Dutch National Indicted and Arrested for Unauthorized Computer Access Conspiracy
SAN JUAN, Puerto Rico / Thursday, October 1, 2026 – On September 16, 2026, a federal grand jury in the District of Puerto Rico returned an indictment charging a Dutch national who resides in the United Kingdom with conspiracy to intentionally access a computer without authorization for financial gain, intentionally causing damage without authorization to a protected computer, and intentionally transmitting a threat to obtain information from a protected computer without authorization with the intent to extort. The Dutch national named in the indictment, Fouad Eltibrizi (a/k/a Archduke), was arrested on September 30, 2026, in the United Kingdom.
According to court documents, from at least March 2025 to November 2025, Eltibrizi and co-conspirators (forming what is known as the Kill Security Ransomware Group (“KillSec”)) targeted and gained access to victims’ computers through the exploitation of different vulnerabilities. KillSec would then exfiltrate (steal) the victims’ data (often sensitive business or client information) and store it on an exfiltration server abroad. A portion of the data would be published on the dark web (on KillSec’s leak site) and then the victims would be contacted with a ransom demand which, if not complied with, would result in the full publication or sale of the data on the dark web.
In March 2025, KillSec posted on their leak site that they had breached a victim in Puerto Rico. KillSec gave the company a seven-day countdown to meet their ransom demands. The post on the leak site contained samples of stolen patient data. The victim did not respond to the demands made by KillSec, which then released approximately 180 gigabytes of stolen victim data on the dark web. The indictment also describes similar breaches in other locations on the mainland of the United States, such as California, Washington State, and Louisiana.
“The defendant and his co-conspirators carried out targeted intrusions against multiple companies and organizations, stealing highly sensitive information and attempting to extort their victims for substantial sums of money,” said Héctor Ramírez‑Carbó, Acting United States Attorney for the District of Puerto Rico. “Ransomware remains a serious and evolving threat to all sectors of our economy, from critical infrastructure to small businesses. The Justice Department and the U.S. Attorney’s Office for the District of Puerto Rico will continue to work closely with our international partners to identify, disrupt, and prosecute anyone—anywhere—who seeks to harm U.S. and Puerto Rico businesses and consumers through these attacks.”
“Cyber-crimes will not go unpunished. These arrests are an example of the FBI’s unwavering commitment to protect the American people against cyber criminals,” said Carlos R. Goris, Special Agent in Charge of FBI San Juan. “We will continue to diligently locate and bring to justice those who exploit our digital environments, no matter where they operate. We encourage citizens to report any cyber incidents to the FBI through IC3.gov or by contacting their local field office.”
In addition, on September 30, 2026, as part of this coordinated international operation, authorities in the United States and Europe carried out eight residential searches in Spain, Greece, the United Kingdom, and Romania, made three provisional arrests, and seized digital infrastructure, evidence, and criminal assets. The operation was conducted in close cooperation with Europol, Eurojust, Germany (LKA541), Spain (Guardia Civil and Mossos d’Esquadra), the United Kingdom (Eastern Region Special Operations Unit), Romania (Central Cybercrime Unit), Greece (Hellenic Police), Belgium (Federal Police), as well as authorities in Switzerland (Federal Office of Police). The Netherlands also provided valuable assistance leading up to the takedown.
Law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorized access. As explained above, the cybercrime group used the leak site to threaten organizations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an investigation into around 1,000 suspected attacks worldwide. KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organizations’ systems. Around 500 of the suspected attacks (worldwide) have so far been identified as having succeeded. This figure may change as investigators examine the evidence seized during Operation KillSwitch.
Eltibrizi is charged with unauthorized computer access conspiracy and is pending extradition from the United Kingdom. Once extradited, he will have an initial appearance in front of a magistrate judge of the U.S. District Court for the District of Puerto Rico. If convicted, he faces a maximum penalty of 10 years in prison. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.
Assistant U.S. Attorney Julian N. Radzinschi, the Computer Hacking and Intellectual Property (CHIP) Coordinator of the Financial Fraud & Public Corruption Section is prosecuting the case against Eltibrizi. The Federal Bureau of Investigation in San Juan, Puerto Rico investigated the case.
The Justice Department’s Office of International Affairs and the International Computer Hacking and Intellectual Property (ICHIP) prosecutor based in The Hague provided crucial support to this operation.
The Justice Department is providing cybercrime technical assistance to foreign law enforcement, prosecutorial, and judicial partners in other countries through the ICHIP program. Learn more about the Criminal Division’s ICHIP Program, jointly administered by the Criminal Division’s Office of Overseas Prosecutorial Development, Assistance and Training (OPDAT) and the Computer Crime and Intellectual Property Section through partnership between the U.S. Department of State’s Bureau of International Narcotics and Law Enforcement Affairs, here.
An indictment is merely an allegation and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.
###
Source: U.S. Attorney's Office, District of Puerto Rico












