Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After seizing LockBit’s infrastructure on February 19, 2024, authorities used the group’s own website to publicize the operation and cast doubt on whether its leader and affiliates could trust one another. The website’s claim that LockBitSupp had “engaged with Law Enforcement” was deliberately ambiguous; it did not establish that he had become an informant. The operation caused a major disruption, but LockBit later attempted to return.

What Operation Cronos did to LockBit

Operation Cronos was an international infrastructure seizure, not just a police takeover of a website. In a 2024 brief, CERT-EU reported that the operation, led by the UK National Crime Agency and coordinated with Europol and Eurojust, took down 34 servers, involved arrests in Poland and Ukraine, and froze more than 200 cryptocurrency accounts. FBI Director Christopher Wray later described the sequenced operation as involving 10 countries and the seizure of U.S.-based servers, in remarks reported by the FBI on April 4, 2024.

Those actions interrupted the systems LockBit used to operate and communicate. They also gave authorities control of the group’s seized public-facing site, which became a platform for a second kind of disruption.

How police used LockBit’s website to sow doubt

Authorities replaced links on the seized site with law-enforcement material about press releases, sanctions, arrests and decryption. A post teased information about “LockBitSupp,” the alias associated with the group’s leader, then said he “has engaged with Law Enforcement.” It offered no explanation of what “engaged” meant.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That ambiguity was central to the effect described by cybersecurity experts: readers inside the criminal network could interpret the phrase as a hint of cooperation, a police infiltration, or both. CyberScoop’s February 23, 2024 report described the messaging as an effort to make hackers question whether there were infiltrators inside LockBit. These were expert readings of the campaign, not official police confirmations that an informant or undercover source existed.

Why the message could unsettle affiliates

Ransomware groups depend on trust among operators and affiliates who may share access, tools and proceeds. A public suggestion that law enforcement had reached someone close to LockBit’s leader could prompt suspicion even without proof. Allan Liska of Recorded Future’s Insikt Group told CyberScoop the message could imply that LockBitSupp was an informant or that police had infiltrated his inner circle.

Recorded Future analyst Alexander Leslie characterized the tactic as law enforcement “sowing the seeds of distrust.” Jon DiMaggio, chief security strategist at Analyst1, called it “a psychological operation” and said he had advocated such mitigation strategies. These characterizations describe analysts’ interpretations of the messaging; they do not establish the agencies’ private intent or prove that LockBit’s inner circle had been penetrated.

Why make the disruption public?

Adam Hickey, a former deputy assistant attorney general in the U.S. Department of Justice’s National Security Division, told CyberScoop that an operation’s disruption “needs to sell” and “land as impactful” if law enforcement is to be seen as effective. He described the splash page as an attempt to make the operation more marketable. That is Hickey’s assessment, not an official explanation from the agencies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is known about LockBitSupp—and what is not

The seized site’s wording alone does not show that LockBitSupp cooperated with law enforcement. “Engaged with Law Enforcement” could be read in several ways, and the post did not specify which was intended. The reporting cited here records expert interpretations of the insinuation, not evidence that he was an informant or that police had infiltrated LockBit’s leadership.

The distinction matters: the public message could create uncertainty without resolving it. Its potential impact on trust came from leaving affiliates and observers to consider the possibility of compromise, not from a substantiated public account of a source inside the group.

Disruption versus durability

Dimension What the reporting establishes What it does not establish
Technical disruption CERT-EU’s 2024 brief recorded 34 servers taken down, arrests in Poland and Ukraine, and more than 200 cryptocurrency accounts frozen. Those figures do not show that every LockBit operator, affiliate or copy of its data was eliminated.
Psychological pressure The seized site carried police material and an ambiguous message about LockBitSupp; experts described the messaging as an attempt to foster distrust. The message did not prove that LockBitSupp was an informant or that law enforcement had infiltrated the leadership.
Short-term effect and durability The infrastructure seizure disrupted LockBit’s operations; later reporting documented attempts to reappear. A takedown did not permanently end the LockBit brand or demonstrate that all subsequent activity had ceased.

The aftermath illustrates the difference between disrupting a criminal operation and permanently removing its brand. The Record reported on February 26, 2024 that LockBit had tried to relaunch on replacement infrastructure and minimize reputational damage. On May 6, 2024, TechCrunch reported that the former dark-web site had reappeared with new authority posts while the gang had also returned with a new leak site. Those reports show attempted recovery and rebranding pressure; they do not mean the original infrastructure seizure had failed to disrupt the group.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did Operation Cronos destroy LockBit?

No. It delivered a substantial blow to LockBit’s infrastructure and publicly challenged the trust on which its network depended, but the later relaunch attempts show that a takedown is not the same as permanently ending a ransomware brand. The available reporting does not establish that LockBitSupp cooperated with police or that an infiltration caused the disruption.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.