Dutch hacker charged in international ransomware case
Dutch suspect arrested in the United Kingdom during international operation against KillSec.
A Dutch man has been arrested in the United Kingdom on suspicion of involvement with the ransomware group KillSec. US prosecutors want to extradite him to Puerto Rico, where he is accused of unauthorised access to computers and extortion.
The suspect, Fouad E., was arrested in the United Kingdom on 30 September. A grand jury in Puerto Rico had previously indicted him for conspiring to access computers without authorisation, damage protected computers and send threats with the aim of obtaining data or extorting money.
According to the indictment, E. was involved in KillSec’s activities between March and November 2025. The group is alleged to have exploited vulnerabilities in computer systems and poorly secured access points. Data were then copied and victims put under pressure through threats to publish the information.
The US Department of Justice says it is investigating approximately one thousand attacks worldwide linked to KillSec. In around five hundred cases, access to systems is said to have been obtained. These figures are preliminary investigative figures and may still change as seized equipment is examined.
Police and judicial authorities from, among others, Germany, Spain, the United Kingdom, Belgium, Romania and Greece took part in the international operation. Europol reports that three suspects have been provisionally arrested and that eight homes were searched. KillSec’s leak website was also taken over.
According to the authorities, at least 110 terabytes of data were stored on that infrastructure. The seizure is intended to prevent the group from extorting victims again by threatening to publish files. Investigators are also trying to map the financial flows and cryptocurrencies linked to the group.
E. has not been convicted. He is in the United Kingdom awaiting extradition proceedings. According to the US indictment, he could receive a maximum prison sentence of ten years if convicted; a US judge will decide that only later.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The key facts can be found in official publications by the US Department of Justice, Europol and the British police. Allegations have consistently been presented as suspicions.
- confirmed The Dutch suspect was arrested in the United Kingdom on 30 September. — Mentioned in the publication by the US Department of Justice. source
- confirmed The suspect is accused in Puerto Rico of unauthorised access to computers and extortion. — The indictment and the stated descriptions of the offences appear in the US announcement. source
- confirmed KillSec is linked to approximately one thousand suspected attacks. — Europol mentions approximately one thousand suspected attacks and stresses that the investigation is ongoing. source
- confirmed Authorities took control of at least 110 terabytes of data. — This figure is mentioned by Europol and the US Department of Justice. source
Editor's note
The arrest, indictment and international operation have been confirmed. The suspect’s role and the scale of the attacks are allegations and preliminary investigative figures.Sources
- Dutch National Indicted and Arrested for Unauthorized Computer Access Conspiracy — U.S. Department of Justice
- Teenager suspected of leading KillSec ransomware group — Europol
- ERSOU supports international takedown of global ransomware network — Eastern Region Special Operations Unit
More on this in Dutch media
- de Volkskrant — „ransomware killsec”
- NOS — „ransomware killsec”
- Het Parool — „ransomware killsec”