Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LockBit is a criminal ransomware-as-a-service (RaaS) ecosystem, not a single piece of malware or one attacker. A core operation supplied malware, negotiation and leak-site infrastructure, while affiliates broke into organizations, stole data, encrypted systems and demanded payment. Operation Cronos seized major LockBit infrastructure in February 2024 and obtained potential decryption capabilities, but it did not guarantee permanent eradication. Technical reporting in 2025 and leak-site monitoring in 2026 indicate that LockBit activity returned under the LockBit 5.0 name.

What is LockBit?

LockBit is an organized ransomware operation that sells or shares attack capability with affiliates. The developers and administrators maintain the ransomware, recruit participants, run an online control panel and provide services such as data-transfer infrastructure. Affiliates obtain access to networks, conduct the intrusion and use the supplied tools to extort the victim.

A typical attack combines double extortion: criminals encrypt files and demand money for a decryption key, then threaten to publish stolen files on a leak site. This division of labor means an incident may involve an affiliate that the victim never hears about, alongside a separate core operation controlling the technology and payment process.

How the LockBit RaaS model worked

The core operation

  • Developed and updated ransomware builds.
  • Recruited and managed affiliates through an administration panel.
  • Provided infrastructure, including the StealBit data-transfer platform and a public leak site.
  • Handled rules, negotiations and revenue sharing.

Affiliates

  • Purchased, discovered or brokered access to vulnerable systems.
  • Moved through the victim’s environment, sought privileged accounts and disabled recovery controls.
  • Stole data, deployed encryption and negotiated with the victim.

The model allowed people with different skills to participate without building a complete ransomware operation themselves. It also makes attribution and victim counts difficult: one affiliate can attack many organizations, and public claims may not be independently verified.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How large was LockBit’s impact?

Published estimates use different dates and definitions, so they must not be added together or treated as one cumulative total.

Source and date Reported measure How to interpret it
U.S. Department of Justice, February 20, 2024 More than 2,000 victims; more than $120 million in ransom payments; demands totaling hundreds of millions of dollars Estimate presented with the 2024 disruption announcement.
U.S. Attorney’s Office, District of New Jersey, May 2024 More than 2,500 victims and more than $500 million in ransom payments Case summary covering activity from about January 2020 through at least July 2024; broader losses were described as billions when lost revenue, response and recovery are included.
National Crime Agency, 2024 LockBit accounted for 25% of ransomware attacks in the preceding year Historical characterization on the Operation Cronos page, not a 2026 market-share measurement.
Check Point Research, Q1 2026 163 public victim postings; LockBit ranked fourth in its global monitoring Vendor-monitored data-leak-site posts, not verified attacks or unique victims.
Check Point Research, Q2 2026 105 public victim postings Monitored posts, with activity lower than in Q1; not a complete census of incidents.

What happened in Operation Cronos?

On February 20, 2024, the U.K. National Crime Agency, U.S. Department of Justice, FBI and international partners announced a coordinated disruption known as Operation Cronos. Authorities seized public-facing sites and servers used by LockBit administrators, including infrastructure associated with the StealBit transfer platform.

The NCA reported obtaining source code, data and intelligence, and taking control of LockBit’s principal administration environment and dark-web leak site. The NCA described that environment as the place where affiliates built and carried out attacks.

Decryption assistance

The FBI said it had access to nearly 1,000 potential decryption capabilities and planned victim engagement with more than 1,600 known U.S. victims. The NCA described about 1,000 keys and routes for affected people in the U.K., U.S. and elsewhere. “Potential” is important: a key may depend on the LockBit variant, encryption implementation and the affected files, so the announcement was not a promise that every system could be decrypted.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Charges against an alleged developer

In May 2024, the DOJ announced charges against Dmitry Khoroshev, whom prosecutors identified as an alleged LockBit developer. Prosecutors allege that he received a 20% share of ransom payments and retained copies of data from victims who paid, despite alleged promises to delete it. The DOJ reported six LockBit members charged at that point. These statements are allegations in a prosecution, not adjudicated findings.

Did Operation Cronos permanently shut down LockBit?

No. The operation removed or controlled important infrastructure and exposed the group’s systems, but disruption is not the same as permanent elimination. Criminal operators can rebuild, change affiliates, obtain new access and rebrand their tooling.

LockBit 5.0 reporting

Health-ISAC’s October 2025 bulletin described a September 2025 return identified as LockBit 5.0. Its assessment covered Windows, Linux and VMware ESXi targeting, anti-analysis measures, randomized file extensions and changes intended to give operators more flexibility. Those are reported capabilities, not proof that every LockBit 5.0 incident uses every feature.

Check Point Research monitored 163 LockBit leak-site postings in Q1 2026 and 105 in Q2 2026. The Q1 report described a February dip followed by a March rise; the Q2 report described fewer posts than in Q1. These are public claims collected by a security vendor, not independently confirmed incidents, and the latest figures available here run through Q2 2026 rather than providing a real-time count.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should a LockBit victim do?

  1. Contain safely. Follow your incident-response plan. Isolate affected systems from networks where practical, but preserve evidence and avoid actions that destroy logs or volatile data.
  2. Use official reporting channels. Contact the FBI or Internet Crime Complaint Center in the United States, the NCA in the United Kingdom, or the relevant national cybercrime authority. The NCA’s Operation Cronos page is historical and marked expired, so verify current contact instructions before sending information.
  3. Check current decryption assistance. Ask the FBI, NCA or No More Ransom whether a current decryptor or key matches your specific infection. Eligibility and technical recoverability vary.
  4. Preserve ransom notes and indicators. Keep file extensions, ransom-note text, wallet addresses, timestamps, affected host names and forensic images for investigators and responders.
  5. Coordinate recovery and legal obligations. Engage qualified incident-response and legal specialists where appropriate, assess notification duties, and document decisions. Do not assume that paying removes the risk of publication or guarantees working decryption.

How organizations can reduce LockBit risk

CISA and international partners’ LockBit advisory is a useful starting point for hardening and preparedness. Adapt its mitigations to your environment rather than treating it as a guarantee against compromise.

  • Require phishing-resistant or otherwise strong multifactor authentication for remote access and privileged accounts.
  • Patch internet-facing systems quickly, especially remote-access, virtualization and identity infrastructure.
  • Apply least privilege, segment critical networks and monitor administrative and remote-management activity.
  • Protect backups from the production domain, keep offline or otherwise immutable copies, and test restoration regularly.
  • Centralize and retain logs so lateral movement, credential abuse and mass file changes can be investigated.
  • Prepare an exercised ransomware playbook covering isolation, evidence handling, communications, legal review and restoration priorities.

An external hard drive can be one offline-backup component, but a single drive is not a complete organizational recovery design, does not prevent initial access and should not be represented as a CISA-endorsed brand or solution. A recovery plan should include protected copies, access controls, geographic considerations and tested restoration.

How to choose an incident-response provider

If internal expertise is insufficient, compare providers on capabilities rather than a generic ransomware label:

  • Documented ransomware investigation and recovery experience.
  • Forensic evidence handling, chain-of-custody procedures and secure data transfer.
  • Ability to coordinate identity, endpoint, cloud, virtualization and backup recovery.
  • Clear scope, staffing, escalation procedures and geographic coverage.
  • Support for regulatory notifications, insurer requirements and communications with law enforcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What LockBit means for defenders now

LockBit should be treated as an adaptable criminal ecosystem rather than a closed case. Operation Cronos materially disrupted its infrastructure and helped produce decryption opportunities, while later LockBit 5.0 reporting shows why organizations must continue patching, protecting identities, isolating backups and practicing recovery. Public leak-site counts can signal activity, but they cannot substitute for incident verification or an organization’s own monitoring and response process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can LockBit victims decrypt their files without paying?

Sometimes. Law-enforcement seizures produced potential decryption capabilities, but whether one works depends on the specific LockBit variant and affected data. Contact current FBI, NCA or No More Ransom channels rather than relying on an old key or email address.

Is every leak-site post proof of a LockBit attack?

No. Posts monitored by researchers are public claims. They may be incomplete, duplicated or unverified, so they should not be treated as a confirmed count of unique victims.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.