Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Teen Arrested in Spain for Leading Ransomware Group

Teen Arrested in Spain for Leading Ransomware Group

Posted on October 1, 2026 By CWS

Authorities in Spain have apprehended a 16-year-old suspected of operating the notorious KillSec ransomware syndicate. The group is accused of extracting sensitive information from organizations and demanding ransom under the threat of exposing the stolen data on their leak site.

International Police Efforts

The arrest took place on September 30, alongside two others in different countries. The operation was spearheaded by the Hamburg police, with additional coordination from the Guardia Civil and Mossos d’Esquadra in Spain. Searches were conducted in Alicante, targeting both residential and business locations linked to the suspect.

Additional arrests occurred in the U.K. and Romania, involving individuals in their twenties. The Europol spokesperson confirmed that the U.S. is seeking extradition for the individual detained in the U.K., while Romanian authorities are investigating a 24-year-old for various cybercrime-related offenses.

Operational Details

The investigation revealed that KillSec’s operations were supported by exploiting software weaknesses and unsecured platforms, particularly targeting cloud storage systems. The group managed to infiltrate organizations, acquire confidential data, and leverage it to extort victims.

KillSec’s ransomware operations allegedly began as a hacktivist initiative in 2021, evolving to ransomware activities by 2023. The group’s ransomware, known as KillSecurity 2.0 and 3.0, is designed to encrypt files, yet they have also engaged in extortion without encryption, using stolen data as leverage.

Future Investigations and Implications

Eurojust announced that this international collaboration successfully dismantled the KillSec group, but investigations continue to identify more associates and victims. Authorities are now meticulously analyzing the seized data and equipment to uncover further insights into the group’s operations and financial networks.

The investigation spans approximately 1,000 potential attacks, with around 500 confirmed as successful. This figure may change as more evidence is scrutinized. The collaborative efforts of Europol, Eurojust, and security firms like Bitdefender and Group-IB underscore the complexity and global nature of cybercrime investigations.

As authorities proceed with dismantling the group’s financial and operational networks, the hunt for additional members and possible affiliates remains active. The scope of KillSec’s activities illustrates the ongoing challenges faced by global cybersecurity agencies in combating sophisticated ransomware threats.

The Hacker News Tags:Arrest, Cryptocurrency, cyber investigation, Cybercrime, Cybersecurity, data theft, Eurojust, Europol, FBI, hacktivism, international operation, KillSec, Ransomware, Spain

Post navigation

Previous Post: Warlock Ransomware Targets Infrastructure via SharePoint
Next Post: Police Dismantle KillSec Ransomware, Identify Teen Leader

Related Posts

Google Cloud API Key Exposure Risks Highlighted in New Study Google Cloud API Key Exposure Risks Highlighted in New Study The Hacker News
Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud The Hacker News
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry The Hacker News
Researchers Uncover GPT-5 Jailbreak and Zero-Click AI Agent Attacks Exposing Cloud and IoT Systems Researchers Uncover GPT-5 Jailbreak and Zero-Click AI Agent Attacks Exposing Cloud and IoT Systems The Hacker News
Understanding MFA Prompt Bombing: Risks and Solutions Understanding MFA Prompt Bombing: Risks and Solutions The Hacker News
MikroTik Routers Vulnerable to Unauthenticated SSH Attacks MikroTik Routers Vulnerable to Unauthenticated SSH Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Microsoft 365 for Windows Backdoor
  • Police Dismantle KillSec Ransomware, Identify Teen Leader
  • Teen Arrested in Spain for Leading Ransomware Group
  • Warlock Ransomware Targets Infrastructure via SharePoint
  • Rob Juncker’s Journey from Hacking to Cybersecurity Leadership

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Microsoft 365 for Windows Backdoor
  • Police Dismantle KillSec Ransomware, Identify Teen Leader
  • Teen Arrested in Spain for Leading Ransomware Group
  • Warlock Ransomware Targets Infrastructure via SharePoint
  • Rob Juncker’s Journey from Hacking to Cybersecurity Leadership

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark