LockBit Ransomware Network Disrupted by Law Enforcement
On February 19-20, 2024, law enforcement agencies from ten countries, including the FBI, UK National Crime Agency (NCA), Europol, and agencies from Australia, Canada, France, Germany, Japan, the Netherlands, and Sweden, executed Operation Cronos, seizing LockBit’s ransomware infrastructure.
LockBit had been the dominant ransomware-as-a-service (RaaS) operation since at least 2022, responsible for thousands of attacks against hospitals, schools, governments, and critical infrastructure globally. The operation generated over $1 billion in extorted payments.
Operation Cronos resulted in the seizure of 34 servers across Europe and North America, the takedown of LockBit’s dark web leak sites and affiliate portals (replaced with law enforcement seizure notices), recovery of more than 1,000 decryption keys, and two arrests in Poland and Ukraine. The US, UK, and Australia imposed sanctions on key LockBit figures, and the alleged leader “LockBitSupp” was identified as Dmitry Khoroshev, a Russian national.