What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

U.S. agencies warned that LockBit is an affiliate-run ransomware operation whose attacks can involve both stolen data and file encryption. Their 2023 advisories recommend a layered defense: close common access routes, limit an intruder’s ability to move through a network, detect suspicious activity, and maintain tested, immutable backups. Those advisories describe findings through 2023; they do not establish LockBit’s operational status or prevalence in 2026.

What the government advisories said

Two official documents provide distinct views of the threat. CISA and international partners published “Understanding Ransomware Threat Actors: LockBit” (AA23-165A) on June 14, 2023. It covers the broader LockBit operation, its observed behaviors, and mitigations. The FBI, CISA, and MS-ISAC published “#StopRansomware: LockBit 3.0” (AA23-075A) on March 16, 2023. Its indicators of compromise and tactics, techniques, and procedures reflect FBI investigations through March 2023.

The June advisory characterized LockBit as the most deployed ransomware variant worldwide in 2022 and said it remained prolific in 2023. It also reported approximately $91 million in U.S. impact since LockBit activity was first observed in the United States on January 5, 2020. These are historical figures from the 2023 advisory, not current statistics. The advisory also cited French agency ANSSI figures: it handled 80 LockBit-linked alerts, representing 11% of the ransomware cases it handled in the stated period; about 13% of those alerts had an unconfirmed or denied breach status.

Why LockBit 3.0 calls for layered defenses

Affiliates make attack methods vary

The advisories describe LockBit as ransomware-as-a-service: the operation maintains ransomware and supporting infrastructure, while affiliates carry out attacks. Because affiliates use varied tactics, a defense built around one assumed entry route or a fixed set of indicators can miss other activity. The March advisory describes LockBit 3.0 as an affiliate-based continuation of earlier versions, with businesses and critical infrastructure among its targets.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encryption is not the only threat

The June advisory describes double extortion since 2021: affiliates may steal data as well as encrypt it, then threaten to publish the stolen information if demands are not met. A business therefore needs to consider confidentiality and disruption, not just whether it can restore encrypted files.

LockBit leak sites do not provide a complete or reliable timeline of victims. The June advisory says they disclose only a portion of incidents and are not a dependable way to determine when an attack occurred. A missing listing should not be treated as evidence that an organization was not attacked.

Prioritize controls by the stage of an attack

The advisories point to complementary measures rather than a single product or fix. Use the following sequence to reduce the chance of entry, contain an intrusion, improve detection, and preserve recovery options.

1. Reduce opportunities for initial access

  • Prioritize remediation of known exploited vulnerabilities, as urged in the March advisory.
  • Secure internet-exposed services and close remote-access ports that are not in use.
  • Use multifactor authentication. The March advisory specifically recommends phishing-resistant MFA; a FIDO2 security key may be one way to implement it, depending on compatibility with the organization’s identity platform and policy. The advisory does not endorse a particular product.
  • Filter malicious email and train users to recognize and report phishing.
  • Require administrator credentials for software installation.

2. Limit movement and privilege inside the network

  • Segment networks so an attacker cannot move freely between systems.
  • Isolate web-facing applications where appropriate.
  • Apply least privilege and review Active Directory control paths to identify ways an attacker could gain broader access.

3. Improve detection and constrain suspicious activity

  • Monitor network traffic and signs of lateral movement.
  • Use endpoint detection and response where appropriate.
  • Apply application control or allowlisting to restrict which software can run.
  • Validate security controls against the behaviors described in the advisories and tune them based on results. The March advisory’s indicators and TTPs are a dated defensive reference, not a complete or current indicator set.

4. Make recovery dependable

  • Keep backups encrypted and immutable, and ensure they cover the organization’s data infrastructure.
  • Test restoration and the broader recovery process so that backups are useful under incident conditions, not merely present.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use the right guidance for the right purpose

The March LockBit 3.0 advisory is useful for understanding the agency observations and mitigation priorities available as of March 2023. The June advisory broadens the picture with the affiliate model, double-extortion risk, and additional defensive recommendations. For general ransomware prevention, response, and recovery beyond LockBit-specific reporting, consult CISA’s #StopRansomware Guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The June advisory’s authoring organizations state: “The authoring organizations encourage the implementation of the recommendations found in this CSA to reduce the likelihood and impact of future ransomware incidents.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.