ThreatPaper
Weak Evidence

Eltibrizi was indicted on charges incl. computer damage and threats

Assessment

GovInfoSecurity reported Eltibrizi was indicted "on charges including conspiracy to access computers without authorization, damaging a protected computer and transmitting threats with intent to extort", which reads as several charges. The court docket for United States v. Eltibrizi, 3:26-cr-00383 (D.P.R.), records the indictment as count 1 only, with the pending count "18:371 CONSPIRACY", and DOJ's own release says "Eltibrizi is charged with unauthorized computer access conspiracy". The damage and threat offences are objects of that one conspiracy count, not separate charges. DOJ's first paragraph is ambiguously worded, which is likely where the reading came from.

Where this claim appeared

GovInfoSecurity · 2026-10-01

https://www.govinfosecurity.com/spain-arrests-teen-suspected-running-killsec-ransomware-a-33002

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Operation KillSwitch: KillSec ransomware takedown, a 16-year-old suspect and a US indictment

Think this assessment is wrong? Report an error.