The authorities in Europe and the United States said on Thursday that they had seized the infrastructure of the KillSec ransomware group and arrested three people, identifying a 16-year-old as its suspected main operator.

The German-led effort, called Operation KillSwitch, replaced the group’s dark-web leak site with a police seizure notice and secured at least 110 terabytes of stolen data, according to Europol and national police forces. KillSec has been linked to around 1,000 suspected attacks worldwide, the police said.

The official accounts left much unclear. Europol described the 16-year-old as “the group’s suspected main operator” but did not say whether he had been arrested. The Spanish police separately announced the arrest of a “minor,” a Romanian national living in Spain, without publicly connecting him to the teenager Europol described.

The only suspect named publicly is Fouad Eltibrizi, a Dutch national arrested by the British police. The U.S. Department of Justice said it had charged him with cybercrimes in the United States and Puerto Rico and was seeking his extradition. Europol told The Register that Mr. Eltibrizi was suspected of being one of KillSec’s negotiators.

The Romanian police said a 24-year-old had helped establish KillSec in October 2023 — other authorities date the group’s formation to 2024 — and officials confirmed to The Register that a Romanian man in his twenties had been arrested there as a suspected affiliate. Europol also identified a suspected developer who turned 18 in August and was a minor when some of the alleged offenses were committed. The Spanish police said a woman remained under investigation but had not been arrested.

The coordinated raids took place on Sept. 30, after investigations that began in early 2025. Ten police agencies from Europe and the United States took part, searching eight properties across Greece, Romania, Spain and Britain. The Spanish police raided a home and an office in an Alicante hotel; the Romanian police searched four homes. Neither Greece nor Britain has described its role.

Over the course of the investigation, officers took control of five central servers the group used to manage its activities and store victims’ data. The authorities said the stolen information would be held as part of the inquiry and, where appropriate, destroyed through legally authorized processes to prevent further misuse.

KillSec used double extortion, encrypting victims’ systems and threatening to publish stolen data unless they paid. Group-IB, one of two security firms that supported the investigation alongside Bitdefender, recently put the group, also called Kill Security and k1llsec, in its 2025 top 10 rankings of ransomware operations active in Asia and the Pacific, Latin America and the Middle East. Its researchers said KillSec most often preyed on financial services and health care organizations but also hit government bodies and large companies, and that it offered stolen data for sale at prices from $5,000 to $500,000. The group began with a Windows encryptor and later added a version that attacks VMware ESXi hosts, deleting data, shutting down virtual machines and wiping recovery points.

“Servers can be replaced in weeks; the people who build the platform and approve every attack cannot,” Dmitry Volkov, Group-IB’s chief executive, said. “Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end.”

The takedown follows earlier multinational operations, including Operation Cronos, which went after the LockBit ransomware group, and Operation Endgame, which targeted malware networks and the infrastructure behind them.

Investigators are now examining the seized devices and data to identify victims, attacks and other suspects, and to trace the group’s criminal proceeds.