Update on Monday, Feb. 26: Following the coordinated takedown of LockBit’s infrastructure on Monday, the group launched a new dark web leaks site on Saturday.
In a statement, the group’s leader, identified as “LockBitSupp,” said the group will continue to operate despite being in the crosshairs of law enforcement.
LockBitSupp admitted “personal negligence and irresponsibility” in failing to update LockBit’s PHP. This ultimately allowed law enforcement to access the group’s servers by capitalizing on a known vulnerability (CVE-2023-3824). The group plans to prevent future takedowns by decentralizing their infrastructure.
Law enforcement has stated that they know the identity of LockBitSupp, their whereabouts, and their net worth, but LockBitSupp seems to be undeterred.
In a joint international operation, law enforcement has dealt a crippling blow to the notorious LockBit group, responsible for “the world’s most prolific and harmful ransomware,” Europol announced on Tuesday.
“Operation Cronos,” which followed a complex investigation by the UK’s National Crime Agency (NCA), led to the seizure of critical infrastructure used by the ransomware syndicate, including public-facing websites and servers. Two members of LockBit have also been indicted, a press release from the U.S. Department of Justice (DoJ) said.
Known for its ransomware-as-a-service (RaaS) operation, the LockBit gang encrypted victims’ data and demanded huge amounts in ransom payments, sometimes using a triple extortion method that involved threats of data leaks and Distributed Denial-of-Service (DDoS) attacks to further pressure victims.
“Over the past few days, the Justice Department has worked together with our partners in the United Kingdom and around the world to take down LockBit, one of the most prolific ransomware variants in the world.” U.S. Attorney General Merrick Garland said on Tuesday.
“LockBit is widely recognized as the world’s most prolific and harmful ransomware, causing billions of euros worth of damage,” Europol noted.
Law enforcement now possesses extensive data from the investigation to dismantle the group’s network and target its key members and assets. Also, free decryption tools are now available for victims of LockBit ransomware.
The Takedown: A Coordinated International Effort
In its press release, Europol highlighted the scope of the operation, involving law enforcement from 10 countries.
The operation resulted in the takedown of 34 cybercriminal servers across Europe, Australia, and North America. Law enforcement also froze over 200 cryptocurrency accounts linked to the group and seized 14,000 malicious accounts.
Besides two major LockBit actors arrested in Poland and Ukraine, French and U.S. judicial authorities have also issued warrants and indictments for other suspects.
LockBit emerged late in 2019, initially under the name “ABCD” ransomware. By 2022, it had become “the most deployed ransomware variant in the world,” Europol said. LockBit’s core team developed malware and managed its site, while affiliates executed attacks globally, retaining about three-quarters of the ransom collected.
The LockBit gang “targeted over 2,000 victims, received more than $120 million in ransom payments, and made ransom demands totaling hundreds of millions of dollars,” the DoJ said.
In 2022, the group added California’s Department of Finance to its list of victims, claiming the theft of sensitive data, including databases, financial files, and court proceedings.
Also, in 2022, a report by the European Union Agency for Cybersecurity (ENISA) mentioned LockBit as one of the most prolific ransomware groups in the world.
Free Decryption Tools Are Now Available
Besides taking down LockBit’s infrastructure, law enforcement also obtained the encryption keys used by the group and created free decryption tools that are now available on the “No More Ransom” initiative’s portal.
Europol and the DoJ stressed the importance of comprehensive cybersecurity measures and public cooperation. Europol has compiled a directory of websites for reporting cybercrime across EU member states. LockBit victims in the U.S. are advised to reach out to the FBI.
While LockBit has been taken down, many ransomware groups still exist. To avoid falling victim to ransomware attacks, we recommend creating a secure backup of your data, implementing multi-factor authentication, and educating your employees about phishing and other common cyber threats.
Here are the U.S. Attorney General’s remarks on the operation to take down the LockBit ransomware group:
For more news, follow us on X (Twitter), Threads, and Mastodon!

