Police in Spain arrest a 16-year-old suspected of running the KillSec ransomware group, as part of an international operation. Multiple outlets report that authorities seize the group’s data leak site and related servers, and that the action involves three arrests in total, including the teenager identified as the alleged administrator.
Eurojust says KillSec has been active since 2024 and is linked to nearly 1,000 attacks worldwide. Investigators describe tactics in which the group gains access by exploiting poorly secured systems, with emphasis on access connected to cloud storage. Once inside, outlets report that KillSec steals data, copies it to its own infrastructure, and threatens victims with publication of the stolen material unless they pay.
Coverage aligns on the basic facts of the arrest, the seizure of the leak infrastructure, and the role attributed to the 16-year-old. Outlets differ mainly in framing—some emphasize the law-enforcement operation and infrastructure takedown, while others focus more on Eurojust’s assessment of KillSec’s activity level and reported targeting methods.