Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
SAN JUAN, Puerto Rico — A Dutch national accused of participating in the Kill Security ransomware group, known as KillSec, has been arrested in the United Kingdom following a federal indictment in Puerto Rico and a coordinated international law enforcement operation that seized digital infrastructure, evidence and criminal assets across several European countries.
Fouad Eltibrizi, also known as “Archduke,” was arrested September 30, 2026, in the United Kingdom. A federal grand jury in the District of Puerto Rico had returned an indictment against him on September 16.
Eltibrizi, a Dutch citizen who resides in the United Kingdom, is charged in connection with an alleged conspiracy involving unauthorized computer access for financial gain, intentionally causing damage to protected computers and transmitting threats designed to obtain information from protected computers as part of an extortion scheme.
According to federal prosecutors, Eltibrizi and other alleged members of KillSec targeted companies and organizations from at least March through November 2025 by exploiting vulnerabilities and poorly secured access points in computer systems.
Once inside a victim network, KillSec allegedly stole sensitive data, including business records and customer or client information, and transferred the material to infrastructure located outside the victim’s environment.
The group then allegedly used a dark-web leak site as part of its extortion operation. Samples of stolen data would be published publicly, followed by ransom demands threatening the release or sale of the remaining information if victims refused to pay.
Federal investigators say one of those attacks targeted an organization in Puerto Rico in March 2025.
KillSec allegedly announced the breach on its leak site and placed the victim under a seven-day deadline to meet its ransom demand. Samples of stolen patient information were published as evidence that the group had obtained access to the organization’s data.
When the victim did not comply with the demand, KillSec allegedly released approximately 180 gigabytes of stolen information on the dark web.
The indictment also describes alleged intrusions involving victims in California, Washington state and Louisiana, expanding the case beyond Puerto Rico and demonstrating the geographically dispersed nature of the alleged campaign.
The September 30 arrest formed part of a much larger coordinated operation targeting KillSec infrastructure and suspected participants.
Authorities carried out eight residential searches in Spain, Greece, the United Kingdom and Romania. Three provisional arrests were made, and investigators seized digital infrastructure, electronic evidence and assets believed to be connected to criminal activity.
The multinational operation involved law enforcement authorities in the United States and Europe, including Europol and Eurojust, along with agencies in Germany, Spain, the United Kingdom, Romania, Greece and Belgium. Authorities in Switzerland also participated, and investigators credited the Netherlands with providing assistance leading up to the takedown.
Law enforcement took control of KillSec’s leak site during the operation.
Authorities said the seizure secured at least 110 terabytes of data against further unauthorized access. The infrastructure had allegedly been used by KillSec to pressure victims by threatening to release stolen information unless ransom payments were made.
The enforcement effort is part of Operation KillSwitch, an international investigation examining approximately 1,000 suspected cyberattacks attributed to KillSec.
Investigators have so far identified approximately 500 of those suspected attacks as successful. That number could change as authorities continue examining digital evidence and infrastructure seized during the operation.
Data-extortion operations can pressure victims even when systems remain operational because attackers threaten exposure of confidential information, customer records, intellectual property or other sensitive material. Publishing samples of stolen files can serve as proof that access occurred while increasing pressure on an organization to pay before additional information is released.
The KillSec investigation also demonstrates the international infrastructure commonly involved in major cybercrime operations. Attackers can reside in one country, operate servers in another, compromise victims across several jurisdictions and move stolen information through infrastructure distributed around the world.
Acting U.S. Attorney Héctor Ramírez-Carbó said the alleged conspirators targeted multiple companies and organizations, stole sensitive information and attempted to extort their victims for substantial amounts of money.
FBI San Juan Special Agent in Charge Carlos R. Goris said the bureau would continue pursuing cybercriminals regardless of where they operate.
The FBI San Juan Field Office investigated the federal case against Eltibrizi.
Assistant U.S. Attorney Julian N. Radzinschi, the Computer Hacking and Intellectual Property Coordinator for the Financial Fraud and Public Corruption Section, is prosecuting the case.
The Justice Department’s Office of International Affairs and an International Computer Hacking and Intellectual Property prosecutor based in The Hague also supported the international operation.
Eltibrizi remains pending extradition from the United Kingdom. If extradited to the United States, he is expected to make an initial appearance before a federal magistrate judge in the District of Puerto Rico.
If convicted, he faces a maximum penalty of 10 years in federal prison. Any sentence would be determined by a federal district judge after consideration of the U.S. Sentencing Guidelines and other statutory factors.
The charges against Eltibrizi remain allegations. He is presumed innocent unless and until proven guilty beyond a reasonable doubt in court.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



