He is 16. He allegedly ran an international ransomware network. Arrested in Alicante.

An international operation against KillSec has brought five servers under police control and secured 110 terabytes of data. Investigators are examining hundreds of suspected cyberattacks and searching for other possible members of the network.
A 16-year-old Romanian national has been arrested in the province of Alicante over his suspected role as the main administrator of the international group KillSec. Investigators believe the network specialised in cyberattacks and extortion: its members stole confidential information from organisations and threatened to publish it unless victims paid a ransom.
The arrest took place on 30 September 2026 as part of the international Operation KillSwitch, coordinated by Europol and Eurojust. Three people were provisionally arrested and eight searches were carried out in Spain, Greece, Romania and the United Kingdom. The Spanish investigation was conducted by the Guardia Civil and Catalonia’s Mossos d’Esquadra, in cooperation with the US Federal Bureau of Investigation.
A thousand attacks and more than 280 potential victims
According to Europol, investigators link KillSec to around 1,000 suspected cyberattacks worldwide. Approximately 500 are believed to have resulted in successful access to victims’ systems. More than 280 organisations may have been affected. These figures could change as investigators continue examining the seized evidence.
The group is believed to have been active since around 2024. Its members exploited software vulnerabilities and poorly secured access points, including those associated with cloud storage. Once inside an organisation’s systems, they copied internal documents and other sensitive information to servers under their control.
The organisations were then named on a leak website on the dark web. The criminals threatened to publish the stolen files unless a ransom was paid. If a victim refused to pay, the data could be made available for download.
110 terabytes of data and five servers
During the operation, law enforcement took control of KillSec’s leak site and secured at least 110 terabytes of data against further unauthorised access. Five central servers and several domains used by the group were also brought under police control.
In Alicante province, officers carried out two searches: one at a residence and another at an office inside a hotel establishment. Investigators seized computer equipment, mobile phones, cryptocurrency wallets, and tools used for encryption and anonymisation.
An initial analysis identified transactions consistent with ransom payments made by some victims. Media reports citing the investigation have said that some payments may have reached approximately €500,000 in cryptocurrency.
Europol also reports that the group used artificial intelligence to build and maintain its ransomware infrastructure and identify potential victims. The technical details of that activity have not yet been fully disclosed.
How investigators identified the suspect
The Spanish investigation, known as Operation ROTOMA, began in 2025 following cooperation between the Guardia Civil and the FBI office in San Juan, Puerto Rico. The Mossos d’Esquadra opened a separate line of inquiry after a cyberattack against a Catalan organisation in early 2025.
According to the Guardia Civil, specialists from its Central Operative Unit (UCO) identified one of KillSec’s suspected administrators using a profile image. Further investigation led them to his location in Alicante province.
The attack under investigation in Catalonia allegedly involved unauthorised access to computer systems, the theft of confidential information and an attempted extortion. The initial estimated damage was close to €1 million.
Investigators believe the network divided responsibilities among different roles, including an administrator, a developer, a negotiator and an affiliate involved in individual attacks. Inquiries into other possible members are continuing.
Spain: cybercrime has increased more than fivefold in a decade
The KillSec case is part of a much wider problem. According to Spain’s Ministry of the Interior, 92,716 cybercrimes were recorded in 2016. In 2025, the figure reached 488,426 — approximately 5.3 times higher.
Cybercrime accounted for 19.8% of all recorded crime in Spain in 2025. Of the total, 429,677 cases were computer fraud. This distinction matters: the national statistics include many types of offences committed using digital technologies and do not mean that every recorded case involved hacking or ransomware extortion.
During 2025, law enforcement agencies arrested or investigated 19,876 people across the various categories of cybercrime. That figure also covers a broad range of offences, not ransomware alone.
Two cases that illustrate the scale of the threat
The 2023 attack on Hospital Clínic in Barcelona. In March, a ransomware attack disrupted the hospital’s computer systems and those of related units. Around 150 non-urgent operations and up to 3,000 appointments had to be cancelled. The incident showed that digital extortion can affect not only finances and data, but also the delivery of healthcare.
The international operation against LockBit in 2024. Europol and law enforcement agencies from several countries disrupted the infrastructure of one of the world’s most active ransomware groups. The operation targeted servers, technical resources and tools used by the criminals. It demonstrated that tackling ransomware requires not only arrests, but also the disruption of the infrastructure that enables further attacks.
These incidents are not identical to the KillSec case, but they help illustrate the scale of the threat and the consequences of attacks on organisations and essential services.
The investigation is ongoing
The international operation targeted both the suspected members of KillSec and the infrastructure that enabled the group’s activities. Investigators are continuing to analyse seized devices and data, trace possible criminal proceeds — including cryptocurrency assets — and identify further potential victims.
The key question now is what the analysis of 110 terabytes of data will reveal. The material could uncover additional attacks, affected organisations and other people suspected of involvement in the network.
An arrest is not a conviction. The teenager’s role and the responsibility of the other suspects must be established through the investigation and judicial proceedings.






Comments