An international law-enforcement operation led by the UK National Crime Agency disrupted LockBit’s ransomware-as-a-service operation on February 20, 2024. Working with the FBI and partners from nine other countries, investigators infiltrated LockBit’s network, took control of its primary administration environment and dark-web leak site, and seized source code and intelligence on affiliates. Operation Cronos also dismantled Stealbit data-exfiltration infrastructure across three countries, took down 28 affiliate servers, froze more than 200 cryptocurrency accounts, and led to arrests in Poland and Ukraine alongside U.S. charges and indictments. Authorities obtained more than 1,000 decryption keys to support victim recovery.
LockBit relaunched its leak site on February 24 and listed 16 victims by February 26, signaling that the disruption had not eliminated the operation. The group claimed investigators exploited vulnerabilities in its PHP servers while backup infrastructure remained unaffected, and announced plans to harden infrastructure, distribute affiliate access across multiple servers, and manually release decryptors. A free recovery tool became available through No More Ransom, although its coverage across attack dates and LockBit variants remained unclear. Victims should seek assistance through law enforcement and assess available decryption tools; the NCA found that LockBit retained victim data even after ransom payments. The disruption could undermine affiliate confidence, but LockBit’s recovery and affiliate migration to other ransomware operations remain risks.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
In its public disclosure of the operation, the NCA revealed that seized LockBit systems still contained data belonging to victims who had paid ransoms. The finding showed that payment did not guarantee deletion of stolen information.
The US Department of Justice announced that two defendants accused of using LockBit were charged and in custody. Authorities also unsealed indictments against two additional Russian nationals accused of conspiring to conduct LockBit attacks.
Authorities arrested two LockBit actors in Poland and Ukraine as part of the coordinated operation. They also froze more than 200 cryptocurrency accounts linked to the group.
International authorities disrupted LockBit, taking control of its primary administration environment and dark-web leak site and seizing source code, operational intelligence, and more than 1,000 decryption keys. ReliaQuest reported 34 servers taken down and more than 14,000 rogue accounts seized; the NCA separately identified 28 affiliate servers taken down and Stealbit infrastructure seized across three countries.
LockBit 3.0, also known as LockBit Black, began operating. The report noted that this version likely used different encryptors from earlier LockBit versions.
Operation Cronos began as an international investigation targeting LockBit. The UK National Crime Agency led the operation, with Europol and Eurojust coordinating European action.
LockBit announced plans to strengthen infrastructure security and distribute affiliate-panel access across multiple servers according to partners' trust levels. It also announced plans to release decryptors manually and offer trial file decryptions.
LockBit administrators claimed law enforcement exploited vulnerabilities in the group's PHP servers while leaving backup infrastructure unaffected. The group acknowledged what it described as its own negligence and claimed its attack against Fulton County motivated the operation.
By 10 a.m. ET on February 26, LockBit's reestablished data-leak website listed 16 victims.
LockBit reestablished a data-leak website after the law-enforcement disruption, demonstrating that the group had resumed part of its public-facing operations.
Following Operation Cronos, a free LockBit decryption tool became available through the No More Ransom portal. Its coverage of specific attack dates and ransomware versions remained unclear.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.