top of page

Arrest of KillSec member marks breakthrough in international cybercrime probe

Writer: The San Juan Daily Star
The San Juan Daily Star
1 hour ago
2 min read

By THE STAR STAFF


A Dutch citizen accused of helping run a ransomware group that stole and leaked massive amounts of sensitive data from a Puerto Rico company has been arrested in the United Kingdom, federal authorities announced late last week.


Fouad Eltibrizi, known online as Archduke, was taken into custody last Wednesday as part of Operation KillSwitch, an international crackdown targeting the cybercriminal group KillSec. Prosecutors say the organization carried out hundreds of intrusions against companies and institutions across the United States and Europe, stealing confidential information and extorting victims under threat of public disclosure.


According to the U.S. Attorney’s Office in Puerto Rico, Eltibrizi was indicted on Sept. 16 by a federal grand jury on charges including conspiracy to access protected computer systems for profit, causing damage to a protected computer, and transmitting extortion threats to obtain information.


Interim U.S. Attorney Héctor Ramírez Carbó said Eltibrizi and his co‑conspirators “carried out intrusions directed at multiple companies and organizations, stole highly confidential information, and attempted to extort their victims for substantial sums of money.”


Federal prosecutors say that between March and November 2025, KillSec exploited security vulnerabilities to infiltrate victims’ networks and siphon data to servers overseas. The group then posted samples of stolen files on a dark‑web portal and demanded payment to prevent full disclosure.


In March 2025, KillSec claimed responsibility for breaching a company in Puerto Rico, giving it seven days to meet its financial demands. When the company did not respond, the group released roughly 180 gigabytes of data, including patient information. The indictment also cites similar attacks against victims in California, Washington and Louisiana.


Eltibrizi’s arrest was one of several actions taken on Sept. 30, when authorities executed eight residential searches in Spain, Greece, the U.K. and Romania. Three suspects were detained provisionally, and investigators seized digital infrastructure, evidence, and assets tied to the group’s operations.


Law enforcement agencies also took control of KillSec’s dark‑web portal and secured at least 110 terabytes of data to prevent further unauthorized access.


“Cybercrimes will not go unpunished,” said Carlos Goris, special agent in charge of the FBI in San Juan. “These arrests demonstrate the FBI’s unwavering commitment to protecting the American people from cybercriminals.”


Europol, Eurojust, and authorities from Germany, Spain, the U.K., Romania, Greece, Belgium, Switzerland and the Netherlands assisted in the operation.


Eltibrizi remains in the U.K. pending extradition to Puerto Rico. Once transferred, he will appear before a magistrate judge in the U.S. District Court for the District of Puerto Rico.


If convicted, he faces up to 10 years in federal prison. The investigation is being led by the FBI in San Juan, and the case is being prosecuted by Assistant U.S. Attorney Julian Radzinschi.


Federal officials emphasized that the charges are allegations and that Eltibrizi is presumed innocent unless proven guilty beyond a reasonable doubt.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page