Image showing the main webpage of the LockBit ransomware gang, now under the control of law enforcement.


February 26, 2024

Law enforcement agencies from several countries, including the U.K.’s National Crime Agency (NCA), have dealt a significant blow to the notorious LockBit ransomware gang. The operation involved seizing infrastructure and source code, arresting two individuals in Poland and Ukraine, and freezing 200 cryptocurrency accounts associated with the group.

The NCA, along with international partners, infiltrated LockBit's network, taking control of its services in three countries and compromising 28 servers, effectively crippling the gang's criminal activities. This included disrupting servers in the U.S. that hosted their "StealBit" data exfiltration platform.

The NCA emphasized that LockBit's capabilities and credibility have been severely damaged, and they are determined to continue targeting the group and its affiliates. They have taken control of LockBit's primary administration environment and its public-facing leak site on the dark web, where they will now post information exposing LockBit's operations.

Additionally, the NCA has obtained LockBit's source code and intelligence on their activities and associates. The operation also resulted in the seizure of over 1,000 decryption keys, which will be provided to victims of LockBit ransomware attacks.

The U.K. announcement follows reports of the seizure of the gang's website, which now indicates that it is under the control of the NCA, working with international partners.

LockBit has been a target of law enforcement for some time, leading to previous arrests and charges. The recent takedown involved the unsealing of indictments against Russian nationals Artur Sungatov and Ivan Kondratyev, who are accused of deploying LockBit against numerous victims.

The joint background paper released last June by cybersecurity agencies from seven countries highlighted LockBit's significant activity in 2022, with the gang being the most active global ransomware group that year.

The U.S. estimated that LockBit had targeted over 2,000 victims worldwide and received more than US$120 million in ransom payments. Canada estimated that LockBit was responsible for 22 per cent of attributed ransomware incidents in 2022.

While the takedown will have a substantial short-term impact on LockBit's operations, experts warn that the group may resurface under a different name, with current members joining or establishing other gangs. There is a global effort to hunt down ransomware gangs and their leaders, and technical mistakes by these groups can lead to successful takedowns like this one.

There are also implications for victims of LockBit. Law enforcement agencies may share information about data breaches and ransom payments with other national authorities for further investigation. Paying ransoms may violate U.S. sanctions, and GDPR regulations in Europe require reporting data breaches, potentially leading to investigations against companies that paid ransoms to conceal breaches.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

Nintendo’s Switch 2 Preview Fails to Impress, Stock Takes a Hit

Nintendo recently teased its highly anticipated Switch 2, but the reveal left many disappointed, resulting in a significant drop in....

TikTok Shutdown Looms: What U.S. Users Need to Know

TikTok, a wildly popular app with over 170 million American users, faces an imminent shutdown in the United States on....

DJI Flip Combines Lightweight Design with Advanced Features

DJI has unveiled its latest innovation, the Flip drone, a compact and user-friendly device designed for both beginners and seasoned....

TikTok Ban Sparks RedNote Surge Among US Creators

As TikTok faces a looming ban in the United States, a growing number of users and creators are flocking to....

Apple Struggles Globally as AI Features Fall Short in Phones

Apple Inc. faced a challenging year in 2024 as its iPhone sales declined, losing market share to rising Chinese smartphone....

TSMC starts making 4-nanometer chips in Arizona, Raimondo confirms

Taiwan Semiconductor Manufacturing Co. (TSMC) has reached a significant milestone in the semiconductor industry by beginning production of advanced four-nanometer....

Meta Accused of Using Pirated Books for AI Training

Meta Platforms, the parent company of Facebook, stands accused by a group of authors of using pirated versions of copyrighted....

Apple Denies Using Siri Data for Ads After $95M Settlement

Apple has reaffirmed its commitment to user privacy, addressing concerns about its Siri voice assistant in the wake of a....

Tech Industry Warns US on AI Chip Export Restrictions

A leading tech industry group called on the Biden administration to reconsider a proposed rule limiting global access to advanced....

Nvidia's Latest Innovations and Partnerships at CES 2025

At the CES 2025 conference in Las Vegas, Nvidia introduced several groundbreaking technologies aimed at transforming the artificial intelligence (AI),....

Pony.ai Targets Robotaxi Service Launch in Hong Kong

Pony.ai Inc., a company based in Guangzhou, is making moves to launch its autonomous taxi services in Hong Kong, competing....

US Sanctions Chinese Firm Over Alleged Global Hacking Operation

The United States imposed sanctions on China's Integrity Technology Group on Friday, accusing the Beijing-based company of orchestrating a vast....