Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LockBit-associated administrators claimed a comeback after a website reappeared on February 24, 2024, four days after law enforcement announced Operation Cronos. That showed the site was visible again; it did not establish that LockBit’s ransomware service was fully restored or available to affiliates. The U.K. National Crime Agency (NCA) said the operation remained “completely compromised.” Later reporting documented renewed LockBit attacks in September 2025, but the available sources do not establish the group’s status in October 2026.

What did the February 2024 comeback claim actually show?

On February 24, a LockBit-associated site appeared online, listing alleged victims and threatening to publish data. LockBit administrators said they were back. But a website’s return is not the same as restoring the criminal operation behind it: the site’s appearance did not confirm that affiliates could again use the platform to conduct attacks.

In a February 26 report, CyberScoop said the extent of any restored service was unclear. The NCA told the outlet that it had compromised the entire operation and that LockBit remained “completely compromised.” The agency expected an attempt to regroup and said it had intelligence that would support further disruption. Emsisoft threat analyst Brett Callow also expressed skepticism about LockBit’s claims; that was his contemporaneous assessment, not proof of the group’s technical condition.

What did Operation Cronos disrupt?

On February 20, 2024, the NCA, the U.S. Department of Justice (DOJ), the FBI and international partners announced Operation Cronos. Authorities seized public-facing websites and servers used by LockBit administrators. The DOJ said the action disrupted attackers’ ability to encrypt networks and extort victims; the FBI described a disruption of both front-end and back-end infrastructure. The NCA said it took control of the primary administration environment, the affiliate-facing platform and the public leak site, and gathered source code and intelligence. See the NCA’s Operation Cronos information page, the DOJ announcement and the FBI statement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why the affiliate platform mattered

DOJ described LockBit as ransomware-as-a-service. Administrators developed the ransomware and operated a control panel; affiliates used the service to access vulnerable systems and deploy malware that encrypted and stole data. Extortion could include demands for payment to decrypt files or to prevent stolen information from being published. Seizing the administrators’ systems and the affiliate platform therefore targeted more than the public-facing leak site.

What authorities said they learned

The DOJ’s February 20, 2024 release said LockBit had targeted more than 2,000 victims and received more than $120 million in ransom payments; it also said ransom demands totaled at least hundreds of millions of dollars. These are DOJ figures from that release, not current, independently audited totals. The NCA says information obtained during the operation identified a network of 194 affiliates. The NCA page also stated that 1,000 decryption keys were available to victims; that statement is not a guarantee that a key is currently available for any particular incident.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Did LockBit become active again?

There is evidence of later attacks, but it does not answer whether LockBit is active today. Check Point Research reported that it identified 12 organizations targeted in September 2025, half by LockBit 5.0. The reported attacks spanned Windows, Linux and ESXi systems in Europe, the Americas and Asia. Check Point Research’s findings were also summarized by CERT-EU.

Those observations show renewed attack activity in September 2025. They do not establish the group’s exact operational status on October 8, 2026, or prove that the service had been continuously available since the February 2024 website reappearance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should LockBit victims do?

Organizations affected by a LockBit incident should follow the latest official reporting and assistance instructions. The NCA’s Operation Cronos page directs victims in the U.K. to the NCA, U.S. victims to the FBI’s Internet Crime Complaint Center (IC3), and victims elsewhere to No More Ransom. The page asks organizations to provide details such as their organization or domain, LockBit identifier, incident date, any prior law-enforcement reference and a contact. Assistance channels and decryption-key availability can change, so check the current instructions rather than assuming a key will work for a particular case. The DOJ’s 2024 release also directed U.S. victims to an IC3 LockBit questionnaire.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.