16-year-old allegedly led ransomware gang behind hundreds of attacks

When you picture the person running an international ransomware operation, a 16-year-old probably does not come to mind. Yet investigators say a teenager was the suspected main operator behind KillSec, a cybercrime group linked to around 1,000 suspected attacks worldwide. About 500 of those attacks have so far been identified as successful.
Now, an international law enforcement operation has taken KillSec's leak site and key servers offline. Authorities also secured at least 110 terabytes of stolen data that could have been exposed or used to pressure victims. The takedown offers a remarkable look at how accessible cybercrime has become. More importantly, it shows how attackers continue to find their way into poorly protected systems and turn stolen files into leverage. What investigators uncovered about KillSec shows how the group operated, how AI reportedly played a role and what you can do to make ransomware attacks harder to pull off.
Join us for a free CyberGuy LIVE class.
Kurt "CyberGuy" Knutsson shares practical ways to stay safer, smarter and more confident with technology. Explore classes on stopping spam, phone security, financial protection and using AI to get better health care. Each class is free, easy to follow and comes with a free printable checklist.
See the classes and register at CyberGuyLive.com
FBI STRIKES BACK AT HACKING GROUP WITH OVERSEAS ARREST OF ALLEGED LEADER

Guardia Civil, Mossos d’Esquadra and FBI personnel took part in the coordinated international investigation targeting KillSec. (Europol)
Police take down KillSec ransomware operation
The crackdown, known as Operation KillSwitch, took place on Sept. 30. Authorities from the United States and several European countries participated in the investigation. Europol and Eurojust also helped coordinate the effort.
Police carried out eight searches in Greece, Romania, Spain and the United Kingdom. Three suspects were provisionally arrested. Investigators also took control of five central servers connected with KillSec's operation. One of the biggest moves involved KillSec's dark web leak site. The group allegedly used the site to name victims and threaten to publish stolen files unless they paid. Authorities have now taken control of that infrastructure.
A 16-year-old is suspected of running the operation
Perhaps the most startling part of this case involves the age of the suspected operator. Investigators identified a 16-year-old as KillSec's suspected administrator and main operator. Another suspected member, described as a developer, turned 18 in August and was reportedly still a minor when some of the alleged crimes occurred.
Investigators also identified people suspected of serving as a negotiator and an affiliate. Authorities say the investigation remains ongoing. Age aside, the alleged operation was anything but small. KillSec has been active since around 2024. According to Europol, the group exploited software vulnerabilities and poorly secured access points to break into organizations. Attackers then copied sensitive internal files to systems they controlled.
How KillSec allegedly pressured its victims
Once attackers had the files, the pressure began. KillSec allegedly listed organizations on its dark web site and threatened to publish their stolen data if they refused to pay. In some cases, the stolen files were reportedly made available after victims declined to hand over a ransom.
Europol says the group received substantial ransom payments from some attacks. That strategy shows how ransomware has changed over the years. Criminals do not always need to lock every file on a computer to create leverage. Stolen information itself can become the threat. If an attacker gets employee records, customer information or confidential business documents, the victim can face serious consequences even when backups work perfectly.
KillSec reportedly used AI to support its attacks
Investigators also uncovered another detail that caught my attention. Europol says members of KillSec used artificial intelligence to help build and maintain ransomware infrastructure and identify potential victims.
That does not mean AI carried out the entire attack by itself. However, it shows how cybercriminals can use the same technology everyone else is experimenting with to speed up parts of their work. A teenager may no longer need to build every piece of an attack from scratch. Tools, stolen credentials, vulnerable systems and AI assistance can lower some of the barriers that once required deeper technical expertise. That should make all of us pay closer attention to basic security habits.
FBI'S FIRST CYBER FUGITIVE ON TEN MOST WANTED LIST RETURNS TO US AFTER CAPTURE IN VENEZUELA

Operation KillSwitch brought together international law enforcement agencies to seize KillSec’s servers, leak site and stolen data. (Felix Zahn/Photothek via Getty Images)
What happens to KillSec now?
The investigation remains active. Authorities are examining computers, servers and other seized evidence. Investigators are also following cryptocurrency and other alleged criminal proceeds.
That evidence could uncover additional attacks, victims or people connected with the operation. Europol also cautions that the current number of successful attacks may change as investigators continue reviewing what they seized.
For now, KillSec's core infrastructure has taken a significant hit. However, ransomware groups have a long history of disappearing, reorganizing and resurfacing under different names. That makes prevention especially important even after a major takedown.
Why this ransomware takedown should get your attention
KillSec appears to have focused mainly on organizations rather than individual home computer users. Still, the methods behind the attacks offer lessons that apply to everyone. Europol says the group exploited software vulnerabilities and poorly secured access points. Those are the same types of weaknesses security experts have warned about for years.
An old router, forgotten account or unpatched computer can give attackers an opening. A compromised password can do the same. Once criminals gain access, they can steal information before anyone realizes something has gone wrong. So, while you probably cannot stop an international ransomware gang yourself, you can make your devices and accounts harder to break into.
7 ways to reduce your ransomware risk
A few simple security habits can close some of the openings attackers commonly look for.
1) Install software and security updates
Do not keep putting off updates on your computer, phone, browser and other connected devices. Security updates often fix vulnerabilities attackers already know how to exploit. CISA recommends regularly patching operating systems and software, especially on devices exposed to the internet. Turn on automatic updates when that option is available.
2) Use strong, unique passwords
Using the same password across several accounts gives an attacker more opportunities if one login is exposed. Create a different password for each important account. A password manager can help generate and store strong credentials without forcing you to remember every one. You should also check whether passwords you already use have appeared in known data leaks. Your iPhone or Android phone may already have tools that can flag compromised passwords.
HACKER CLAIMS 7.49M CUSTOMER RECORDS STOLEN FROM AMERICAN UTILITY COMPANY
Law enforcement collected laptops, phones and storage devices as evidence during the Operation KillSwitch takedown. (Europol)
3) Turn on two-factor authentication
A stolen password becomes much less useful when your account requires another form of verification. Enable two-factor (2FA) or multifactor authentication on your email, financial accounts, cloud storage and other important services. When available, consider phishing-resistant options such as passkeys or security keys instead of relying only on text-message codes.
4) Keep an offline backup of important files
Ransomware becomes far more painful when your only copy of a photo, document or financial record lives on the compromised device. Back up important files regularly. Consider keeping one copy in the cloud and another on an external drive. If you use an external drive, disconnect it when the backup finishes. Some ransomware can also target drives that remain connected to an infected computer.
5) Be careful with unexpected downloads and attachments
A convincing email, fake update warning or malicious attachment can provide an attacker with a way into your computer. Avoid opening files you were not expecting. Instead of clicking an urgent update prompt from a webpage or email, open the app itself and check for updates there. If something feels unusual, stop before entering a password or running a downloaded file.
6) Use security software on your devices
Strong antivirus software can help detect ransomware, malicious downloads and other threats before they spread. Keep the protection updated and run a full scan if your computer suddenly behaves differently, redirects your browser or shows unfamiliar programs. Security software will never replace safe habits. However, it can provide another opportunity to catch a threat before the damage grows. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
7) Know what to do if ransomware hits
If you see a ransom message or suddenly lose access to important files, disconnect the affected device from your network. Avoid plugging backup drives into the compromised computer until you know the device is clean. The FBI says it does not support paying ransomware demands because payment does not guarantee that your information will be restored. The agency also encourages victims to report ransomware incidents. You can file a report with the FBI's Internet Crime Complaint Center at IC3.gov or contact your local FBI field office. The FBI specifically directs ransomware victims to use those channels. One more thing: type IC3.gov directly into your browser. The FBI has warned that scammers have created fake IC3 websites, including lookalike pages that may appear in sponsored search results.
Kurt's key takeaways
The age of KillSec's suspected operator is going to grab the headlines, and I understand why. Sixteen is incredibly young to be accused of running an operation connected with this many attacks. What stays with me, though, is how familiar the alleged entry points sound. Vulnerable software and poorly protected access can still give criminals exactly the opening they need. That is why I keep coming back to the basics. Update your devices. Protect important accounts with more than a password. Keep a backup that an attacker cannot easily reach. You may never know which security step stopped an attack. That is far better than discovering which one you skipped after your files are already gone.
If a 16-year-old can allegedly help run a ransomware operation tied to hundreds of successful attacks, do you think powerful hacking tools and AI are making cybercrime too easy to enter at a young age? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Newsletter
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com - trusted by millions who watch CyberGuy on TV daily.
- Plus, you'll get instant access to my Ultimate Scam Survival Guide free when you join.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Copyright 2026 CyberGuy.com. All rights reserved.
Kurt "CyberGuy" Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on "FOX & Friends." Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.