Authorities Arrested Suspected KillSec Ransomware Leader

The arrest follows an international investigation into a group responsible for an estimated 500 cyberattacks.

Updated on Oct. 1, 2026 in Cybersecurity

Bold flat-color editorial illustration depicting a single dark server monolith against a cream background, representing international cybercrime disruption.
Federal authorities arrested Dutch national Fouad Eltibrizi in the United Kingdom following a grand jury indictment for his leadership of the KillSec ransomware group. AI Illustration. Upload story photo >

Live Poll

Do you believe law enforcement is doing enough to hold international cybercriminals accountable for data theft?

Federal authorities arrested Dutch national Fouad Eltibrizi in the United Kingdom following a grand jury indictment for his role in the KillSec ransomware group. The operation also involved the seizure of 110 terabytes of data from the group's digital infrastructure.

Why it matters

The takedown disrupts a criminal operation that targeted victims globally by exfiltrating sensitive data and threatening its release for financial extortion. Law enforcement efforts have now moved to analyzing the seized data to better understand the full scope of the group's activities.

Operation KillSwitch led to the seizure of 110 terabytes of data from the group's leak site, significantly outpacing the 180 gigabytes the group previously released publicly. The investigation spanned 8 residential searches across Spain, Greece, the United Kingdom, and Romania.

The players

Fouad Eltibrizi

A Dutch national indicted for his leadership role within the KillSec ransomware collective.

KillSec

A criminal ransomware group that operated from March to November 2025, specializing in data exfiltration and extortion.

The details

KillSec gained unauthorized access to victim networks by targeting vulnerabilities and poorly secured access points. Once inside, the group exfiltrated sensitive files to offshore servers before hosting them on dark web leak sites to extort victims. The operation resulted in three provisional arrests and the discovery of 500 successful breach events during the group's active period.

Timeline

  1. March 2025 - November 2025: KillSec conducted global ransomware and exfiltration campaigns.

  2. September 16, 2026: A federal grand jury returned an indictment against Fouad Eltibrizi.

  3. September 30, 2026: Law enforcement arrested Fouad Eltibrizi in the United Kingdom.

The Tech Race

This arrest represents a major tactical shift in the ongoing Operation KillSwitch initiative to dismantle global ransomware syndicates. Investigators are currently prioritizing the analysis of 110 terabytes of seized evidence to determine the extent of the group's compromised data caches.

Victims and organizations previously targeted by this group should monitor for further disclosures as investigators review the 110 terabytes of seized material. Those concerned about institutional security should consult the FBI internet crime complaint center for guidance on reporting and mitigation.

The takeaway

This case highlights the persistence required to map criminal digital infrastructure across international borders. Observers should track upcoming extradition hearings in Puerto Rico, which will clarify the jurisdictional timeline for the trial.

What happens next

Fouad Eltibrizi is expected to face an initial appearance in a Puerto Rico court following the completion of extradition proceedings.

Further reading

For more on evolving threat landscapes, visit our Cybersecurity section.

More information

For resources on cybercrime prevention and reporting, visit the FBI internet crime complaint center.

Source note: This article includes information reported by The United States Department of Justice.

Live Poll

Do you believe law enforcement is doing enough to hold international cybercriminals accountable for data theft?