Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On 20 February 2024, the U.K. National Crime Agency (NCA), FBI and international partners announced Operation Cronos, a coordinated operation that infiltrated and seized key parts of LockBit’s ransomware infrastructure. Authorities took control of the group’s affiliate administration environment and data-leak site, seized servers, froze cryptocurrency accounts and obtained decryption keys for victims. LockBit later tried to rebuild; the NCA reported sharply reduced activity in the U.K. after the operation, not that the group had disappeared permanently.

What authorities seized in Operation Cronos

The operation targeted the systems that helped LockBit affiliates carry out attacks and extort victims. According to the NCA’s 20 February 2024 announcement, investigators took control of the administration environment affiliates used to build and launch attacks, as well as the leak site used to threaten publication of stolen data. They also obtained LockBit’s source code and intelligence about its affiliates.

The agencies’ figures describe different parts of the operation, not competing totals:

Agency and date Reported action or figure What it describes
FBI, February 2024 Nearly 11,000 domains and servers seized or controlled The FBI’s broader count of public-facing websites and servers associated with LockBit’s operations.
NCA, February 2024 28 affiliate servers taken down; infrastructure in three countries seized The NCA’s reported server and infrastructure actions.
NCA, February 2024 More than 200 cryptocurrency accounts frozen Financial disruption reported by the NCA.

Europol described Cronos as a multinational sweep involving law-enforcement agencies from a dozen countries. The FBI said it had identified nearly 1,000 potential decryption capabilities and planned to engage more than 1,600 known U.S. victims. Those are FBI-reported figures and should not be read as the number of victims whose files were necessarily restored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How LockBit’s ransomware operation worked

LockBit operated as ransomware-as-a-service: its affiliates used malware and supporting infrastructure supplied by the group, then broke into victim networks, stole data and encrypted systems. They demanded cryptocurrency and threatened to publish the stolen information if victims did not pay.

The NCA said data obtained during the disruption showed that paying a ransom did not guarantee that stolen data would be deleted. A payment therefore could not ensure that information would remain private or that systems would be fully restored.

Can LockBit victims decrypt their files?

Some may be able to, but decryption depends on the incident and the key available for it; the agencies did not promise that every victim could recover files. In February 2024, the NCA said it had obtained more than 1,000 decryption keys. In a May 2024 update, it reported holding more than 2,500 and having proactively contacted nearly 240 victims in the U.K. The FBI directed U.S. victims to its LockBit victim portal.

If you believe your organization was affected, use official law-enforcement victim-assistance channels or No More Ransom’s official resources to check for help. Preserve ransom notes, file identifiers and incident-report details, and coordinate recovery with your organization’s security or incident-response team. Do not assume a key for one LockBit incident will work for another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who was arrested, and who is LockBitSupp?

Authorities reported arrests of two alleged LockBit actors in Poland and Ukraine during the February 2024 operation. The announcements cited here did not identify those two people by name.

In May 2024, the NCA identified Russian national Dmitry Khoroshev, known online as LockBitSupp, as the alleged administrator and developer of LockBit. The U.K., U.S. and Australia sanctioned him. U.S. authorities unsealed an indictment and announced a reward. These were later attribution and enforcement actions, distinct from the February infrastructure seizure.

Did Operation Cronos end LockBit?

No permanent end was established. The NCA said in May 2024 that LockBit had attempted to rebuild but was operating at limited capacity. It reported a 73% reduction in average monthly LockBit attacks in the U.K. after the February disruption and said the number of active affiliates had fallen to 69.

The NCA also warned that LockBit republished old victims and made misleading claims, so apparent victim counts should be treated cautiously. Its attack and affiliate figures are agency measurements reported in May 2024; they do not establish the group’s activity after that update.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the seizure mattered

Cronos disrupted more than a website: authorities gained access to the group’s administration systems, source code and affiliate intelligence, while also removing infrastructure and freezing accounts. The decryption keys and victim outreach offered a route to assistance for some affected organizations. The operation weakened LockBit’s capacity, according to the NCA’s reported U.K. measures, but the group’s attempted rebuild is why the seizure should be described as a major disruption rather than a final eradication.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.