The charges reported against him, conspiracy to access computers without authorization, damaging a protected computer, and transmitting threats with intent to extort, are standard federal cybercrime charges that carry substantial prison exposure if he is convicted, though no conviction has occurred at this stage.

For the other two suspects, including the 16-year-old, the legal process will likely play out locally in Spain rather than through extradition, since European law enforcement has primary jurisdiction over suspects arrested on its own soil absent a specific extradition request. Whether additional suspects get identified from the 110 terabytes of seized data remains the open question that will shape how this case develops over the next several months.

5 Predictions for the Next Phase of the KillSec Case

  • Expect at least one follow-on arrest within six months as investigators work through the 110 terabytes of seized data for affiliate identities, mirroring how prior RaaS seizures have generated secondary cases.
  • Eltibrizi’s extradition fight will likely stretch into mid-2027 if he contests it, consistent with typical UK-to-US extradition timelines for contested cybercrime cases.
  • KillSec-branded activity will probably go quiet on its old leak site permanently, but expect chatter on cybercrime forums about a rebrand attempt by remaining affiliates within three to six months.
  • Additional law-enforcement statements naming more participating countries are likely as agencies in the ten-country coalition CyberScoop referenced publish their own summaries of the operation.
  • Expect cyber-insurance carriers and incident-response firms to request access to the seized data set to cross-reference undisclosed client breaches, a pattern that followed both the LockBit and ALPHV seizures.

Frequently Asked Questions

What is Operation KillSwitch?
Operation KillSwitch is the international law-enforcement action that took control of the KillSec ransomware group’s leak site on September 30, 2026, leading to three provisional arrests and the seizure of at least 110 terabytes of data.

Who is Fouad Eltibrizi?
Fouad Eltibrizi, also known online as “Archduke,” is a Dutch national arrested in the United Kingdom on September 30, 2026. The US Department of Justice says he faces a federal indictment out of the District of Puerto Rico and is awaiting extradition to the United States.

Is the KillSec leader really a teenager?
Europol and Spanish authorities identified a 16-year-old as KillSec’s suspected main operator and administrator. The teen’s identity has not been publicly released, and it is described as a suspected role rather than a confirmed legal finding.

How much data did investigators seize from KillSec?
Europol says authorities secured at least 110 terabytes of data from KillSec’s leak-site infrastructure. The Record separately reported that five servers tied to the group’s operations were seized.

How many attacks is KillSec linked to?
Investigators have tied KillSec to approximately 1,000 suspected ransomware attacks worldwide. Separate reporting citing Europol and the DOJ put the number of organizations successfully compromised since 2024 at roughly 500.

Which countries were involved in the raids?
Officers searched eight properties across Greece, Romania, Spain, and the United Kingdom. CyberScoop reported that the wider operation was supported by agencies from ten countries in total.

What charges does Eltibrizi face?
Reported charges include conspiracy to access computers without authorization, damaging a protected computer, and transmitting threats with intent to extort, stemming from a federal grand jury indictment filed in Puerto Rico on September 16, 2026. He has not been convicted of any of these charges.

Will KillSec come back under a different name?
No one can say for certain, but ransomware-as-a-service affiliates have historically rebranded after takedowns, as seen with ALPHV/BlackCat resurfacing weeks after its December 2023 disruption. Whether KillSec’s remaining affiliates attempt the same remains to be seen.