# Police say a 16-year-old ran KillSec, a gang tied to 1,000 ransomware attacks

> Europe's Operation KillSwitch seized KillSec's leak site, five core servers and 110TB of stolen data. Europol says the alleged administrator is 16.

- Published: 2026-10-09
- Topic: [Security](https://futuretechnologyhq.com/topic/security/)
- URL: https://futuretechnologyhq.com/article/killsec-ransomware-takedown-16-year-old/
- Publisher: [Future Technology](https://futuretechnologyhq.com/), free to read. Quote as "Future Technology" with a link to the article.

## Key points

- Police seized KillSec's dark web leak site and took control of five core servers holding at least 110TB of data.
- Europol says a 16-year-old Romanian national arrested in Alicante, Spain, was the group's administrator.
- Two people in their twenties were arrested in the UK and Romania; a fourth suspect has been identified, and the US has indicted a Dutch national.
- KillSec is linked to roughly 1,000 suspected attacks worldwide.

## Article

The alleged boss of a ransomware operation linked to around 1,000 attacks worldwide is 16 years old.

That is the headline from Operation KillSwitch, a European police action against the KillSec ransomware group announced at the start of October. Run by police and prosecutors in Hamburg with help from ten countries, Europol and Eurojust, it took KillSec's infrastructure offline and put four people in the frame.

## What police seized

According to [SecurityWeek](https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/), officers took over KillSec's dark web leak site, the page where gangs publish stolen files to pressure victims into paying. They also gained control of five core servers, including the systems the group used to run operations and store stolen data, and blocked further access to at least 110TB of it. KillSec's domains now show a law enforcement seizure notice.

That 110TB matters. It is victims' data that will no longer be dumped publicly, and it gives investigators a map of who was hit and when.

## Who was arrested

Europol describes a 16-year-old as KillSec's administrator and main operator. Reuters reported the suspect is a Romanian national arrested in Alicante, Spain. Two other people in their twenties were arrested, one in Britain and one in Romania. A fourth suspect, a developer who turned 18 in August, has been identified but not arrested. Separately, the US Justice Department has indicted a Dutch national over his alleged role, and he is awaiting extradition.

All of these are allegations. The investigation is ongoing, and Europol has said the attack count may change as seized evidence is examined. Some reports put confirmed successful attacks at around 500.

## Why a teenager can run a ransomware gang

Ransomware stopped being an elite skill years ago. Groups like KillSec run as a service: encryptors, leak sites, negotiation scripts and affiliate programmes come off the shelf, and the "operator" is often closer to a platform manager than a master hacker. Initial access is bought or phished. Sophos's latest ransomware research found phishing and stolen credentials now outrank exploited vulnerabilities as the main way in.

So the age of the alleged admin is less shocking than it first sounds. What it should change is how we picture the threat. The person encrypting a hospital's file shares might be a bored teenager with a Telegram account and a rented toolkit.

## Does a takedown actually help?

Short term, yes. Seizing servers and leak sites breaks a gang's ability to extort, and it rattles affiliates who now wonder what police found about them. Long term, the pattern from previous takedowns is that affiliates drift to the next brand within weeks.

The useful bit for defenders is the same as ever. The way in for most of these attacks is a reused password, a phished login or an unpatched edge device. Our [zero-day network device checklist](/article/zero-day-network-device-checklist/) covers the edge kit that keeps getting hit, and multi-factor authentication on every remote access route remains the cheapest ransomware insurance there is.

## Sources

- [SecurityWeek](https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/)
- [The Hacker News](https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html)
- [Dark Reading](https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old)
