Police in Europe allege that a 16-year-old is the leader of a ransomware group called KillSec, which tried to extort hundreds of businesses and organizations.
Europol says the investigation also led to the shutdown of the KillSec site on the dark web, which has since been replaced with a seizure notice.
“The alleged administrator and main operator is 16 years old,” Europol said. Investigators also identified another teenager who turned 18 last month as a KillSec developer. A third suspect was identified as a negotiator for the group, while a fourth acted as an “affiliate,” or a buyer who leased access to KillSec’s ransomware attacks.
According to Europol, “Authorities carried out eight house searches in Spain, Greece, Romania, and the United Kingdom, made three provisional arrests , and seized evidence and assets.”
The investigation underscores a persistent trend of teenagers fueling cybercrime, prompting efforts to steer youngsters away from hacking for profit.
Europol alleges that KillSec, active since 2024, is behind 1,000 suspected cyberattacks, half of which were successful. The group is known for infiltrating companies by exploiting software vulnerabilities or server misconfigurations to breach IT networks and then spreading ransomware to encrypt computers.
The group also uses " double extortion " to steal sensitive information from their targets. “Victims were named on the group’s dark web leak site and threatened with publication of their data unless paid. Where a victim did not pay, the stolen files could be made available for free download,” Europol added.
The authorities began investigating the group early last year, leading to the seizure of five key servers. “Investigators also uncovered how the group used AI to build and operate its ransomware infrastructure and to identify potential victims,” police in Germany said.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
