Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members

A major blow has been dealt to a notorious data extortion group, with authorities arresting three alleged members and seizing their infrastructure. The operation, dubbed “Operation KillSwitch,” was a globally coordinated effort involving 10 countries and private cybersecurity companies.

At the center of this operation is KillSec, a group that made headlines for its brazen cyberattacks on over 500 organizations since 2024. According to investigators, the alleged leader of the group is just 16 years old, with one of their members, Fouad Eltibrizi, arrested in the UK and awaiting extradition to the US.

Eltibrizi, a Dutch national, was accused of acting as a negotiator for the group and was indicted last month in Puerto Rico. If convicted, he faces up to 10 years in prison for unauthorized computer access conspiracy. The operation also targeted a suspected developer involved in KillSec, who committed multiple crimes before turning 18 in August.

The seizure of KillSec’s data-leak site and over 110 terabytes of stolen data is a significant blow to the group’s operations. Law enforcement officials say that their efforts have imposed “serious cost” on the group, degrading its core capabilities and limiting its ability to rebuild or launch future attacks. The operation also highlighted the growing threat of ransomware, which continues to pose a significant risk to organizations across industries.

The victims of KillSec’s extortion demands include several high-profile targets, including Instituto de Ojos, US BioTek Laboratories, and Accelerated Academy. Prosecutors accuse Eltibrizi and his co-conspirators of stealing sensitive information and attempting to extort their victims for substantial sums of money.

The takeaway from this operation is clear: law enforcement agencies are taking a proactive approach to targeting cybercrime groups like KillSec. This coordinated effort demonstrates the importance of international cooperation in addressing the global threat of ransomware. As organizations continue to face the risk of data breaches and extortion demands, they would do well to prioritize cybersecurity measures and stay vigilant against emerging threats.

By understanding how these types of operations work, individuals and organizations can take steps to protect themselves from similar cyberattacks. This includes keeping software up-to-date, implementing robust security protocols, and staying informed about emerging threats. By working together, we can build a safer digital landscape for all.


Source: CyberScoop — 2026-10-01