Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actioncybercrime-service-ecosystemoperational-disruption

Global LockBit Takedown Disrupted Operations and Exposed Its Leadership

Updated 28d agoFirst seen May 25, 202612 sources

An international law enforcement operation led by the UK's National Crime Agency and the FBI seized LockBit infrastructure on 19 February 2024, disrupting one of the world's most prolific ransomware-as-a-service groups. Follow-on actions publicly identified and sanctioned a senior LockBit leader, while officials said the campaign targeted the gang's administrators, infrastructure, and criminal affiliates. Subsequent reporting said the disruption sharply reduced LockBit's standing in ransomware rankings after years in which the group had claimed thousands of victims across more than 100 countries.

Threat research shows LockBit's reach was driven by a scalable affiliate model rather than malware alone, with intrusions commonly starting through abused VPN, Citrix, and RDP access or stolen credentials, followed by use of tools such as Impacket, Mimikatz, PsExec, Rclone, and StealBit. Affiliates increasingly targeted VMware ESXi environments to maximize operational impact, and some skipped encryption entirely in favor of data-theft extortion using LockBit-branded notes. The group's earlier attacks included a reported $80 million demand against CDW, but researchers and investigators warn that even as LockBit declines, its affiliates and copycats are likely to continue operating under other ransomware brands.

Share:
Global LockBit Takedown Disrupted Operations and Exposed Its Leadership
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 9, 20263mo ago

State Department offers rewards for information on LockBit members

On 2026-04-09, the U.S. Department of State announced Rewards for Justice offers of up to $10 million for information identifying or locating key LockBit leaders and up to $5 million for information leading to the arrest or conviction of participants in LockBit activities. The notice described LockBit as responsible for more than 2,000 attacks since January 2020 and at least $144 million in bitcoin ransom payments.

Reward for Information: LockBit Ransomware as a Service (RaaS) - United States Department of State
Dec 20, 20242y ago

DOJ charges alleged LockBit developer Rostislav Panev

U.S. prosecutors announced charges against Rostislav Panev, a dual Russian-Israeli national accused of serving as a LockBit developer and helping build and maintain the group's malware and infrastructure from around 2019 through February 2024. The DOJ said Panev had been arrested in Israel in August 2024 on a U.S. provisional arrest request and remained in custody pending extradition.

District of New Jersey | U.S. Charges Dual Russian And Israeli National As Developer Of Lockbit Ransomware Group | United States Department of Justice
Jun 22, 20242y ago

BlackSuit ransomware blamed for CDK Global outage

On 2024-06-22, reporting attributed the major CDK Global outage to a BlackSuit ransomware attack. This is a separate ransomware event included in the references but not part of the LockBit enforcement timeline.

May 22, 20242y ago

Reports show LockBit's standing falls after the takedown

By 2024-05-22, reporting indicated the February disruption had significantly reduced LockBit's prominence among ransomware groups. The takedown was described as taking a measurable toll on the gang's activity and rankings.

May 7, 20242y ago

DOJ unseals indictment against alleged LockBit administrator

On 2024-05-07, the U.S. Department of Justice unsealed a 26-count indictment against Dmitry Yuryevich Khoroshev, alleging he created, developed, and administered LockBit from 2019 through May 2024. The DOJ said the case followed the February infrastructure seizure and described LockBit as responsible for more than 2,500 victims worldwide and at least $500 million in ransom payments.

Office of Public Affairs | U.S. Charges Russian National with Developing and Operating LockBit Ransomware | United States Department of Justice

LockBit leader identified as Dmitry Khoroshev and sanctioned

On 2024-05-07, UK and US authorities publicly unmasked LockBit's alleged administrator, Dmitry Khoroshev, and imposed sanctions on him. The announcement marked a major attribution and enforcement escalation following the February takedown.

Feb 19, 20242y ago

Global law-enforcement operation disrupts LockBit infrastructure

On 2024-02-19, a multinational operation led by the UK's National Crime Agency and the FBI seized LockBit infrastructure and disrupted the ransomware group's operations. The action also targeted individuals associated with the group.

Dec 31, 20232y ago

LockBit reaches more than 2,350 named victims worldwide by end of 2023

Secureworks reported that LockBit had compromised thousands of organizations and accumulated more than 2,350 named victims across 112 countries by the end of 2023. The scale was driven by its ransomware-as-a-service affiliate model and strong criminal branding.

Oct 14, 20233y ago

LockBit extorts CDW and demands $80 million ransom

By mid-October 2023, reports said the LockBit ransomware gang had attacked CDW and demanded an $80 million ransom. This reflects LockBit's continued high-profile activity before the 2024 law-enforcement disruption.

Apr 1, 20224y ago

International LockBit investigation begins

Europol said the multinational investigation into LockBit began in April 2022, well before the public takedown. The long-running probe involved coordination among multiple law-enforcement agencies ahead of Operation Cronos.

Six things we learned from the LockBit takedown | TechCrunch
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Global LockBit Takedown Disrupted Operations and Exposed Its Leadership | Mallory