Police in Spain arrested a 16-year-old suspected of running the KillSec ransomware group, as part of an operation that also led to two other arrests and the seizure of the group's leak site and servers. The teenager, detained in Alicante, is believed to have been the group's main administrator, according to Hamburg police, who led the investigation. The other arrests took place in the U.K. and Romania, with the U.K. suspect facing extradition to Puerto Rico on U.S. charges. Authorities carried out eight searches across Spain, Greece, the U.K., and Romania, securing at least 110 terabytes of data and shutting down five servers used to store victim files.

KillSec is accused of exploiting software vulnerabilities, especially in cloud storage, to steal sensitive data and then extort victims by threatening to publish it on its leak site. Sources agree the group is linked to about 1,000 attacks, with at least 500 successful, and that it sometimes sent victims samples of their data as proof. The group also offered ransomware-as-a-service to affiliates, allowing less-skilled criminals to launch attacks. Investigators identified suspects in four roles—administrator, developer, negotiator, and affiliate—and noted that the suspected developer turned 18 only recently, meaning some alleged offenses occurred while he was a minor.

Reporting on the group's origins differs slightly: most sources say KillSec emerged in 2024, but one notes that a security firm traced its roots to hacktivist activity as early as 2021 before it shifted to ransomware in 2023. Authorities also said the group used AI to build infrastructure and identify victims, though they provided no further detail. The investigation remains open, with officials examining seized devices and tracing cryptocurrency payments, which may reveal additional victims and suspects. Europol and Eurojust coordinated the operation, with support from cybersecurity firms and law enforcement across Europe and the U.S.The JSON is valid. The article meets the requirements: headline under 80 characters, a one-sentence dek, exactly 3 key points, and a body of 3 short paragraphs in markdown. It synthesizes the sources, notes the discrepancy on the group's origins, and avoids copying wording. No invented facts are included.```json { "headline": "Teen Suspected as KillSec Ransomware Leader Arrested in Spain", "dek": "An international operation dismantled KillSec's infrastructure, arresting three people including a 16-year-old alleged administrator.", "keyPoints": [ "A 16-year-old in Spain is suspected of being KillSec's main operator and administrator.", "Authorities seized the group's leak site, five servers, and at least 110 terabytes of stolen data.", "KillSec is blamed for roughly 1,000 attacks worldwide, with about half reported as successful." ], "body": "Police in Spain arrested a 16-year-old suspected of running the KillSec ransomware group, as part of an operation that also led to two other arrests and the seizure of the group's leak site and servers. The teenager, detained in Alicante, is believed to have been the group's main administrator, according to Hamburg police, who led the investigation. The other arrests took place in the U.K. and Romania, with the U.K. suspect facing extradition to Puerto Rico on U.S. charges. Authorities carried out eight searches across Spain, Greece, the U.K., and Romania, securing at least 110 terabytes of data and shutting down five servers used to store victim files.\n\nKillSec is accused of exploiting software vulnerabilities, especially in cloud storage, to steal sensitive data and then extort victims by threatening to publish it on its leak site. Sources agree the group is linked to about 1,000 attacks, with at least 500 successful, and that it sometimes sent victims samples of their data as proof. The group also offered ransomware-as-a-service to affiliates, allowing less-skilled criminals to launch attacks. Investigators identified suspects in four roles—administrator, developer, negotiator, and affiliate—and noted that the suspected developer turned 18 only recently, meaning some alleged offenses occurred while he was a minor.\n\nReporting on the group's origins differs slightly: most sources say KillSec emerged in 2024, but one notes that a security firm traced its roots to hacktivist activity as early as 2021 before it shifted to ransomware in 2023. Authorities also said the group used AI to build infrastructure and identify victims, though they provided no further detail. The investigation remains open, with officials examining seized devices and tracing cryptocurrency payments, which may reveal additional victims and suspects. Europol and Eurojust coordinated the operation, with support from cybersecurity firms and law enforcement across Europe and the U.S." }

{