Today we’re announcing Operation KillSwitch, a joint sequenced operation led by
@FBISanJuan targeting the Kill Security Ransomware Group (“KillSec”). Authorities in the U.S. and Europe took control of KillSec’s leak site, securing at least 110 terabytes of data against further criminal access, and arrested Dutch national Fouad Eltibrizi, an alleged KillSec member who is now pending extradition to the United States.
As part of this global operation,
@FBI and its partners made two additional arrests and carried out eight residential searches across Europe, seizing digital infrastructure, evidence, and criminal assets.
KillSec conducts targeted intrusions worldwide, exploiting vulnerabilities to steal sensitive data and extort victims. The group is linked to 1,000 suspected cyberattacks across the globe.
The arrests and other actions have imposed serious cost and degraded the adversary’s core capabilities. We have undermined the group’s ability to rebuild, limited their operational reach, and reduced the likelihood of future attacks.
The operation was conducted in close cooperation with Europol, Eurojust, Germany (LKA541), Spain (Guardia Civil and Mossos d’Esquadra), the United Kingdom (Eastern Region Special Operations Unit), Romania (Central Cybercrime Unit), Greece (Hellenic Police), Belgium (Federal Police), as well as authorities in Switzerland (Federal Office of Police). The Netherlands also provided valuable assistance leading up to the takedown.
justice.gov/usao-pr/pr/dutch…
ALT Red and black splash page announcing Operation KillSwitch and seizures by FBI and international law enforcement agencies.