Police have seized the KillSec ransomware group’s leak site and five of its servers, taking at least 110 terabytes of stolen data into custody. The action ran on 30 September 2026 across Greece, Romania, Spain and the United Kingdom, and produced three provisional arrests. Europol published the results on 1 October 2026.
What Police Took Control Of
The seizure covered KillSec’s public-facing extortion site and the infrastructure behind it. The operation, codenamed KillSwitch, was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office in Germany, with coordination from Europol’s European Cybercrime Centre and the EU judicial agency Eurojust.
- Five servers: central machines used to run the group and store data taken from victims are now under police control.
- Five domains: KillSec’s web addresses, including the leak site, now redirect to a law enforcement seizure notice.
- 110 terabytes: the minimum volume of stolen data recovered from that infrastructure.
- Eight searches: properties were searched in four countries on the day of the action.
Ten countries took part in the investigation: Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom and the United States. The security firms Bitdefender and Group-IB supplied intelligence.
Three Arrests, and One Named Indictment
The three provisional arrests and the one unsealed criminal case are separate matters. Investigators identified a 16-year-old Romanian national, arrested in Alicante in Spain, as KillSec’s suspected administrator and main operator. Two further suspects in their twenties were arrested in the United Kingdom and Romania. None has been convicted.
The named case is American. According to the United States Department of Justice, a federal grand jury in the District of Puerto Rico indicted Fouad Eltibrizi, a Dutch national living in the United Kingdom who used the handle Archduke, on 16 September 2026 on a charge of conspiracy to access computers without authorisation. He was arrested in the United Kingdom on 30 September 2026 and faces a maximum of 10 years in prison if convicted. The indictment describes a double-extortion campaign and an attack on a company in Puerto Rico whose stolen patient data, about 180 gigabytes, was published after a seven-day payment deadline passed.
As of 5 October 2026 he remains in the United Kingdom pending extradition and has not appeared before a United States court. An indictment is an allegation, and a defendant is presumed innocent until proven guilty.
Where KillSec’s Victims Were
The victim list was global and weighted towards North America and Asia. Group-IB, the Singapore-headquartered security firm that monitored KillSec’s leak site and Telegram channels, counted 274 organisations publicly claimed as victims and broke them down by country.
| Country or region | Share of claimed victims |
|---|---|
| United States | 35% |
| India | 17% |
| Brazil | 3% |
| United Kingdom | 3% |
| Australia | 3% |
| Colombia | 3% |
By region, Group-IB put North America at 35% of claimed victims, Asia-Pacific at 30%, Europe at 14% and the Middle East and Africa at 10%. Financial services and healthcare were the most affected sectors, with government bodies and large enterprises also on the list.
Europol puts the investigation’s scope at around 1,000 suspected attacks worldwide since the group emerged in 2024, of which about 500 have so far been identified as successful.
What the Takedown Does Not Undo
Seizing the data does not unpublish it. Files that KillSec already released, including the roughly 180 gigabytes in the Puerto Rico case, were downloadable while the leak site was live, and the takedown does not reach copies that were taken during that window.
The 110 terabytes now sits with investigators as evidence rather than deleted. Europol says analysts are examining seized devices and tracing the group’s proceeds, including cryptocurrency, and expect that work to surface further victims, attacks and suspects. Affected organisations are directed to law enforcement in their own jurisdiction.
KillSec worked by stealing data rather than only encrypting it, exploiting internet-facing software and badly secured cloud storage. Bitdefender, which supported the operation, advises defenders to “patch internet-facing software first, because that is where the scanning happens”, then audit cloud storage access. That pattern matches recent campaigns against exposed print servers and network switches.
What Happens Next
Three strands remain open. Extradition proceedings continue in the United Kingdom; the German-led investigation continues into other members, including a suspected developer who was identified but not arrested; and the examination of the seized servers continues.
The takedown follows a separate arrest in the ShinyHunters case days earlier, and lands in a year in which Microsoft measured a one-day gap between a flaw becoming public and being weaponised.
Frequently Asked Questions
Is the KillSec Ransomware Group Shut Down?
Its leak site, five domains and five servers are in police hands and three suspects have been arrested. Europol says the investigation into other members continues, so no authority has declared the group permanently gone.
How Much Data Did Police Recover?
At least 110 terabytes, taken from five central servers. Investigators are still analysing it and say it may identify victims who did not know they were attacked.
Who Has Been Charged in the United States?
Fouad Eltibrizi, a Dutch national living in the United Kingdom, alleged to have used the handle Archduke. He was indicted in Puerto Rico on 16 September 2026 and faces a maximum of 10 years if convicted. He has not entered a plea in a US court.
Which Countries Had the Most KillSec Victims?
The United States, with 35% of the organisations publicly claimed on the leak site, followed by India at 17%, according to Group-IB’s count of 274 victims.
What Should an Affected Organisation Do Now?
Contact law enforcement in its own jurisdiction, because the stolen files may now be in police custody. Europol is matching seized data to victims as part of the continuing investigation.




